Skip to main content

Projects

Register projects, manage their API keys and redirect URIs, and grant or review their access to servers.

MC Project registration and server access grants - system admin only

List all projects

GET/api/admin/projects

Authentication: Admin session token (Authorization: Bearer <token>)

Parameters

NameInTypeRequiredDescription
isActivequerybooleannoFilter by active/inactive status.
isInternalquerybooleannoFilter by internal/external project type.
namequerystringnoFilter by project name (case-insensitive partial match).

Responses

StatusDescriptionBody
200Projects retrieved successfully.
400Invalid parameter.
401Authentication required.
403System Admin access required.

Open in Swagger (opens in a new tab)

Create a project

POST/api/admin/projects

Registers a new project and returns its API key. The full key is returned once and never stored - save it immediately.

Authentication: Admin session token (Authorization: Bearer <token>)

Request body (JSON, required): CreateProjectDto schema.

Responses

StatusDescriptionBody
201Project created. API key returned once.any
400Validation error.
401Authentication required.
403System Admin access required.

Open in Swagger (opens in a new tab)

List access change audit logs

GET/api/admin/projects/access/audit

Authentication: Admin session token (Authorization: Bearer <token>)

Parameters

NameInTypeRequiredDescription
limitquerynumbernoMax entries to return (1-500, default 100).
projectIdquerystringnoFilter by project ID.
serverIdquerystringnoFilter by server ID.
actionquery"GRANT" or "UPDATE" or "REVOKE"noFilter by audit action type.

Responses

StatusDescriptionBody
200Audit logs retrieved successfully.
400Invalid limit parameter.
401Authentication required.
403System Admin access required.

Open in Swagger (opens in a new tab)

List full project-server access matrix

GET/api/admin/projects/access/matrix

Returns every project-server mapping including operations and per-server scopes.

Authentication: Admin session token (Authorization: Bearer <token>)

Parameters

NameInTypeRequiredDescription
projectIdquerystringnoFilter by project ID.
serverIdquerystringnoFilter by server ID.
scopequery"read_members" or "check_permissions"noFilter by scope.
projectNamequerystringnoFilter by project name (partial, case-insensitive).

Responses

StatusDescriptionBody
200Access matrix retrieved successfully.any
400Invalid parameter.
401Authentication required.
403System Admin access required.

Open in Swagger (opens in a new tab)

List projects that can access a server

GET/api/admin/projects/servers/{serverId}/projects

Authentication: Admin session token (Authorization: Bearer <token>)

Parameters

NameInTypeRequiredDescription
serverIdpathstringyesDiscord server ID
scopequery"read_members" or "check_permissions"noFilter projects by required scope.
isActivequerybooleannoFilter by project active status.

Responses

StatusDescriptionBody
200Project mappings retrieved successfully.
400Invalid server ID format.
401Authentication required.
403System Admin access required.

Open in Swagger (opens in a new tab)

Get a project by ID

GET/api/admin/projects/{id}

Authentication: Admin session token (Authorization: Bearer <token>)

Parameters

NameInTypeRequiredDescription
idpathstringyesProject UUID

Responses

StatusDescriptionBody
200Project retrieved successfully.
400Invalid project ID format.
401Authentication required.
403System Admin access required.
404Project not found.

Open in Swagger (opens in a new tab)

Update a project

PATCH/api/admin/projects/{id}

Authentication: Admin session token (Authorization: Bearer <token>)

Parameters

NameInTypeRequiredDescription
idpathstringyesProject UUID

Request body (JSON, required): UpdateProjectDto schema.

Responses

StatusDescriptionBody
200Project updated successfully.
400Invalid project ID or request body.
401Authentication required.
403System Admin access required.
404Project not found.

Open in Swagger (opens in a new tab)

Delete a project

DELETE/api/admin/projects/{id}

Authentication: Admin session token (Authorization: Bearer <token>)

Parameters

NameInTypeRequiredDescription
idpathstringyesProject UUID

Responses

StatusDescriptionBody
204Project deleted.
400Invalid project ID format.
401Authentication required.
403System Admin access required.
404Project not found.

Open in Swagger (opens in a new tab)

Reveal project API key info

GET/api/admin/projects/{id}/api-key

Returns the API key prefix and metadata. The full secret cannot be recovered - use POST :id/regenerate-api-key to generate a new one.

Authentication: Admin session token (Authorization: Bearer <token>)

Parameters

NameInTypeRequiredDescription
idpathstringyesProject UUID

Responses

StatusDescriptionBody
200API key info retrieved.any
400Invalid project ID format.
401Authentication required.
403System Admin access required.
404Project not found.

Open in Swagger (opens in a new tab)

Revoke API key

DELETE/api/admin/projects/{id}/key

Authentication: Admin session token (Authorization: Bearer <token>)

Parameters

NameInTypeRequiredDescription
idpathstringyesProject UUID

Responses

StatusDescriptionBody
204API key revoked.
400Invalid project ID format.
401Authentication required.
403System Admin access required.
404Project not found.

Open in Swagger (opens in a new tab)

Update allowed redirect URI(s)

PATCH/api/admin/projects/{id}/redirect-uri

Sets the redirect URI(s) allowed for this project. Accepts a single URI or a comma-separated list. The value passed to GET /auth/authorize must exactly match one of these.

Authentication: Admin session token (Authorization: Bearer <token>)

Parameters

NameInTypeRequiredDescription
idpathstringyesProject UUID

Request body (JSON, required): UpdateRedirectUriDto schema.

Responses

StatusDescriptionBody
200Redirect URI updated.object
400Invalid project ID or redirect URI.
401Authentication required.
403System Admin access required.
404Project not found.

Open in Swagger (opens in a new tab)

Regenerate project API key (admin)

POST/api/admin/projects/{id}/regenerate-api-key

Generates a new API key. The old key is immediately invalidated. Returns full key metadata.

Authentication: Admin session token (Authorization: Bearer <token>)

Parameters

NameInTypeRequiredDescription
idpathstringyesProject UUID

Responses

StatusDescriptionBody
200API key regenerated successfully.object
400Invalid project ID format.
401Authentication required.
403System Admin access required.
404Project not found.

Open in Swagger (opens in a new tab)

Restore a revoked API key

POST/api/admin/projects/{id}/restore-key

Authentication: Admin session token (Authorization: Bearer <token>)

Parameters

NameInTypeRequiredDescription
idpathstringyesProject UUID

Responses

StatusDescriptionBody
204API key restored.
400Invalid project ID format.
401Authentication required.
403System Admin access required.
404Project not found.

Open in Swagger (opens in a new tab)

List servers accessible by a project

GET/api/admin/projects/{projectId}/servers

Authentication: Admin session token (Authorization: Bearer <token>)

Parameters

NameInTypeRequiredDescription
projectIdpathstringyesProject UUID
scopequery"read_members" or "check_permissions"noFilter servers by required scope.

Responses

StatusDescriptionBody
200Server mappings retrieved successfully.any
400Invalid project ID format.
401Authentication required.
403System Admin access required.

Open in Swagger (opens in a new tab)

Grant or update project access to a server

PUT/api/admin/projects/{projectId}/servers/{serverId}

Creates or updates the access mapping between a project and a server. You can set both the allowed operations and the scopes per server. If scopes are omitted, existing scopes are preserved (or all scopes are granted for new mappings).

Authentication: Admin session token (Authorization: Bearer <token>)

Parameters

NameInTypeRequiredDescription
projectIdpathstringyesProject UUID
serverIdpathstringyesDiscord server ID

Request body (JSON, required): SetProjectServerAccessDto schema.

Responses

StatusDescriptionBody
200Access mapping upserted.any
400Invalid project or server ID format.
401Authentication required.
403System Admin access required.
404Project or server not found.

Open in Swagger (opens in a new tab)

Revoke project access to a server

DELETE/api/admin/projects/{projectId}/servers/{serverId}

Authentication: Admin session token (Authorization: Bearer <token>)

Parameters

NameInTypeRequiredDescription
projectIdpathstringyesProject UUID
serverIdpathstringyesDiscord server ID

Responses

StatusDescriptionBody
200Access mapping revoked.
400Invalid project or server ID format.
401Authentication required.
403System Admin access required.
404Access mapping not found.

Open in Swagger (opens in a new tab)

Schemas

AccessOperationsDto schema

FieldTypeRequiredDescription
MANAGE_WEBHOOKSbooleannoDefault: false.
READbooleannoDefault: true.
SEND_MESSAGESbooleannoDefault: false.

CreateProjectDto schema

FieldTypeRequiredDescription
descriptionstringno
isActivebooleannoWhether the project is active. Defaults to true.
isInternalbooleannoWhether this is an internal MicroClub platform project. Internal projects use the main server automatically. Defaults to false.
namestringyes
serverAccessarray of ProjectServerAccessDtonoServer access configurations. If omitted, the project is automatically granted all available scopes to all servers where is_main = true.
webhookUrlstring (uri)noOptional Discord webhook URL for this project.

ProjectServerAccessDto schema

FieldTypeRequiredDescription
scopesarray of "read_members" or "check_permissions"noScopes to grant for this server. If omitted, all available scopes are granted.
serverIdstringyes

SetProjectServerAccessDto schema

FieldTypeRequiredDescription
operationsAccessOperationsDtono
scopesarray of "read_members" or "check_permissions"noScopes granted to this project for this server. If omitted, defaults to all available scopes.

UpdateProjectDto schema

FieldTypeRequiredDescription
descriptionstringno
isActivebooleannoWhether the project is active.
isInternalbooleannoWhether this is an internal MicroClub platform project.
namestringno
webhookUrlstring (uri)noOptional Discord webhook URL for this project.

UpdateRedirectUriDto schema

FieldTypeRequiredDescription
redirectUristringyesAllowed redirect URI(s) for this project. Use a comma-separated list to allow multiple URIs. The value passed in GET /auth/authorize must exactly match one of these.

Source: apps/api/openapi.json.