Admin API overview
How the admin dashboard talks to MCDI: the admin session it needs and every endpoint at a glance, grouped by area.
These endpoints serve the admin dashboard and are not meant for projects. They need an admin session, a system administrator signed in with Discord. The dashboard sends the session as a cookie; in Swagger you give it as a Bearer token.
The endpoints for projects are in the Project API.
79 endpoints in 14 groups.
Admin Settings
| Method | Path | Summary |
|---|---|---|
GET | /api/admin/profile | Get the current admin profile |
PATCH | /api/admin/profile | Update the admin profile |
GET | /api/admin/settings | Get effective system settings |
PATCH | /api/admin/settings | Update editable settings |
POST | /api/admin/settings/reset | Reset editable settings to environment defaults |
Audit
| Method | Path | Summary |
|---|---|---|
GET | /api/admin/audit/logs | Get audit logs |
GET | /api/admin/audit/logs/export | Export audit logs as CSV |
Authentication
| Method | Path | Summary |
|---|---|---|
GET | /api/auth/admin/discord | Initiate system admin Discord OAuth2 login |
POST | /api/auth/admin/logout | Log out of the admin dashboard |
GET | /api/auth/admin/me | Get current system admin profile |
POST | /api/auth/cleanup | Cleanup expired sessions (maintenance) |
Channels
| Method | Path | Summary |
|---|---|---|
GET | /api/admin/servers/{serverId}/channels | List all channels in a server (admin session) |
GET | /api/admin/servers/{serverId}/channels/{channelId} | Get channel details (admin session) |
GET | /api/admin/servers/{serverId}/channels/{channelId}/messages | Get recent messages from a channel (admin session) |
Inbound Webhooks (Admin)
| Method | Path | Summary |
|---|---|---|
GET | /api/admin/inbound-webhooks | List inbound webhooks |
POST | /api/admin/inbound-webhooks | Create an inbound webhook |
POST | /api/admin/inbound-webhooks/schema/preview | Check a schema and preview its docs |
GET | /api/admin/inbound-webhooks/settings | Get the inbound webhook settings |
PUT | /api/admin/inbound-webhooks/settings | Replace the default reader roles |
GET | /api/admin/inbound-webhooks/{id} | Get one inbound webhook |
PATCH | /api/admin/inbound-webhooks/{id} | Update an inbound webhook |
DELETE | /api/admin/inbound-webhooks/{id} | Delete an inbound webhook and all its submissions |
GET | /api/admin/inbound-webhooks/{id}/docs | Export developer documentation for this webhook |
GET | /api/admin/inbound-webhooks/{id}/roles | List the Discord roles permitted to read submissions |
PUT | /api/admin/inbound-webhooks/{id}/roles | Replace the read-access role grants |
POST | /api/admin/inbound-webhooks/{id}/rotate-secret | Rotate the signing secret |
Inbound Webhooks (Read)
| Method | Path | Summary |
|---|---|---|
GET | /api/inbound-webhooks | List the inbound webhooks I am permitted to read |
GET | /api/inbound-webhooks/{id}/submissions | List submissions |
GET | /api/inbound-webhooks/{id}/submissions/{submissionId} | Get one submission |
Members
| Method | Path | Summary |
|---|---|---|
GET | /api/admin/members | List members with optional server, role, filter and search criteria (paginated) |
GET | /api/admin/members/cross-server | List members across servers (paginated) |
GET | /api/admin/members/export | Export members report |
GET | /api/admin/members/{discordId}/servers | Get member cross-server view |
Monitoring
| Method | Path | Summary |
|---|---|---|
GET | /api/admin/monitoring/auth-failures | Recent authentication failures |
GET | /api/admin/monitoring/health | System health check |
GET | /api/admin/monitoring/usage | API usage statistics |
Permissions
| Method | Path | Summary |
|---|---|---|
POST | /api/permissions/admin/servers/{serverId}/roles/{roleId}/impact | Preview impact of a permission change on a role |
GET | /api/permissions/admin/servers/{serverId}/roles/{roleId}/permissions | Get all permissions assigned to a role |
POST | /api/permissions/admin/servers/{serverId}/roles/{roleId}/permissions | Add permissions to a role |
DELETE | /api/permissions/admin/servers/{serverId}/roles/{roleId}/permissions/{permissionId} | Remove a permission from a role |
GET | /api/permissions/inheritance-rules | List inheritance rules |
POST | /api/permissions/inheritance-rules | Create or update an inheritance rule |
Projects
| Method | Path | Summary |
|---|---|---|
GET | /api/admin/projects | List all projects |
POST | /api/admin/projects | Create a project |
GET | /api/admin/projects/access/audit | List access change audit logs |
GET | /api/admin/projects/access/matrix | List full project-server access matrix |
GET | /api/admin/projects/servers/{serverId}/projects | List projects that can access a server |
GET | /api/admin/projects/{id} | Get a project by ID |
PATCH | /api/admin/projects/{id} | Update a project |
DELETE | /api/admin/projects/{id} | Delete a project |
GET | /api/admin/projects/{id}/api-key | Reveal project API key info |
DELETE | /api/admin/projects/{id}/key | Revoke API key |
PATCH | /api/admin/projects/{id}/redirect-uri | Update allowed redirect URI(s) |
POST | /api/admin/projects/{id}/regenerate-api-key | Regenerate project API key (admin) |
POST | /api/admin/projects/{id}/restore-key | Restore a revoked API key |
GET | /api/admin/projects/{projectId}/servers | List servers accessible by a project |
PUT | /api/admin/projects/{projectId}/servers/{serverId} | Grant or update project access to a server |
DELETE | /api/admin/projects/{projectId}/servers/{serverId} | Revoke project access to a server |
Servers
| Method | Path | Summary |
|---|---|---|
GET | /api/servers | List all servers |
POST | /api/servers | Register a server |
GET | /api/servers/{serverId} | Get a server by ID |
PATCH | /api/servers/{serverId} | Update server settings |
DELETE | /api/servers/{serverId} | Delete a server |
PATCH | /api/servers/{serverId}/disable | Disable a server |
PATCH | /api/servers/{serverId}/enable | Enable a server |
Statistics
| Method | Path | Summary |
|---|---|---|
GET | /api/admin/stats/cross-server | Cross-server member overlap |
GET | /api/admin/stats/export | Export a statistics report as CSV or JSON |
GET | /api/admin/stats/members | Aggregate member statistics |
GET | /api/admin/stats/members/growth | Member growth over time |
GET | /api/admin/stats/roles | Role distribution (scoped or cross-server) |
GET | /api/admin/stats/servers | Server-level statistics |
Sync
| Method | Path | Summary |
|---|---|---|
POST | /api/admin/sync/full | Trigger a full sync |
GET | /api/admin/sync/logs | Get paginated sync logs for a server |
GET | /api/admin/sync/logs/{syncLogId}/changes | Get granular change details for a specific sync log |
GET | /api/admin/sync/status | Get the latest sync status for a specific server |
GET | /api/admin/sync/status/all | Get latest sync status for all active servers |
Webhooks
| Method | Path | Summary |
|---|---|---|
GET | /api/admin/projects/{projectId}/webhooks | List a project's webhooks (admin session) |
GET | /api/admin/webhooks/{webhookId} | Get webhook details (admin session) |
DELETE | /api/admin/webhooks/{webhookId} | Delete a webhook (admin session) |
Source: apps/api/openapi.json.