V8 Central — Product & Technical Spec
  1. Docs
  2. Technical
  3. API architecture

#API architecture

#Shared frontend API client (lib/api/)

ConcernRule
Base URLhttps://sa-central-api-2.167-233-229-184.nip.io (from env, never another pair's API)
AuthenticationAuthorization: Bearer <access token> added server-side (BFF route handlers / server components) from the httpOnly cookie. The browser never sees the token (D-1)
Cookies / sessionhttpOnly, secure, sameSite=Lax. Refresh token in its own httpOnly cookie
Organization contextOrganization id in the path of organization-scoped calls (/organizations/{org}/…, V7 style) Assumption. Never a global header the server trusts blindly
LocaleAccept-Language from the chosen locale (cookie)
ErrorsNormalised to {status, code, message, fields, reference}. 401 → refresh once → login. 403 → permission state. 404 → not-found. 422 → form. 429 → back off with Retry-After
RetryGET only: 1 retry on network error/502/503/504 with backoff. Never auto-retry POST/PUT/PATCH/DELETE
CancellationAbortController per request. Cancel on unmount, org switch, and a newer search
Request statesidle → loading → success / error, exposed by a small hook or TanStack Query Open question (TanStack Query isn't installed; the project rules mention "TanStack queries")
Timeouts15 s default. Proxied server calls up to 60 s; long jobs use 202 + polling

#Response conventions (proposed for sa-central-api-2)

Follow the OSS conventions so both APIs feel the same Assumption:

  • Named top-level keys ({"servers": [...]}), no generic data wrapper.
  • Errors: {"message": "...", "code": "...", "errors": {...}, "reference": "..."}.
  • Pagination meta: {current_page, per_page, total, last_page}, ?page=&per_page=.
  • Timestamps: ISO-8601 UTC (frontend formats). OSS uses DD-MM-YYYY HH:mm:ss, which the proxy passes through or converts Open question.
Proposed error shape (same as OSS)
// 422
{"message": "The given data was invalid.", "code": "validation_failed",
 "errors": {"email": ["The email has already been taken."]}}
// 403 (plan)
{"message": "Your plan allows 5 servers.", "code": "plan_limit_reached",
 "limit": 5, "used": 5}
// 504 (proxied server)
{"message": "This server is not responding.", "code": "server_unreachable",
 "server_id": 42, "reference": "3f9a…"}

#API dependency table

Every Central endpoint is missing today (sa-central-api-2 has none). The "V7 reference" column shows the existing V7 equivalent. It's not a V8 contract, and V8 paths are decided per phase. OSS rows exist now.

ModuleCapabilityV7 reference (method path)AuthOrg-scopedV8 status
AuthRegisterPOST /userspublicnoMissing V8 requirement 2.1
AuthVerify email / resendGET /verify/{token}, POST /resend/verification-linkpublicnoMissing
AuthLoginPOST /loginpublicnoMissing V8 requirement 2.3
Auth2FA verify / resendPOST /two-factor-authentication/verify, /resendpublic (pending login)noMissing
AuthSocial loginPOST /users/{provider}/url, GET /users/{provider}/callbackpublicnoMissing
AuthForgot / resetPOST /forgot-password, POST /reset-passwordpublicnoMissing
AuthIP approvalGET /user/whitelist-ip/{key}/authorizepublic (signed)noMissing
AuthRefresh tokenPassportrefresh tokennoMissing V8 requirement 2.9
AuthLogoutGET /user/logoutusernoMissing
AuthCurrent userGET /meusernoMissing
AccountProfile, email, password, 2FA, Google 2FA, IP whitelist, login history, API access, sessions/user/*, /user/2fa/*, /user/google-2fa/*, /user/whitelist-ip, /login-historyusernoMissing V8 requirement Phase 3
OrganizationsList / create / show / update / deleteGET/POST /organizations, GET/PATCH/DELETE /organizations/{id}, GET /auth/user/organizationsuser—Missing
OrganizationsMy permissionsGET /organizations/{org}/my-permissions/{level}memberyesMissing
MembersList / invite / role / removeGET/POST /organizations/{org}/members, PATCH …/{member}/assign-role, DELETE …/{member}member + permyesMissing
MembersAccept invitationPOST /user/password-set/{token} or register with invitation_tokenpublic tokennoMissing
RolesCRUDRoute::resource /organizations/{org}/rolesmember + permyesMissing
RolesPermission catalogGET /organizations/{org}/permissionsmemberyesMissing
PlansCatalognone in V7 (hard-coded)user?Missing
SubscriptionShow + usageGET /organizations/{org}/new-subscription-planowneryesMissing
SubscriptionCreate / change / renew / cancel / resume / quotePOST /create-subscription, PATCH /change-subscription, /renew-subscription, /cancel-subscription, /resume-subscription, GET /remaining-creditownerV7: userMissing
BillingWallet top-upPOST /user/walletuserV7: userMissing
BillingTransactions, receiptGET /payment, GET /payment-receipt/{key}/receiptuserV7: userMissing
BillingPayment execute / verifyGET /payment/{key}/execute, GET /payment/{key}/verifypublic keynoMissing
BillingCards, auto-recharge/payment-detail/cards*, /stripe-auto-chargeusernoMissing
BillingInvoicesGET /organizations/{org}/invoices, POST …/{number}/{action}owneryesMissing
BillingBilling detailsGET/POST /organizations/{org}/billing-details, /billing-detailowneryesMissing
ServersList / connect / show / disconnect(V7 servers were agent-based, not reusable)member + permyesMissing
ServersProxy to OSS—member + permyesMissing (D-10)
DashboardAggregates—memberyesMissing
ProvidersList / connect / OAuth callback / delete/organizations/{org}/cloud-server-providers*, GET /integrations/cloud-service-providersmember + permyesMissing
ProvidersRegions / sizes…/{id}/regions, …/{id}/sizesmember + permyesMissing
ProvidersCreate VPSPOST /organizations/{org}/servers (V7 store)member + permyesMissing
BlueprintsCRUD, upload, WP.org search/wordpress-blueprints*userV7: userMissing
AuditListGET /organizations/{org}/activities, GET /activitiesmember + permyesMissing
SearchGlobal(V7 route disabled)memberyesMissing
NotificationsList / unread / mark readGET /notifications/unread, /mark-as-readusernoMissing
NotificationsChannels/user/notification-channels*usernoMissing

#OSS endpoints Central calls (exist today) OSS API

PurposeMethod + pathAuth
Health / versionGET /api/healthnone
Validate key / identityGET /api/auth/meBearer central key
Facts / metrics / processesGET /api/server/facts, /server/metrics/live, /server/metrics/history, /server/processesBearer
CapabilitiesGET /api/server/capabilitiesBearer
Applications, databases, system users, services, firewall, cron, backups, PHP, Node, Fail2ban, settings, logs, disk cleaner, syncsee Server detailsBearer
Paid add-onsGET /api/central/addons, GET /api/central/addons/runs/{run}, /api/central/addons/applications/{id}/wordpress/*, /log-monitoring/*Bearer (Central only)
Install with keyCENTRAL_TOKEN=… bash install.sh --stack=…installer env
Not available to CentralPOST/DELETE /central (enable/revoke) needs an OSS admin session; user/role mutations → 403—
ServerAvatar V8 Central · prepared by central-app-2 (Pair 2 frontend) for Bhavik Jethwa · nothing in this spec is implemented yet · Built 2026-10-05 12:37 UTC