API: Account
Session login, API key, notifications. No JWT, no OAuth.
Every HTML route returns JSON with Accept: application/json. Authentication: session cookie, X-API-KEY, Authorization: Bearer or Basic.
GET
Login page
/auth/loginguestcurl -X GET -H 'Accept: application/json' 'http://staging.app.molodetz.nl/auth/login'
const response = await fetch("/auth/login", { method: "GET", headers: { "Accept": "application/json" } });
console.log(await response.json());
import httpx
print(httpx.request("GET", BASE + "/auth/login", headers={"Accept": "application/json", "X-API-KEY": API_KEY}).json())
{
"errors": [],
"next": "/admin"
}
Not sent yet.
POST
Log in
/auth/loginguestSets an httponly session cookie (7 days, 30 with remember me).
| Field | Type | Location | Required |
|---|---|---|---|
username | string | body | yes |
password | password | body | yes |
remember | boolean | body | no |
curl -X POST -H 'Accept: application/json' -H 'Content-Type: application/json' -d '{"username": "retoor"}' 'http://staging.app.molodetz.nl/auth/login'
const response = await fetch("/auth/login", { method: "POST", headers: { "Accept": "application/json" } });
console.log(await response.json());
import httpx
print(httpx.request("POST", BASE + "/auth/login", headers={"Accept": "application/json", "X-API-KEY": API_KEY}).json())
{
"data": null,
"ok": true,
"redirect": "/admin"
}
POST
Log out
/auth/logoutguestcurl -X POST -H 'Accept: application/json' 'http://staging.app.molodetz.nl/auth/logout'
const response = await fetch("/auth/logout", { method: "POST", headers: { "Accept": "application/json" } });
console.log(await response.json());
import httpx
print(httpx.request("POST", BASE + "/auth/logout", headers={"Accept": "application/json", "X-API-KEY": API_KEY}).json())
{
"data": null,
"ok": true,
"redirect": "/"
}
GET
View API key
/profile/api-keyMembercurl -X GET -H 'Accept: application/json' -H 'X-API-KEY: YOUR_API_KEY' 'http://staging.app.molodetz.nl/profile/api-key'
const response = await fetch("/profile/api-key", { method: "GET", headers: { "Accept": "application/json" } });
console.log(await response.json());
import httpx
print(httpx.request("GET", BASE + "/profile/api-key", headers={"Accept": "application/json", "X-API-KEY": API_KEY}).json())
{
"api_key": "{{api_key}}"
}
Not sent yet.
POST
Renew API key
/profile/api-key/regenerateMembercurl -X POST -H 'Accept: application/json' -H 'X-API-KEY: YOUR_API_KEY' 'http://staging.app.molodetz.nl/profile/api-key/regenerate'
const response = await fetch("/profile/api-key/regenerate", { method: "POST", headers: { "Accept": "application/json" } });
console.log(await response.json());
import httpx
print(httpx.request("POST", BASE + "/profile/api-key/regenerate", headers={"Accept": "application/json", "X-API-KEY": API_KEY}).json())
{
"data": {
"api_key": "..."
},
"ok": true,
"redirect": "/profile/api-key"
}
POST
Renew avatar
/profile/avatar/regenerateMembercurl -X POST -H 'Accept: application/json' -H 'X-API-KEY: YOUR_API_KEY' 'http://staging.app.molodetz.nl/profile/avatar/regenerate'
const response = await fetch("/profile/avatar/regenerate", { method: "POST", headers: { "Accept": "application/json" } });
console.log(await response.json());
import httpx
print(httpx.request("POST", BASE + "/profile/avatar/regenerate", headers={"Accept": "application/json", "X-API-KEY": API_KEY}).json())
{
"ok": true
}
GET
Notifications
/notificationsMembercurl -X GET -H 'Accept: application/json' -H 'X-API-KEY: YOUR_API_KEY' 'http://staging.app.molodetz.nl/notifications'
const response = await fetch("/notifications", { method: "GET", headers: { "Accept": "application/json" } });
console.log(await response.json());
import httpx
print(httpx.request("GET", BASE + "/notifications", headers={"Accept": "application/json", "X-API-KEY": API_KEY}).json())
{
"notifications": [],
"unread": 0
}
Not sent yet.
POST
Mark all read
/notifications/readMembercurl -X POST -H 'Accept: application/json' -H 'X-API-KEY: YOUR_API_KEY' 'http://staging.app.molodetz.nl/notifications/read'
const response = await fetch("/notifications/read", { method: "POST", headers: { "Accept": "application/json" } });
console.log(await response.json());
import httpx
print(httpx.request("POST", BASE + "/notifications/read", headers={"Accept": "application/json", "X-API-KEY": API_KEY}).json())
{
"ok": true,
"redirect": "/notifications"
}
Not sent yet.
GET
Terms
/termsguestcurl -X GET -H 'Accept: application/json' 'http://staging.app.molodetz.nl/terms'
const response = await fetch("/terms", { method: "GET", headers: { "Accept": "application/json" } });
console.log(await response.json());
import httpx
print(httpx.request("GET", BASE + "/terms", headers={"Accept": "application/json", "X-API-KEY": API_KEY}).json())
{
"title": "Terms"
}
Not sent yet.
POST
Accept terms
/terms/acceptMembercurl -X POST -H 'Accept: application/json' -H 'X-API-KEY: YOUR_API_KEY' 'http://staging.app.molodetz.nl/terms/accept'
const response = await fetch("/terms/accept", { method: "POST", headers: { "Accept": "application/json" } });
console.log(await response.json());
import httpx
print(httpx.request("POST", BASE + "/terms/accept", headers={"Accept": "application/json", "X-API-KEY": API_KEY}).json())
{
"ok": true,
"redirect": "/"
}
Not sent yet.
GET
Privacy
/privacyguestcurl -X GET -H 'Accept: application/json' 'http://staging.app.molodetz.nl/privacy'
const response = await fetch("/privacy", { method: "GET", headers: { "Accept": "application/json" } });
console.log(await response.json());
import httpx
print(httpx.request("GET", BASE + "/privacy", headers={"Accept": "application/json", "X-API-KEY": API_KEY}).json())
{
"title": "Privacy"
}
Not sent yet.