API and authentication
Every route has four faces: HTML, JSON, documentation and (where selected) an assistant tool. Ask for JSON with Accept: application/json.
Authentication
Resolution order:
sessioncookie (64 hex characters) after logging in at/auth/login.X-API-KEYheader with your API key.Authorization: Bearer <key>.Authorization: Basicwith name or email and password.
There is no JWT and no OAuth.
Example
curl -H 'Accept: application/json' https://molodetz.nl/roll
Errors
Errors have the shape {"error": {"status": 404, "message": "..."}}. Validation errors return 422 with {"error": "validation", "fields": [...], "messages": [...]}.
Invites
Membership starts from a join request plus an admin-issued invite. Admins call POST /admin/joins/{uid}/invite (returns claim_url and expires_at in data) and POST /admin/joins/{uid}/invite/revoke. The public claim is GET and POST /invite/{token} with username, email, password, password_confirm and terms. Claim links are single use and every dead link answers 404 with the same message.
Gallery
GET /admin/gallery reports live flyer and meme counts plus catalogued source files missing from disk. POST /admin/gallery/resync re-reads the sources and retires removed entries. See Galleries and content for how publishing works.
Old paths
The Dutch paths from before (/rol, /standaard, /mensen, /binnen, /voorwaarden) answer with a 301 to their English replacement. Query strings are kept.