Skip to content

API — Supporting Endpoints ​

The remaining endpoint groups: search, quota, inquiries, messaging, notifications, profiles, reports, dashboard, taxonomy, admin, and public routes.

Search & discovery ​

MethodPathAuthNotes
GET/searchrequireAuth?q=&tab=products|sellers&state=&district=&trustTier=&hasActiveLeads=&minResponseRate=&page=&limit=. Postgres trigram (or Meilisearch when configured).
GET/quota/todayrequireAuthAll 3 axes (used/limit) + IST resetsAt.
GET/tile-counts/:siderequireAuthside = buy|sell → { browse, myEngagements, inquiries, myLeads }.
GET/engagement-countsrequireAuthSidebar leaf badge counts.

Inquiries (pre-engagement threads) ​

MethodPathAuthNotes
GET/inquiriesrequireActiveUserThreads (unread first); ?archived=true.
POST/inquiriesrequireActiveUser{ productId, body } — find-or-create by (productId, senderId).
POST/inquiries/:id/messagesrequireActiveUserAppend.
POST/inquiries/:id/readrequireActiveUserMark received as read.
POST/inquiries/:id/{archive,unarchive}requireActiveUserPer-participant archive.

Messaging (deal threads) ​

MethodPathAuthNotes
GET/messaging/threadsrequireActiveUserAll deal threads.
GET/messaging/threads/:idmembershipThread + last 50 messages.
POST/messaging/threads/:id/messagesmembershipSend — gated on ACCEPTED (422 MESSAGING_LOCKED otherwise). Inquiry threads bypass the gate.
PATCH/messaging/threads/:id/readmembershipMark received as read (idempotent even when locked).

Notifications & nudges ​

MethodPathNotes
GET/notifications?read=true|false&page=&limit=
PATCH/notifications/:id/readMark one read
PATCH/notifications/read-allMark all read
GET/profile/scoreTrust score breakdown + tier
POST/profile/nudges/snooze{ hours?: number } (default 24)
PATCH/profile/nudges/preferencesPer-type opt-out toggles

Profiles, farms & warehouses ​

MethodPathNotes
GET / PUT/farmer/profileOwn farmer profile (upsert)
GET / POST / PATCH / DELETE/farmer/farms[/:id]Farm CRUD (requireRole('farmer') + ownership)
POST / DELETE/farmer/farms/:id/photos[/:photoId]Farm photos
GET / PUT/trader/profileOwn trader profile
GET / POST / PATCH / DELETE/trader/warehouses[/:id]Warehouse CRUD (requireRole('trader') + ownership)
POST / DELETE/trader/warehouses/:id/photos[/:photoId]Warehouse photos
GET/users/:userIdPublic profile card

Reports (owner-only) ​

MethodPathNotes
GET/reports/pnlPeriod P&L summary + bucketed trend
GET/reports/transactionsPaginated sales + purchases; direction + product filter
GET/reports/exportCSV / XLS (dependency-free SpreadsheetML) / PDF (audit-hash footer). 5000-row cap → RANGE_TOO_LARGE

All report endpoints scope to req.user.id; there is no admin or shared view. Realised P&L is read live (cost basis) with a fixed sale-price snapshot.

Dashboard, taxonomy, lookups ​

MethodPathNotes
GET/dashboard4 tiles + weather
GET/taxonomy/treeFull taxonomy tree (admins see PENDING; nodes carry hsnCode/gstRate)

Admin (/admin/*, authorize('admin')) ​

Selected endpoints — the authoritative source is apps/api/src/routes/admin.routes.ts.

MethodPathNotes
GET/admin/statsPlatform counts
GET/admin/usersFilters: role, kycStatus, membershipNumber
PATCH/admin/users/:userId/kycSet KYC status (self-edit 403)
PATCH/admin/users/:userId/membershipACTIVE needs a future date; BASIC forces null
POST/admin/users/:userId/sub-admin{ grant } — sub-admins get grievance routes only
GET/admin/users/:userId/search-historyDPDP audit-gated (reason ≥10; writes an audit log)
GET/admin/orders + POST /admin/orders/backfillDeals dashboard + V1 rescue
GET/POST/PATCH/DELETE/admin/{group-affiliations,makhana-varieties,crops}[/:id]Lookup CRUD
PATCH / POST/admin/taxonomy/nodes[/:nodeId]Edit / create nodes (name, icon, GST bracket)
GET / POST/admin/taxonomy/suggestions[/:id/approve|reject]Suggestion queue
POST/admin/retention-purge{ retentionYears? } — the only hard-delete path

Public (no auth) ​

MethodPathNotes
GET/public/homeHero stats + makhana variety list
GET/public/states, /public/districts/:stateCodeLocation dropdowns
GET/public/{group-affiliations,makhana-varieties,crops}Lookup lists
POST/public/contactContact form
GET/api/v1/healthHealth check (DB + Redis probe)

Internal technical documentation — Cropto