Backend REST API Reference
Complete documentation of HTTP endpoints, authentication schemas, request bodies, and JSON response models for developer integration and platform extensions.
🔑 Authentication & Headers
Authenticated endpoints require an HTTP Authorization header containing the JSON Web Token returned upon login or registration:
1. Authentication Endpoints (/api/auth/*)
Register a new user account with email, username, and password.
Request Body:Authenticate existing user via credentials.
Request Body:Authenticate with a Firebase ID token (Google Sign-In or Phone SMS login).
Request Body:Instantly provision a temporary guest account for rapid trial matchmaking.
Response (200 OK):Fetch current authenticated user profile, wallet balance, and VIP status.
2. Payments & Monetization Endpoints (/api/payments/*)
Retrieve configured diamond coin packages with prices and bonus amounts.
Response (200 OK):Validate Google Play Billing or Apple StoreKit receipts server-side (Fail-closed validation).
Request Body:Create a Stripe Checkout Session for web diamond coin purchases.
3. Virtual Gifts & VIP Memberships
Retrieve available animated gifts with their diamond coin costs.
Response (200 OK):Send a virtual gift to a partner during a live call or direct chat (deducts diamonds from sender).
Request Body:Fetch available VIP subscription durations (e.g., 7 days, 30 days, 365 days).
4. WebRTC Infrastructure & Settings
Returns dynamic STUN and TURN ICE server configurations for WebRTC video peers.
Response (200 OK):Client application initialization payload (app name, logo URL, terms URL, enabled auth methods).
5. Administrative Management API (/api/admin/*)
Admin authentication with username & password (returns admin JWT).
Real-time platform metrics (active calls, online users, total registered accounts, gross revenue).
Paginated user management list with search, filter, ban status, and wallet balance.
Toggle ban status for a user to immediately revoke access.