#Missing backend dependencies
sa-central-api-2 has no application endpoints at all (Laravel skeleton, /api/* → 404, checked 2026-10-03). Everything Central needs is missing. This page lists each capability, why it's needed, and what's known. The frontend won't fake any of them.
Priority: P0 blocks the first usable release · P1 needed for launch · P2 later.
| Feature | Required API (capability) | Why | Current status | Suggested backend work | Frontend impact | Priority |
|---|---|---|---|---|---|---|
| Foundation | MariaDB, Redis, Horizon, Passport, CORS | Everything | Specified (Phase 1), not built. .env still SQLite | Build Phase 1 | Can't call any API | P0 |
| Session contract | Login/refresh/logout responses + the cookie/BFF decision | Frontend auth | "Next.js login flow: decided later" | Decide D-1, document token responses | Phase 1 blocked | P0 |
| Authentication | Register, verify, login, 2FA, OAuth, reset, invitation password, IP approval, refresh, logout, current user | Entry | Requirements complete (Phase 2) | Build Phase 2 | Phase 1 | P0 |
| Account | Profile, security, sessions, history, notification channels | Account pages | Requirements complete (Phase 3) | Build Phase 3 | Phase 2 | P1 |
| Organizations | CRUD, list mine, main org, delete rules | Tenant context | Not specified for V8. V7 known | Write the Organizations phase | Phase 3 | P0 |
| Permission catalog + my permissions | Catalog with levels, per-user map with deny reason (role/plan/expired) | Menus, guards | Levels settled — view / manage (Phase 4, 4.5) V8 requirement. The permission names are still unpublished: the backend's permission list and seeder are a separate step | Publish the catalog endpoint and the names | Every page | P0 |
| Roles | CRUD | Access | Not specified | Build | Phase 3 | P0 |
| Members + invitations | List, invite, resend, cancel, accept, change role, remove, statuses | Teams | Not specified. V7 lacks resend/cancel/accept/status | Build with explicit statuses | Phase 3 | P0 |
| Audit log | Structured writer + list with filters | Attribution (OSS logs "central") | V8 Phase 3 covers account activity only | Specify organization/server audit | Phase 4 | P0 |
| Server link | Connect (reachability, key, version, duplicate, limit), list, show, disconnect, status job | Core product | Q1, Q2, Q3 open | Answer Q1–Q3, build | Phase 5 | P0 |
| Plans + subscription | Requirements complete — backend Phase 7 (2026-10-03) V8 requirement: admin-managed plans with a per-plan feature list, one plan per owner across all their organizations, paid from credit (tax added, saved as a charge), trial, change with unused days returned as credit, downgrade checks, cancel / resume, auto-renew, reminders, the V7 expiry flow (day −7 warning, day −15 servers removed from Central + account locked), coupons, plan visibility, enterprise form, activity log | FE: Plans & subscription | Rules written, no endpoints: no plan catalog, no admin plan management, no feature-list API. How credit is bought is still undefined (D-5) | Publish the catalog + admin endpoints and the feature list; decide the gateway (D-5) and tax/currency (D-22) | Phase 6 | P0 |
| Cloud providers | Requirements complete — backend Phase 5 (2026-10-03) V8 requirement: named accounts (several per provider), connect by pasted API token (Lightsail: key + secret), Edit to rename or re-token, "Needs new token" when rejected, disconnect blocked while servers use it, actions by organization role | FE: Integrations | Rules written, no endpoints published. Open: D-27 (account vs organization level). The permission names for the role checks are still missing | Publish endpoints and the permission catalog; settle D-27 | Phase 8 | P1 |
| Create server at a provider | Draft only — moved to the Servers phase on 2026-10-03 V8 requirement: start-up script installs OSS, statuses Creating / Installing OSS / Ready / Failed, Retry or delete at the provider | FE: Integrations §B | Parked draft, no endpoints | Write it in the Servers phase; answer Q13 (OSS registration is open after an automatic install) before the first automatic install | Phase 5 | P0 security (Q13) |
| Git & backup storage accounts | Specified by backend Phase 5 (2026-10-03) V8 requirement: Central holds the form and a note only; secrets are pushed to each server's OSS, with per-server results, update-everywhere and remove-from-one-or-all | FE: Integrations | Rules written, no endpoints published. Q9–Q12 open | Publish endpoints; decide tokens vs one-click login and what happens to V7 connections | Phase 8 | P1 |
| Organizations, members, roles, share, transfer | Specified by backend Phase 4 (2026-10-03) V8 requirement: create/list/update/set default/delete, invites that must be accepted (7-day links, resend, cancel), one role per member, fixed Owner and Admin, custom view/manage roles, share one server, ownership transfer with both sides confirming by password + 2FA within 48 h, organization activity log | FE: Organization & Members | Rules written, no endpoints published, permission names missing | Publish endpoints + the permission catalog; answer D-28 (multi-role V7 members) | Phase 3 | P0 |
| OSS client + proxy | Per-server client (in the V8 plan) + a proxy/feature endpoints with permission + audit | Server Details | Client designed (§2.2), built with the Servers phase, not the Foundation phase (2026-10-03). Proxy not designed | Decide D-10, build | Phase 5 | P0 |
| Plan catalog | Plans with cycles, prices, currency, limits, features, eligibility | Plans screen without hard-coding | Doesn't exist even in V7 (constants) | Model + admin management | Phase 6 | P1 |
| Subscription | Current + usage, create, change, quote, renew, cancel, resume, explicit status | Commercial | Not specified. Ownership conflict | Decide D-3/D-4, build | Phase 6 | P1 |
| Billing | Wallet, top-up, transactions, gateway execute/verify + webhooks, invoices, cards, auto-recharge, billing details, tax, currency | Payment | Not specified | Decide D-4/D-5, build | Phase 6 | P1 |
| Usage counts | Servers + applications per organization | Limits, dashboard | Apps live on OSS | Cached counts via the status job | Phase 6–7 | P1 |
| Dashboard aggregates | One endpoint: KPIs + per-server status/metrics summary + spend + activity | Dashboard | None | Parallel OSS calls with timeouts + cache | Phase 7 | P1 |
| Providers | Connect (OAuth/token), regions, sizes, delete | Create VPS | Not specified | Build | Phase 8 | P2 |
| Provisioning | Create VPS + run installer with --stack + CENTRAL_TOKEN, progress, link | Create server | Not specified | Decide D-12, build jobs | Phase 8 | P2 |
| Blueprints | CRUD, uploads (signed URLs), WP.org search, run + track | Blueprints | Not specified. OSS run exists | Build. Decide D-14 | Phase 9 | P2 |
| WP Toolkit install + licence | Install the add-on on a server, licence it | Blueprint runs | Not specified anywhere in Central | Decide D-15 | Phase 9 | P2 |
| Global search | One query endpoint over permitted Central resources | ⌘K | None | Decide D-16 | Phase 10 | P2 |
| Notifications | List/unread/mark read + channels + delivery | Bell, alerts | Phase 3 specified (not built) | Build | Phase 2/10 | P1 |
| Server alerts source | OSS alerts/events API or Central-side monitoring | 3.17 | OSS has no alerts API | D-17 (OSS team or Central job) | Phase 10 | P2 |
| Key self-revoke on OSS | OSS endpoint for the Central key to revoke itself | Clean disconnect | Not in OSS (admin session only) | OSS team | Disconnect copy | P2 |
| Locale in API | Accept-Language support + error codes | Translated errors | Not specified | Add to the foundation | All forms | P1 |
| V7 migration | Account/billing import, permission mapping, server onboarding | Existing users | "Decided at the end" | Design after D-3/D-4/D-7/D-19 | Launch | P1 |