Route Reference
Authentication
Dashboard auth, Supabase Auth hooks, access checks, session helpers, and permission discovery. Includes generated endpoint contracts from partners-api source.
First created Last updated
End-to-end developer runbook
- Step 1 - Confirm the API area: Identify the product area, route module, endpoint path, and consumer before writing or calling code.
- Step 2 - Read the endpoint contract: Check method, auth, parameters, response, errors, side effects, and related docs.
- Step 3 - Prepare authentication and input: Use the right session, bearer token, webhook secret, or internal header. Validate body and query data before sending it.
- Step 4 - Make the request: Call the endpoint from the correct origin and environment. Keep credentials and secrets out of logs.
- Step 5 - Verify response, side effects, and records: Confirm status code, response shape, database records, external side effects, and audit evidence.
- Step 6 - Add tests, docs, and handoff notes: Update route inventory, consumer notes, and certification checks before depending on the change.
Family summary
Dashboard auth, Supabase Auth hooks, access checks, session helpers, and permission discovery.
Modules audited
auth.ts: 20 generated endpoint entries.authEmail.ts: 1 generated endpoint entries.access.ts: 5 generated endpoint entries.
Endpoint table
| Method | Path | Module | Auth scan | Source |
|---|---|---|---|---|
GET | /api/access | access.ts | Partner dashboard session required. | partners-api/src/routes/access.ts:31 |
GET | /api/cms-token | access.ts | Unknown from source scan; inspect middleware and handler body before use. | partners-api/src/routes/access.ts:280 |
GET | /api/partner-directory | access.ts | Partner dashboard session required. | partners-api/src/routes/access.ts:257 |
GET | /api/partner-permissions | access.ts | Partner dashboard session required. | partners-api/src/routes/access.ts:177 |
PUT | /api/partner-permissions/members/:userId | access.ts | Partner dashboard session required. | partners-api/src/routes/access.ts:194 |
POST | /auth/accept-invite | auth.ts | Dashboard auth flow or auth helper route; inspect handler for exact cookie and Supabase behavior. | partners-api/src/routes/auth.ts:797 |
POST | /auth/change-password | auth.ts | Dashboard auth flow or auth helper route; inspect handler for exact cookie and Supabase behavior. | partners-api/src/routes/auth.ts:730 |
POST | /auth/dev-session | auth.ts | Dashboard auth flow or auth helper route; inspect handler for exact cookie and Supabase behavior. | partners-api/src/routes/auth.ts:592 |
POST | /auth/exchange | auth.ts | Dashboard auth flow or auth helper route; inspect handler for exact cookie and Supabase behavior. | partners-api/src/routes/auth.ts:698 |
GET | /auth/mfa/status | auth.ts | Dashboard auth flow or auth helper route; inspect handler for exact cookie and Supabase behavior. | partners-api/src/routes/auth.ts:434 |
POST | /auth/mfa/totp/enroll | auth.ts | Dashboard auth flow or auth helper route; inspect handler for exact cookie and Supabase behavior. | partners-api/src/routes/auth.ts:480 |
POST | /auth/mfa/totp/unenroll | auth.ts | Dashboard auth flow or auth helper route; inspect handler for exact cookie and Supabase behavior. | partners-api/src/routes/auth.ts:554 |
POST | /auth/mfa/totp/verify | auth.ts | Dashboard auth flow or auth helper route; inspect handler for exact cookie and Supabase behavior. | partners-api/src/routes/auth.ts:511 |
POST | /auth/otp/send | auth.ts | Dashboard auth flow or auth helper route; inspect handler for exact cookie and Supabase behavior. | partners-api/src/routes/auth.ts:252 |
POST | /auth/otp/verify | auth.ts | Dashboard auth flow or auth helper route; inspect handler for exact cookie and Supabase behavior. | partners-api/src/routes/auth.ts:293 |
POST | /auth/passkey/authentication/options | auth.ts | Dashboard auth flow or auth helper route; inspect handler for exact cookie and Supabase behavior. | partners-api/src/routes/auth.ts:335 |
POST | /auth/passkey/authentication/verify | auth.ts | Dashboard auth flow or auth helper route; inspect handler for exact cookie and Supabase behavior. | partners-api/src/routes/auth.ts:354 |
POST | /auth/passkey/registration/options | auth.ts | Dashboard auth flow or auth helper route; inspect handler for exact cookie and Supabase behavior. | partners-api/src/routes/auth.ts:383 |
POST | /auth/passkey/registration/verify | auth.ts | Dashboard auth flow or auth helper route; inspect handler for exact cookie and Supabase behavior. | partners-api/src/routes/auth.ts:404 |
POST | /auth/refresh | auth.ts | Dashboard auth flow or auth helper route; inspect handler for exact cookie and Supabase behavior. | partners-api/src/routes/auth.ts:651 |
POST | /auth/reset-password | auth.ts | Dashboard auth flow or auth helper route; inspect handler for exact cookie and Supabase behavior. | partners-api/src/routes/auth.ts:900 |
POST | /auth/set-password | auth.ts | Dashboard auth flow or auth helper route; inspect handler for exact cookie and Supabase behavior. | partners-api/src/routes/auth.ts:926 |
POST | /auth/sign-in | auth.ts | Dashboard auth flow or auth helper route; inspect handler for exact cookie and Supabase behavior. | partners-api/src/routes/auth.ts:224 |
POST | /auth/sign-out | auth.ts | Dashboard auth flow or auth helper route; inspect handler for exact cookie and Supabase behavior. | partners-api/src/routes/auth.ts:766 |
POST | /auth/sign-up | auth.ts | Dashboard auth flow or auth helper route; inspect handler for exact cookie and Supabase behavior. | partners-api/src/routes/auth.ts:872 |
POST | /hooks/send-email | authEmail.ts | Webhook/internal route; inspect signature or shared secret verification before use. | partners-api/src/routes/authEmail.ts:868 |
Endpoint contract notes
- Action 1 - Verify unknowns: The table is source-generated, but fields marked unknown need manual handler review.
- Action 2 - Check source line: Use the source line as the starting point for exact request, response, and side-effect behavior.
- Action 3 - Review consumers: Search dashboard, rego, EMS LAN, and webhook callers before changing a path or response.
- Action 4 - Update inventory: Regenerate after any route change.