Pour les développeurs
Every HTTP endpoint of the Orochia web app with the access rule that guards it, and the database tables — generated from the code.
Orochia API Reference
Generated from code by
scripts/generate-docs.mjs— do not hand-edit.
Endpoints (70)
| Method | Path | Access | Summary |
|---|---|---|---|
GET | /api/admin/creators | session · ADMIN | Creator accounts with their verification state; ?verified=false lists the review queue. |
PATCH | /api/admin/creators/[id] | session · ADMIN | Records the outcome of a creator's 18 U.S.C. § 2257 review. |
GET | /api/admin/documents | session · ADMIN | A creator's 2257 document (?ref=private/documents/<uuid>.<ext>), for operators only; never cached. |
GET | /api/admin/overview | session · ADMIN | Operator overview: money, catalogue and the three queues that need a human. |
GET | /api/admin/payouts | session · ADMIN | Payout requests with their creator; ?status= filters. |
PATCH | /api/admin/payouts/[id] | session · ADMIN | Advances a payout. |
GET | /api/admin/reports | session · ADMIN | Content reports, newest first; ?status= filters. |
PATCH | /api/admin/reports/[id] | session · ADMIN | Moves a report through triage (open → in review → resolved). |
GET | /api/admin/users | session · ADMIN | Every account (filter by ?role=, ?suspended=, ?q=): role, verification and suspension state. |
PATCH | /api/admin/users/[id] | session · ADMIN | Suspends an account (it can no longer sign in, and its open sessions are refused on their next request), reinstates it, or changes its role. |
GET | /api/admin/videos | session · ADMIN | The catalogue for moderation: every video with its creator, state and open reports; ?state=removed lists takedowns. |
PATCH | /api/admin/videos/[id] | session · ADMIN | Takes a video down (DMCA, terms, a confirmed report) with a recorded reason, or restores it. |
POST | /api/auth/forgot-password | public | E-mails a password-reset link (1 h) to the address, if an active account uses it. |
POST | /api/auth/login | public | Password login. |
POST | /api/auth/logout | public | — |
GET | /api/auth/me | public | The signed-in account (with whether its e-mail is verified), or user: null. |
POST | /api/auth/register | public | Creates a member or creator account (never an administrator), signs it in and e-mails the link that verifies its address — until then the account can do nothing else. |
POST | /api/auth/resend-verification | public | E-mails a new verification link to the signed-in account (the previous link stops working). |
POST | /api/auth/reset-password | public | Sets a new password with the link's one-time token (1 h). |
POST | /api/auth/verify-email | public | Verifies an e-mail address with the link's one-time token (48 h); refreshes the session of that account. |
GET | /api/bunny/analytics | session · ADMIN | Catalogue statistics for administrators, from the database. |
POST | /api/contacts | session · MEMBER / CREATOR / ADMIN | Sends a contact request (accepted at once when the other person already asked). |
DELETE | /api/contacts/[id] | session · MEMBER / CREATOR / ADMIN | Removes a contact or withdraws a request (either side). |
PATCH | /api/contacts/[id] | session · MEMBER / CREATOR / ADMIN | Accepts or rejects a request addressed to you, or blocks the other person. |
GET | /api/creator/payouts | session · CREATOR | The signed-in creator's balance, lifetime earnings and payout history — from the ledger. |
POST | /api/creator/payouts | session · CREATOR | Requests a payout; balances are checked and reserved atomically (requestPayout). |
GET | /api/creators/[username] | public · session-aware | A creator's public page: profile, videos, the collections you may open and, signed in, how you relate to them. |
DELETE | /api/creators/[username]/follow | session · MEMBER / CREATOR / ADMIN | Unfollows a creator. |
POST | /api/creators/[username]/follow | session · MEMBER / CREATOR / ADMIN | Follows a creator; the follow stays PENDING until the creator approves it. |
GET | /api/feed | public | The public feed and the explore search (?q=, ?tag=, paginated); with the featured creator and popular tags. |
GET | /api/health | public | — |
POST | /api/legal/report | public · session-aware | Content reports. |
GET | /api/me/dashboard | session · ADMIN / CREATOR / MEMBER | — |
PATCH | /api/me/followers/[id] | session · CREATOR | A creator approves a follower (opening followers-only videos to them) or removes them. |
GET | /api/me/lists | session · MEMBER / CREATOR / ADMIN | Your reusable audience lists (private to you), with their size. |
POST | /api/me/lists | session · MEMBER / CREATOR / ADMIN | Creates an audience list (names are unique per account). |
DELETE | /api/me/lists/[id] | session · MEMBER / CREATOR / ADMIN | Deletes one of your lists; the videos and collections it opened close to its members. |
PATCH | /api/me/lists/[id] | session · MEMBER / CREATOR / ADMIN | Renames one of your lists. |
DELETE | /api/me/lists/[id]/members | session · MEMBER / CREATOR / ADMIN | Removes someone from one of your lists (?userId=): what the list opened closes to them. |
GET | /api/me/lists/[id]/members | session · MEMBER / CREATOR / ADMIN | The people in one of your lists. |
POST | /api/me/lists/[id]/members | session · MEMBER / CREATOR / ADMIN | Adds an account to one of your lists by username (idempotent; the list stays private). |
GET | /api/me/network | session · MEMBER / CREATOR / ADMIN | Your followers, the creators you follow, your contacts and pending requests. |
PUT | /api/me/profile | session · ADMIN / CREATOR / MEMBER | Updates the signed-in user's own profile. |
GET | /api/metrics | bearer token | Prometheus metrics, behind a bearer token (METRICS_AUTH_TOKEN). |
GET | /api/payments/gateways | public | The gateways a buyer can pay through on this deployment. |
GET | /api/platform/treasury | session · ADMIN | Platform revenue, computed from the ledger only (administrators). |
GET | /api/playlists | session · MEMBER / CREATOR / ADMIN | Your playlists, most recently changed first. |
POST | /api/playlists | session · MEMBER / CREATOR / ADMIN | Creates a playlist. |
DELETE | /api/playlists/[id] | session · MEMBER / CREATOR / ADMIN | Deletes a playlist (owner only). |
GET | /api/playlists/[id] | public · session-aware | A collection and its videos, for a viewer its permission admits (others get a 404). |
PATCH | /api/playlists/[id] | session · MEMBER / CREATOR / ADMIN | Renames a collection, edits its description or who may open it (owner only). |
DELETE | /api/playlists/[id]/items | session · MEMBER / CREATOR / ADMIN | Removes a video from a playlist (owner only). |
POST | /api/playlists/[id]/items | session · MEMBER / CREATOR / ADMIN | Adds a video at the end of a playlist (owner only, idempotent). |
GET | /api/playlists/shared | session · MEMBER / CREATOR / ADMIN | Collections other accounts invited you to. |
GET | /api/search | public | — |
POST | /api/uploads | session · role depends on the request | Stores an avatar (any account), a thumbnail or a 2257 document (creators); size and type checked per kind. |
DELETE | /api/videos/[id] | session · CREATOR | The creator deletes their video. |
PATCH | /api/videos/[id] | session · CREATOR | The creator edits their video: title, description, visibility, unlock price, tags, comments open. |
GET | /api/videos/[id]/comments | public · session-aware | The comments of a video you may watch, oldest first; removed ones keep their place without text. |
POST | /api/videos/[id]/comments | session · MEMBER / CREATOR / ADMIN | Comments on a video you may watch, or replies to one of its comments. |
DELETE | /api/videos/[id]/comments/[commentId] | session · MEMBER / CREATOR / ADMIN | Removes a comment: its author, the video's creator or an operator. |
GET | /api/videos/[id]/details | public · session-aware | A video's public metadata and figures (and whether you liked it); the stream is only served by /stream. |
DELETE | /api/videos/[id]/like | session · MEMBER / CREATOR / ADMIN | Removes your like (idempotent). |
POST | /api/videos/[id]/like | session · MEMBER / CREATOR / ADMIN | Likes a video you may watch (idempotent). |
POST | /api/videos/[id]/shares | public · session-aware | Counts a share of a video you may watch; the shared link still enforces the video's access. |
GET | /api/videos/[id]/stream | public · session-aware | Authorises a viewer and returns a short-lived signed HLS URL (AGENTS.md §2.A). |
POST | /api/videos/create-upload-session | public · session-aware | — |
POST | /api/videos/unlock-video | session · MEMBER / CREATOR / ADMIN | Starts the purchase of a video unlock. |
POST | /api/webhooks/bunny | signed webhook | Bunny Stream encoding events (https://bunny.net/docs/stream/webhooks), signed v1 with the library's Read-Only API key (BUNNY_WEBHOOK_SECRET). |
POST | /api/webhooks/payments/[gateway] | signed webhook | Gateway payment notifications. |
Database tables (23)
| Table | Drizzle export | Defined in |
|---|---|---|
audience_lists | audienceLists | packages/db/src/schema/audiences.ts |
audience_list_members | audienceListMembers | packages/db/src/schema/audiences.ts |
video_viewers | videoViewers | packages/db/src/schema/audiences.ts |
video_audience_lists | videoAudienceLists | packages/db/src/schema/audiences.ts |
playlist_audience_lists | playlistAudienceLists | packages/db/src/schema/audiences.ts |
auth_tokens | authTokens | packages/db/src/schema/auth-tokens.ts |
compliance_reports | complianceReports | packages/db/src/schema/compliance.ts |
contacts | contacts | packages/db/src/schema/contacts.ts |
follows | follows | packages/db/src/schema/contacts.ts |
video_views | videoViews | packages/db/src/schema/engagement.ts |
video_likes | videoLikes | packages/db/src/schema/engagement.ts |
video_comments | videoComments | packages/db/src/schema/engagement.ts |
video_shares | videoShares | packages/db/src/schema/engagement.ts |
tips_ledger | tipsLedger | packages/db/src/schema/ledger.ts |
payment_intents | paymentIntents | packages/db/src/schema/ledger.ts |
payout_requests | payoutRequests | packages/db/src/schema/ledger.ts |
playlists | playlists | packages/db/src/schema/playlists.ts |
playlist_items | playlistItems | packages/db/src/schema/playlists.ts |
playlist_members | playlistMembers | packages/db/src/schema/playlists.ts |
users | users | packages/db/src/schema/users.ts |
profiles | profiles | packages/db/src/schema/users.ts |
videos | videos | packages/db/src/schema/videos.ts |
video_access_grants | videoAccessGrants | packages/db/src/schema/videos.ts |