Projects
Register projects, manage their API keys and redirect URIs, and grant or review their access to servers.
MC Project registration and server access grants - system admin only
List all projects
/api/admin/projectsAuthentication: Admin session token (Authorization: Bearer <token>)
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
isActive | query | boolean | no | Filter by active/inactive status. |
isInternal | query | boolean | no | Filter by internal/external project type. |
name | query | string | no | Filter by project name (case-insensitive partial match). |
Responses
| Status | Description | Body |
|---|---|---|
200 | Projects retrieved successfully. | |
400 | Invalid parameter. | |
401 | Authentication required. | |
403 | System Admin access required. |
Open in Swagger (opens in a new tab)
Create a project
/api/admin/projectsRegisters a new project and returns its API key. The full key is returned once and never stored - save it immediately.
Authentication: Admin session token (Authorization: Bearer <token>)
Request body (JSON, required): CreateProjectDto schema.
Responses
| Status | Description | Body |
|---|---|---|
201 | Project created. API key returned once. | any |
400 | Validation error. | |
401 | Authentication required. | |
403 | System Admin access required. |
Open in Swagger (opens in a new tab)
List access change audit logs
/api/admin/projects/access/auditAuthentication: Admin session token (Authorization: Bearer <token>)
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
limit | query | number | no | Max entries to return (1-500, default 100). |
projectId | query | string | no | Filter by project ID. |
serverId | query | string | no | Filter by server ID. |
action | query | "GRANT" or "UPDATE" or "REVOKE" | no | Filter by audit action type. |
Responses
| Status | Description | Body |
|---|---|---|
200 | Audit logs retrieved successfully. | |
400 | Invalid limit parameter. | |
401 | Authentication required. | |
403 | System Admin access required. |
Open in Swagger (opens in a new tab)
List full project-server access matrix
/api/admin/projects/access/matrixReturns every project-server mapping including operations and per-server scopes.
Authentication: Admin session token (Authorization: Bearer <token>)
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
projectId | query | string | no | Filter by project ID. |
serverId | query | string | no | Filter by server ID. |
scope | query | "read_members" or "check_permissions" | no | Filter by scope. |
projectName | query | string | no | Filter by project name (partial, case-insensitive). |
Responses
| Status | Description | Body |
|---|---|---|
200 | Access matrix retrieved successfully. | any |
400 | Invalid parameter. | |
401 | Authentication required. | |
403 | System Admin access required. |
Open in Swagger (opens in a new tab)
List projects that can access a server
/api/admin/projects/servers/{serverId}/projectsAuthentication: Admin session token (Authorization: Bearer <token>)
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
serverId | path | string | yes | Discord server ID |
scope | query | "read_members" or "check_permissions" | no | Filter projects by required scope. |
isActive | query | boolean | no | Filter by project active status. |
Responses
| Status | Description | Body |
|---|---|---|
200 | Project mappings retrieved successfully. | |
400 | Invalid server ID format. | |
401 | Authentication required. | |
403 | System Admin access required. |
Open in Swagger (opens in a new tab)
Get a project by ID
/api/admin/projects/{id}Authentication: Admin session token (Authorization: Bearer <token>)
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
id | path | string | yes | Project UUID |
Responses
| Status | Description | Body |
|---|---|---|
200 | Project retrieved successfully. | |
400 | Invalid project ID format. | |
401 | Authentication required. | |
403 | System Admin access required. | |
404 | Project not found. |
Open in Swagger (opens in a new tab)
Update a project
/api/admin/projects/{id}Authentication: Admin session token (Authorization: Bearer <token>)
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
id | path | string | yes | Project UUID |
Request body (JSON, required): UpdateProjectDto schema.
Responses
| Status | Description | Body |
|---|---|---|
200 | Project updated successfully. | |
400 | Invalid project ID or request body. | |
401 | Authentication required. | |
403 | System Admin access required. | |
404 | Project not found. |
Open in Swagger (opens in a new tab)
Delete a project
/api/admin/projects/{id}Authentication: Admin session token (Authorization: Bearer <token>)
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
id | path | string | yes | Project UUID |
Responses
| Status | Description | Body |
|---|---|---|
204 | Project deleted. | |
400 | Invalid project ID format. | |
401 | Authentication required. | |
403 | System Admin access required. | |
404 | Project not found. |
Open in Swagger (opens in a new tab)
Reveal project API key info
/api/admin/projects/{id}/api-keyReturns the API key prefix and metadata. The full secret cannot be recovered - use POST :id/regenerate-api-key to generate a new one.
Authentication: Admin session token (Authorization: Bearer <token>)
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
id | path | string | yes | Project UUID |
Responses
| Status | Description | Body |
|---|---|---|
200 | API key info retrieved. | any |
400 | Invalid project ID format. | |
401 | Authentication required. | |
403 | System Admin access required. | |
404 | Project not found. |
Open in Swagger (opens in a new tab)
Revoke API key
/api/admin/projects/{id}/keyAuthentication: Admin session token (Authorization: Bearer <token>)
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
id | path | string | yes | Project UUID |
Responses
| Status | Description | Body |
|---|---|---|
204 | API key revoked. | |
400 | Invalid project ID format. | |
401 | Authentication required. | |
403 | System Admin access required. | |
404 | Project not found. |
Open in Swagger (opens in a new tab)
Update allowed redirect URI(s)
/api/admin/projects/{id}/redirect-uriSets the redirect URI(s) allowed for this project. Accepts a single URI or a comma-separated list. The value passed to GET /auth/authorize must exactly match one of these.
Authentication: Admin session token (Authorization: Bearer <token>)
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
id | path | string | yes | Project UUID |
Request body (JSON, required): UpdateRedirectUriDto schema.
Responses
| Status | Description | Body |
|---|---|---|
200 | Redirect URI updated. | object |
400 | Invalid project ID or redirect URI. | |
401 | Authentication required. | |
403 | System Admin access required. | |
404 | Project not found. |
Open in Swagger (opens in a new tab)
Regenerate project API key (admin)
/api/admin/projects/{id}/regenerate-api-keyGenerates a new API key. The old key is immediately invalidated. Returns full key metadata.
Authentication: Admin session token (Authorization: Bearer <token>)
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
id | path | string | yes | Project UUID |
Responses
| Status | Description | Body |
|---|---|---|
200 | API key regenerated successfully. | object |
400 | Invalid project ID format. | |
401 | Authentication required. | |
403 | System Admin access required. | |
404 | Project not found. |
Open in Swagger (opens in a new tab)
Restore a revoked API key
/api/admin/projects/{id}/restore-keyAuthentication: Admin session token (Authorization: Bearer <token>)
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
id | path | string | yes | Project UUID |
Responses
| Status | Description | Body |
|---|---|---|
204 | API key restored. | |
400 | Invalid project ID format. | |
401 | Authentication required. | |
403 | System Admin access required. | |
404 | Project not found. |
Open in Swagger (opens in a new tab)
List servers accessible by a project
/api/admin/projects/{projectId}/serversAuthentication: Admin session token (Authorization: Bearer <token>)
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
projectId | path | string | yes | Project UUID |
scope | query | "read_members" or "check_permissions" | no | Filter servers by required scope. |
Responses
| Status | Description | Body |
|---|---|---|
200 | Server mappings retrieved successfully. | any |
400 | Invalid project ID format. | |
401 | Authentication required. | |
403 | System Admin access required. |
Open in Swagger (opens in a new tab)
Grant or update project access to a server
/api/admin/projects/{projectId}/servers/{serverId}Creates or updates the access mapping between a project and a server. You can set both the allowed operations and the scopes per server. If scopes are omitted, existing scopes are preserved (or all scopes are granted for new mappings).
Authentication: Admin session token (Authorization: Bearer <token>)
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
projectId | path | string | yes | Project UUID |
serverId | path | string | yes | Discord server ID |
Request body (JSON, required): SetProjectServerAccessDto schema.
Responses
| Status | Description | Body |
|---|---|---|
200 | Access mapping upserted. | any |
400 | Invalid project or server ID format. | |
401 | Authentication required. | |
403 | System Admin access required. | |
404 | Project or server not found. |
Open in Swagger (opens in a new tab)
Revoke project access to a server
/api/admin/projects/{projectId}/servers/{serverId}Authentication: Admin session token (Authorization: Bearer <token>)
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
projectId | path | string | yes | Project UUID |
serverId | path | string | yes | Discord server ID |
Responses
| Status | Description | Body |
|---|---|---|
200 | Access mapping revoked. | |
400 | Invalid project or server ID format. | |
401 | Authentication required. | |
403 | System Admin access required. | |
404 | Access mapping not found. |
Open in Swagger (opens in a new tab)
Schemas
AccessOperationsDto schema
| Field | Type | Required | Description |
|---|---|---|---|
MANAGE_WEBHOOKS | boolean | no | Default: false. |
READ | boolean | no | Default: true. |
SEND_MESSAGES | boolean | no | Default: false. |
CreateProjectDto schema
| Field | Type | Required | Description |
|---|---|---|---|
description | string | no | |
isActive | boolean | no | Whether the project is active. Defaults to true. |
isInternal | boolean | no | Whether this is an internal MicroClub platform project. Internal projects use the main server automatically. Defaults to false. |
name | string | yes | |
serverAccess | array of ProjectServerAccessDto | no | Server access configurations. If omitted, the project is automatically granted all available scopes to all servers where is_main = true. |
webhookUrl | string (uri) | no | Optional Discord webhook URL for this project. |
ProjectServerAccessDto schema
| Field | Type | Required | Description |
|---|---|---|---|
scopes | array of "read_members" or "check_permissions" | no | Scopes to grant for this server. If omitted, all available scopes are granted. |
serverId | string | yes |
SetProjectServerAccessDto schema
| Field | Type | Required | Description |
|---|---|---|---|
operations | AccessOperationsDto | no | |
scopes | array of "read_members" or "check_permissions" | no | Scopes granted to this project for this server. If omitted, defaults to all available scopes. |
UpdateProjectDto schema
| Field | Type | Required | Description |
|---|---|---|---|
description | string | no | |
isActive | boolean | no | Whether the project is active. |
isInternal | boolean | no | Whether this is an internal MicroClub platform project. |
name | string | no | |
webhookUrl | string (uri) | no | Optional Discord webhook URL for this project. |
UpdateRedirectUriDto schema
| Field | Type | Required | Description |
|---|---|---|---|
redirectUri | string | yes | Allowed redirect URI(s) for this project. Use a comma-separated list to allow multiple URIs. The value passed in GET /auth/authorize must exactly match one of these. |
Source: apps/api/openapi.json.