Furries PH Docs
Dashboard
Platform API docs

Getting Started

Local Development

Numbered workflow for running partners-api locally and verifying routes before integration.

First created Last updated

End-to-end developer runbook

  1. Step 1 - Confirm the API area: Identify the product area, route module, endpoint path, and consumer before writing or calling code.
  2. Step 2 - Read the endpoint contract: Check method, auth, parameters, response, errors, side effects, and related docs.
  3. Step 3 - Prepare authentication and input: Use the right session, bearer token, webhook secret, or internal header. Validate body and query data before sending it.
  4. Step 4 - Make the request: Call the endpoint from the correct origin and environment. Keep credentials and secrets out of logs.
  5. Step 5 - Verify response, side effects, and records: Confirm status code, response shape, database records, external side effects, and audit evidence.
  6. Step 6 - Add tests, docs, and handoff notes: Update route inventory, consumer notes, and certification checks before depending on the change.

Local workflow

  1. Step 1 - Install dependencies: Run the package manager used by partners-api/package.json.
  2. Step 2 - Prepare local variables: Use local secret files and Worker bindings. Do not copy production secrets into browser-accessible code.
  3. Step 3 - Start the Worker: Run the repo’s Wrangler development command and note the local API origin.
  4. Step 4 - Call a health or harmless GET route: Verify CORS, JSON responses, and logs before mutating records.
  5. Step 5 - Test from the real consumer: Call from dashboard or rego local origins so cookie and CORS behavior is proven.
  6. Step 6 - Record evidence: Keep command output, route, payload, response, and affected record IDs in the task notes.

Common mistakes

  1. Action 1 - Wrong origin: CORS allows configured origins plus localhost development ports only when request URL is local.
  2. Action 2 - Wrong auth family: Dashboard and rego auth are not interchangeable.
  3. Action 3 - Missing side-effect suppression: Stress or test runs must not send real email, Discord, Telegram, wallet, or deployment side effects unless explicitly intended.

All docs