Developer API

Small endpoints.
Clear contracts.

Public read-only endpoints for health, service discovery, network status, and community metadata. Private application, staff, and CAD operations stay on their own authenticated origins.

API

Public v1 endpoints

Versioned routes for Code Zero-owned integrations.

GET /v1/health

API availability, version, and timestamp.

GET /v1/services

Official Code Zero service directory.

GET /v1/status

Server-side checks against each service health file.

GET /v1/community

Public membership requirements and authentication metadata.

Security

Security boundaries

Public API responses should stay intentionally small.

01

No private applicant data

Application answers remain behind staff authentication.

02

No private CAD records

Member roleplay records remain behind CAD authentication.

03

No staff sessions

Signed staff session details never leave Staff Operations.

04

No secrets

OAuth secrets, bot tokens, and database credentials are never returned.