DevCast API (1.0.0)

Download OpenAPI specification:

DevCast backend API (Slim Framework 4 / PHP).

Generated by hand-reading the live controllers under backend/src/Futures and backend/src/Config/routes.php, since the backend has no schema library (no zod / class-validator equivalent) to generate from automatically. Treat this spec as the source of truth for the HTTP contract; when the backend changes, update the corresponding .tsp file in this directory and recompile with bun run build.

Health

Health_health

Liveness check. Returns a plain-text body, not JSON. backend/src/Futures/Health/HealthController.php:8

Authorizations:
None

Responses

Auth

Auth_oauthUrl

Generates the GitHub OAuth authorization URL. backend/src/Futures/Auth/AuthController.php:13

Authorizations:
None

Responses

Response samples

Content type
application/json
{
  • "data": {
    },
  • "message": "string"
}

Auth_callback

GitHub OAuth callback. On success this issues a 302 redirect to {frontend_base_url}/_auth/callback?token={jwt} rather than a JSON body. backend/src/Futures/Auth/Callback/CallbackController.php:25

Authorizations:
None
query Parameters
code
required
string
state
required
string

Responses

Response samples

Content type
application/json
{
  • "details": {
    },
  • "message": "string",
  • "code": "INVALID_CODE"
}

Auth_getProfile

Requires a bearer JWT. Returns the authenticated user's profile. backend/src/Futures/Auth/Profile/ProfileController.php:14

Authorizations:
BearerAuth

Responses

Response samples

Content type
application/json
{
  • "data": {
    },
  • "message": "string"
}

Auth_accessToken

Exchanges a refresh token (in the request body) for a new access + refresh token pair, rotating the refresh token in the process. Distinct from refreshToken, which requires a bearer JWT and also tears down all of the user's existing sessions. backend/src/Futures/Auth/AccessToken/AccessTokenController.php:15

Authorizations:
None
Request Body schema: application/json
required
refresh_token
required
string

Responses

Request samples

Content type
application/json
{
  • "refresh_token": "string"
}

Response samples

Content type
application/json
{
  • "data": {
    },
  • "message": "string"
}

Auth_refreshToken

Requires a bearer JWT. Invalidates all of the user's existing sessions and refresh tokens, then issues a brand new access + refresh token pair. backend/src/Futures/Auth/RefreshToken/RefreshTokenController.php:14

Authorizations:
BearerAuth

Responses

Response samples

Content type
application/json
{
  • "data": {
    },
  • "message": "string"
}

V1

V1_version

backend/src/Futures/Version1/Version1Controller.php:10

Authorizations:
BearerAuth

Responses

Response samples

Content type
application/json
{
  • "data": {
    },
  • "message": "string"
}

V1_getArticles

Lists the authenticated user's articles. Pass ?metadata=true to also compute publish-state counters across all providers. backend/src/Futures/Version1/Articles/ArticlesController.php:22

Authorizations:
BearerAuth
query Parameters
metadata
string
Enum: "true" "false"

Responses

Response samples

Content type
application/json
{
  • "data": {
    },
  • "message": "string"
}

V1_createArticle

Creates an article owned by the authenticated user and seeds an article_status row (unpublished) for each of their linked providers. Returns the created article directly as data (not nested under an article key). backend/src/Futures/Version1/Articles/ArticlesController.php:49

Authorizations:
BearerAuth
Request Body schema: application/json
required
title
required
string
body
required
string
tags
required
Array of strings

Responses

Request samples

Content type
application/json
{
  • "title": "string",
  • "body": "string",
  • "tags": [
    ]
}

Response samples

Content type
application/json
{
  • "data": {
    },
  • "message": "string"
}

V1_getProviders

backend/src/Futures/Version1/Providers/ProvidersController.php:14

Authorizations:
BearerAuth

Responses

Response samples

Content type
application/json
{
  • "data": {
    },
  • "message": "string"
}

V1_registerProvider

Registers a linked OAuth provider credential for the authenticated user. Fails if a credential for that provider already exists — use updateProvider to rotate an existing one. backend/src/Futures/Version1/Providers/ProvidersController.php:25

Authorizations:
BearerAuth
Request Body schema: application/json
required
provider
required
string
token
required
string
expires_at
required
string

ISO-8601 date-time string, parsed with PHP's new \DateTime(...).

Responses

Request samples

Content type
application/json
{
  • "provider": "string",
  • "token": "string",
  • "expires_at": "string"
}

Response samples

Content type
application/json
{
  • "data": null,
  • "message": "string"
}

V1_updateProvider

Rotates the token/expiry on an existing linked provider credential. backend/src/Futures/Version1/Providers/ProvidersController.php:64

Authorizations:
BearerAuth
Request Body schema: application/json
required
provider
required
string
token
required
string
expires_at
required
string

ISO-8601 date-time string, parsed with PHP's new \DateTime(...).

Responses

Request samples

Content type
application/json
{
  • "provider": "string",
  • "token": "string",
  • "expires_at": "string"
}

Response samples

Content type
application/json
{
  • "data": null,
  • "message": "string"
}

V1_deleteProvider

Unlinks a provider credential from the authenticated user. backend/src/Futures/Version1/Providers/ProvidersController.php:104

Authorizations:
BearerAuth
Request Body schema: application/json
required
provider
required
string

Responses

Request samples

Content type
application/json
{
  • "provider": "string"
}

Response samples

Content type
application/json
{
  • "data": null,
  • "message": "string"
}

Errors

Errors_notFound

path Parameters
path
required
string

Responses

Response samples

Content type
application/json
{
  • "details": {
    },
  • "message": "string",
  • "code": "INVALID_CODE"
}