What is here
Authentication
Discord sign-in, the session cookie, service credentials and Developer Access.
Quickstart
Make a first authenticated request and read the response envelope.
Permissions
Every permission key, what it allows, and which endpoints check it.
Errors
The error envelope, status codes and what a 409 means.
api-reference/openapi.json, kept next to these pages. It lists all 86 implemented operations with their permissions, parameters, request and response shapes, examples and errors.
API areas
Conventions at a glance
- Every path is under
/apion the deployment’s own origin. - Requests and responses are JSON. Timestamps are UTC, ISO-8601.
- Success responses are wrapped as
{ "data": ... }, withmetaon lists. Failures are{ "error": { "code", "message" }, "requestId" }. - Permissions are checked on the server for every request. What the web application shows or hides is never the boundary.