Furries PH Docs
Dashboard
Platform API docs

Foundations

Environments and Bindings

Worker bindings, secrets, local development variables, and external systems used by partners-api.

First created Last updated

End-to-end developer runbook

  1. Step 1 - Confirm the API area: Identify the product area, route module, endpoint path, and consumer before writing or calling code.
  2. Step 2 - Read the endpoint contract: Check method, auth, parameters, response, errors, side effects, and related docs.
  3. Step 3 - Prepare authentication and input: Use the right session, bearer token, webhook secret, or internal header. Validate body and query data before sending it.
  4. Step 4 - Make the request: Call the endpoint from the correct origin and environment. Keep credentials and secrets out of logs.
  5. Step 5 - Verify response, side effects, and records: Confirm status code, response shape, database records, external side effects, and audit evidence.
  6. Step 6 - Add tests, docs, and handoff notes: Update route inventory, consumer notes, and certification checks before depending on the change.

Binding groups

  1. Action 1 - Core database: SUPABASE_URL, SUPABASE_ANON_KEY, SUPABASE_SECRET_KEY, SUPABASE_SERVICE_ROLE_KEY, and SUPABASE_JWT_SECRET.
  2. Action 2 - Origins and apps: ALLOWED_ORIGIN, DASHBOARD_URL, SITE_URL, and REGO_URL.
  3. Action 3 - CMS and media: CMS_GATE_SECRET, CMS_JWT_SECRET, CMS_TOKENS, SANITY_MEDIA_PROJECT_ID, SANITY_MEDIA_DATASET, SANITY_MEDIA_TOKEN, SANITY_PROJECT_ID, and SANITY_API_TOKEN.
  4. Action 4 - Mail and hooks: CONTACT_TO_EMAIL, CONTACT_FROM_EMAIL, FPH_SUPPORT_EMAIL, GAS_EMAIL_WEBHOOK_URL, GAS_EMAIL_WEBHOOK_SECRET, and SUPABASE_AUTH_HOOK_SECRET.
  5. Action 5 - Internal controls: CRON_SECRET, TEST_CONTROL_SECRET, STRESS_TEST_SUPPRESS_SIDE_EFFECTS.
  6. Action 6 - Integrations: Google Wallet, Discord, Telegram, social-link state, partner DB config encryption, and LAN release GitHub bindings.

All docs