Project API overview
How a project calls MCDI: how to authenticate and every endpoint at a glance, grouped by area.
These endpoints are for the backends and browsers of MicroClub projects. A backend call carries the project's API key in the X-API-Key header, and the login endpoints are public because they start a member's sign-in. A few endpoints act on a member's own session and take that member's session token as a Bearer token instead. What a project can do is limited to the servers and operations an administrator granted it.
The endpoints the admin dashboard uses are in the Admin API.
30 endpoints in 7 groups.
Authentication
| Method | Path | Summary |
|---|---|---|
GET | /api/auth/authorize | Initiate authorization request (legacy / force re-auth) |
GET | /api/auth/discord | Redirect to Discord OAuth |
POST | /api/auth/logout | Invalidate session token (project-scoped) |
POST | /api/auth/logout-all | Invalidate all sessions for a member (project-scoped) |
GET | /api/auth/sessions | List active sessions for the current member |
DELETE | /api/auth/sessions/{sessionId} | Revoke a specific session |
POST | /api/auth/token | Exchange callback code for session token (backend-to-backend) |
POST | /api/auth/token/refresh | Refresh an active session token |
POST | /api/auth/validate | Validate session token (project-scoped) |
Authentication (SSO)
| Method | Path | Summary |
|---|---|---|
GET | /api/auth/sso/authorize | Initiate authorization request (SSO-aware - recommended) |
POST | /api/auth/sso/logout | Destroy the global SSO session (log out everywhere) |
GET | /api/auth/sso/session | Get current SSO session status |
GET | /api/auth/sso/sessions | List active project sessions under the current SSO session |
Channels
| Method | Path | Summary |
|---|---|---|
GET | /api/servers/{serverId}/channels | List all channels in a server |
GET | /api/servers/{serverId}/channels/{channelId} | Get channel details |
GET | /api/servers/{serverId}/channels/{channelId}/messages | Get recent messages from a channel |
POST | /api/servers/{serverId}/channels/{channelId}/messages | Send a message to a Discord channel |
Inbound Webhooks (Ingest)
| Method | Path | Summary |
|---|---|---|
POST | /api/inbound-webhooks/{id}/submit | Submit a payload |
Members
| Method | Path | Summary |
|---|---|---|
GET | /api/servers/{serverId}/members | Search members |
GET | /api/servers/{serverId}/members/{discordId} | Get a single member by Discord ID |
GET | /api/servers/{serverId}/members/{discordId}/permissions | Get all effective permissions of a member in a server |
Permissions
| Method | Path | Summary |
|---|---|---|
POST | /api/permissions/check | Check a single permission |
POST | /api/permissions/check-batch | Check multiple permissions (batch) |
GET | /api/permissions/{serverId}/{discordId} | Get full resolved permissions for a member |
Webhooks
| Method | Path | Summary |
|---|---|---|
GET | /api/projects/{projectId}/webhooks | List webhooks for a project |
POST | /api/servers/{serverId}/channels/{channelId}/webhooks | Create a webhook for a channel |
GET | /api/webhooks/{webhookId} | Get webhook details |
PATCH | /api/webhooks/{webhookId} | Update webhook settings |
DELETE | /api/webhooks/{webhookId} | Delete a webhook |
POST | /api/webhooks/{webhookId}/execute | Execute a webhook |
Source: apps/api/openapi.json.