# Endpoints index REST-style API contract for Gishen-B2B. All paths prefixed with `/v1` unless noted. **Workspace:** `/Users/kirukib/Desktop/Yaltopia Project/Gishen-B2B` ## Domain groups | Group | Doc | Description | |-------|-----|-------------| | Auth | [auth.md](auth.md) | Demo login + planned Google/email/phone/Telegram, session, locale, `/me/profile` | | Organisation | [org.md](org.md) | Org profile, registration, departments, verification | | Members | [members.md](members.md) | CRUD, import, invites, join, pharmacy ID card | | Packages | [packages.md](packages.md) | Benefit plans | | Migration | [migration.md](migration.md) | Bulk import jobs | | Finance | [finance.md](finance.md) | Spend, statements, approvals | | Prescriptions | [prescriptions.md](prescriptions.md) | Member Rx upload/status | ## Conventions ### Auth header ``` Authorization: Bearer ``` Mock phase: session cookie `gishen_b2b_session`. ### Org scope Implicit from session `org_id`. Public routes (registration) omit org scope. ### Response envelope Single resource: ```json { "data": { ... } } ``` List (see [OVERVIEW.md](../OVERVIEW.md#pagination)): ```json { "data": [ ... ], "pagination": { ... } } ``` ### Clinical withhold Endpoints returning prescription or order clinical detail check session roles. HR_ADMIN / FINANCE without SUPER_USER receive redacted payloads or `403 CLINICAL_WITHHELD`. ## Public vs authenticated | Path pattern | Auth | |--------------|------| | `/v1/auth/login` | Public | | `/v1/auth/demo-profiles` | Public | | `/v1/org/register*` | Public | | `/v1/invite/:token` (GET) | Public | | `/v1/join` (POST) | Public or member session | | All other `/v1/*` | Required | ## Error reference See [OVERVIEW.md](../OVERVIEW.md#error-model). ## Mock implementation Frontend mocks in `src/mocks/` and adapters in `src/lib/api/` must match these contracts exactly.