Download OpenAPI specification:
DevCast backend API (Slim Framework 4 / PHP).
Generated by hand-reading the live controllers under backend/src/Futures
and backend/src/Config/routes.php, since the backend has no schema
library (no zod / class-validator equivalent) to generate from
automatically. Treat this spec as the source of truth for the HTTP
contract; when the backend changes, update the corresponding .tsp
file in this directory and recompile with bun run build.
GitHub OAuth callback. On success this issues a 302 redirect to
{frontend_base_url}/_auth/callback?token={jwt} rather than a JSON
body.
backend/src/Futures/Auth/Callback/CallbackController.php:25
| code required | string |
| state required | string |
{- "details": {
- "instance": "string",
- "date": "string",
- "status": 0
}, - "message": "string",
- "code": "INVALID_CODE"
}Requires a bearer JWT. Returns the authenticated user's profile. backend/src/Futures/Auth/Profile/ProfileController.php:14
{- "data": {
- "profile": {
- "id": 0,
- "username": "string",
- "email": "string",
- "providers": [
- {
- "id": 0,
- "provider": "string",
- "expires_at": "string"
}
], - "created_at": "string",
- "updated_at": "string",
- "subscription": {
- "stripe_subscription_id": "string",
- "stripe_price_id": "string",
- "status": "string",
- "current_period_start": "string",
- "current_period_end": "string"
}
}
}, - "message": "string"
}Exchanges a refresh token (in the request body) for a new access +
refresh token pair, rotating the refresh token in the process.
Distinct from refreshToken, which requires a bearer JWT and also
tears down all of the user's existing sessions.
backend/src/Futures/Auth/AccessToken/AccessTokenController.php:15
| refresh_token required | string |
{- "refresh_token": "string"
}{- "data": {
- "access_token": "string",
- "refresh_token": "string"
}, - "message": "string"
}Requires a bearer JWT. Invalidates all of the user's existing sessions and refresh tokens, then issues a brand new access + refresh token pair. backend/src/Futures/Auth/RefreshToken/RefreshTokenController.php:14
{- "data": {
- "access_token": "string",
- "refresh_token": "string"
}, - "message": "string"
}Lists the authenticated user's articles. Pass ?metadata=true to
also compute publish-state counters across all providers.
backend/src/Futures/Version1/Articles/ArticlesController.php:22
| metadata | string Enum: "true" "false" |
{- "data": {
- "articles": [
- {
- "id": 0,
- "user_id": 0,
- "title": "string",
- "slug": "string",
- "body": "string",
- "tags": "string",
- "last_updated_at": "string",
- "created_at": "string",
- "updated_at": "string"
}
], - "metadata": {
- "total_count": 0,
- "published_count": 0,
- "draft_count": 0,
- "pending_count": 0
}
}, - "message": "string"
}Creates an article owned by the authenticated user and seeds an
article_status row (unpublished) for each of their linked
providers. Returns the created article directly as data (not
nested under an article key).
backend/src/Futures/Version1/Articles/ArticlesController.php:49
| title required | string |
| body required | string |
| tags required | Array of strings |
{- "title": "string",
- "body": "string",
- "tags": [
- "string"
]
}{- "data": {
- "id": 0,
- "user_id": 0,
- "title": "string",
- "slug": "string",
- "body": "string",
- "tags": "string",
- "last_updated_at": "string",
- "created_at": "string",
- "updated_at": "string"
}, - "message": "string"
}Registers a linked OAuth provider credential for the authenticated
user. Fails if a credential for that provider already exists — use
updateProvider to rotate an existing one.
backend/src/Futures/Version1/Providers/ProvidersController.php:25
| provider required | string |
| token required | string |
| expires_at required | string ISO-8601 date-time string, parsed with PHP's |
{- "provider": "string",
- "token": "string",
- "expires_at": "string"
}{- "data": null,
- "message": "string"
}Rotates the token/expiry on an existing linked provider credential. backend/src/Futures/Version1/Providers/ProvidersController.php:64
| provider required | string |
| token required | string |
| expires_at required | string ISO-8601 date-time string, parsed with PHP's |
{- "provider": "string",
- "token": "string",
- "expires_at": "string"
}{- "data": null,
- "message": "string"
}Unlinks a provider credential from the authenticated user. backend/src/Futures/Version1/Providers/ProvidersController.php:104
| provider required | string |
{- "provider": "string"
}{- "data": null,
- "message": "string"
}