This repository has been archived on 2026-08-11. You can view files and clone it, but cannot push or open issues or pull requests.
Gishen-B2B/docs/backend/endpoints/README.md
kirukib 8fe6d58a09 Document portal auth, profile, and pharmacy ID contracts in backend specs.
Keep the living API sheet aligned with demo personas, avatars, ID-card QR scan, list filters, and Admin/Ecom coordination.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-06 22:10:07 +03:00

1.8 KiB

Endpoints index

REST-style API contract for Gishen-B2B. All paths prefixed with /v1 unless noted.

Workspace: /Users/kirukib/Desktop/Yaltopia Project/Gishen-B2B

Domain groups

Group Doc Description
Auth auth.md Demo login personas, session, locale, /me/profile
Organisation org.md Org profile, registration, departments, verification
Members members.md CRUD, import, invites, join, pharmacy ID card
Packages packages.md Benefit plans
Migration migration.md Bulk import jobs
Finance finance.md Spend, statements, approvals
Prescriptions prescriptions.md Member Rx upload/status

Conventions

Auth header

Authorization: Bearer <token>

Mock phase: session cookie gishen_b2b_session.

Org scope

Implicit from session org_id. Public routes (registration) omit org scope.

Response envelope

Single resource:

{ "data": { ... } }

List (see OVERVIEW.md):

{ "data": [ ... ], "pagination": { ... } }

Clinical withhold

Endpoints returning prescription or order clinical detail check session roles. HR_ADMIN / FINANCE without SUPER_USER receive redacted payloads or 403 CLINICAL_WITHHELD.

Public vs authenticated

Path pattern Auth
/v1/auth/login Public
/v1/auth/demo-profiles Public
/v1/org/register* Public
/v1/invite/:token (GET) Public
/v1/join (POST) Public or member session
All other /v1/* Required

Error reference

See OVERVIEW.md.

Mock implementation

Frontend mocks in src/mocks/ and adapters in src/lib/api/ must match these contracts exactly.