PedMono API

Version 1.0.0 · Base URL https://pedmono.worker.nitlix.com · docs.json · health

Session cookies set by auth_login / auth_register / auth_nitlix. Send requests with credentials included. Auth levels: public (anyone), optional (works signed out, more when signed in), user (signed in), admin.

curl -X POST https://pedmono.worker.nitlix.com/rpc -H 'Content-Type: application/json' \
  -d '{"event":"post_search","input":{"q":"hello","sort":"likes","page":1}}'

HTTP routes

POST/rpcEvery RPC event. Body: { "event": "<name>", "input": { ... } }. Answers { "data": { "ok": true, "data": ... } } or { "data": { "ok": false, "data": "<message>", "code"?: "..." } }.
GET/healthVersion and the live status of the database, both R2 buckets, email and Nitlix sign-in. 503 when degraded.
GET/docsThis page. /docs.json is the same, machine readable.
GET/cover/:postId?v=&share=A post's cover image from the private bucket. Private posts need a session cookie or a share token.
GET/image-proxy?url=Signed in only. Fetches a remote image so the browser can resize it (avatar or cover from a URL).
GET/auth/nitlixStarts a Nitlix sign-in and redirects back to the site's /auth/callback with a ticket for auth_nitlix.

Authentication

live

optional

Returns the signed-in user, refreshing the short-lived auth token when needed.

No input. Send {}.

auth_register

public

Creates an account with a username, email and password, then signs it in.

FieldTypeRules
usernamestring
emailstring
passwordstringmin length 8, max length 128
rememberoptionalbooleandefault false

auth_login

public

Signs in with email and password. remember keeps the session for 30 days, otherwise it ends with the browser session.

FieldTypeRules
emailstring
passwordstringmin length 1, max length 128
rememberoptionalbooleandefault false

auth_nitlix

public

Completes a Nitlix sign-in. Redeems the one-time ticket against the state cookie set by GET /auth/nitlix, linking or creating the account.

FieldTypeRules
ticketstringmin length 1, max length 512
rememberoptionalbooleandefault true

sign_out

optional

Ends the current session and clears the auth cookies.

No input. Send {}.

auth_reset_request

public

Emails a password reset link. Limited to 3 per account per hour. Always answers the same way, so it can't be used to discover accounts.

FieldTypeRules
emailstring

auth_reset_check

public

Checks a reset link before the new password is typed.

FieldTypeRules
codestringmin length 1, max length 128

auth_reset_complete

public

Sets a new password from a reset link and signs out every existing session.

FieldTypeRules
codestringmin length 1, max length 128
passwordstringmin length 8, max length 128

password_change

user

Changes the password (or sets one for Nitlix-only accounts) and signs out every other session.

FieldTypeRules
currentPasswordoptionalstringmax length 128
newPasswordstringmin length 8, max length 128

session_list

user

Lists the signed-in user's active sessions, newest first.

No input. Send {}.

session_revoke

user

Signs out one of the user's sessions.

FieldTypeRules
idstringmin length 1, max length 64

Profile & uploads

profile_update

user

Updates any of username, email, bio and preferences. Omitted fields stay as they are.

FieldTypeRules
usernameoptionalstring
emailoptionalstring
biooptionalstringmax length 500
preferencesoptionalobject

upload_prepare

user

Step 1 of an upload. Reserves unverified objects and returns presigned R2 URLs to PUT WebP bytes to (Content-Type: image/webp). Confirm with upload_verify.

FieldTypeRules
purpose"avatar" | "cover_image"
itemsobject[]max 8 items

upload_verify

user

Step 2 of an upload. The worker HEADs each object in R2, checks its real size and type, and marks it verified. A new avatar set replaces the previous one.

FieldTypeRules
idsstring[]max 8 items

avatar_remove

user

Removes the user's avatar in every size.

No input. Send {}.

user_profile

user

A user's public profile by username. List their posts with post_search and author.

FieldTypeRules
usernamestring

webhook_update

user

Sets (or clears, with url: null) the webhook notified with a signed comment.created event whenever someone comments on one of your posts.

FieldTypeRules
urlstring | nullmax length 2048
rotateSecretoptionalbooleandefault false

webhook_test

user

Sends a signed webhook.test event to the configured webhook and reports how it answered.

No input. Send {}.

Posts & sharing

post_search

optional

Searches posts by title, content or tag, with sorting and pagination. Results only include posts the caller can see: public posts, their own, and (for admins) posts they made private. mine needs a session.

FieldTypeRules
qoptionalstringmax length 200, default ""
inoptional"all" | "title" | "content" | "tag"default "all"
tagoptionalstringmax length 64
typeoptional"public" | "private" | "all"default "public"
sortoptional"new" | "old" | "likes" | "comments" | "title"default "new"
authoroptionalstring
mineoptionalbooleandefault false
pageoptionalintegermin 1, max 10000, default 1
perPageoptionalintegermin 1, max 50, default 12

post_get

optional

A post by id with its comments. Private posts are only visible to their author, or to the admin who made them private.

FieldTypeRules
idstringmin length 1, max length 64

post_get_shared

optional

Opens a post through a temporary access link, even if it's private and the reader is signed out.

FieldTypeRules
tokenstringmin length 3, max length 200

post_create

user

Creates a post. content is HTML and is sanitised against a whitelist. coverId is a verified cover_image upload. Limited by the author's max posts.

FieldTypeRules
titlestringmin length 1, max length 200
contentstringmax length 100000
tagsoptionalstring[]max 20 items
typeoptional"public" | "private"default "public"
coverIdoptionalstring | nullmin length 1, max length 64

post_update

user

Edits any field of a post by id. Authors can edit their own posts. Admins can edit public posts and make them private; they keep access to posts they made private, but not to posts their author made private. coverId: null removes the cover.

FieldTypeRules
idstringmin length 1, max length 64
titleoptionalstringmin length 1, max length 200
contentoptionalstringmax length 100000
tagsoptionalstring[]max 20 items
typeoptional"public" | "private"
coverIdoptionalstring | nullmin length 1, max length 64

post_delete

user

Deletes one of your posts along with its comments, likes, share links and cover image.

FieldTypeRules
idstringmin length 1, max length 64

post_like

user

Likes or unlikes a post you can see. A user can like a post once; repeating a like changes nothing.

FieldTypeRules
idstringmin length 1, max length 64
likedboolean

post_export

user

Exports all of your posts. JSON embeds each cover image as base64 so the file can be re-imported anywhere; CSV is a flat table for spreadsheets.

FieldTypeRules
format"json" | "csv"

post_import

user

Imports posts from JSON (an array, or this API's own export) or XML. Every post is created new; ids in the file are ignored. Invalid entries are skipped and reported.

FieldTypeRules
format"json" | "xml"
contentstringmin length 1, max length 26214400

share_create

user

Creates a temporary access link to a post you can see. It opens the post for anyone until it expires, is revoked, or you lose access to the post.

FieldTypeRules
postIdstringmin length 1, max length 64
hoursnumber

share_list

user

Active share links for a post: all of them for its author, otherwise just the ones you made.

FieldTypeRules
postIdstringmin length 1, max length 64

share_revoke

user

Revokes a share link. Its creator or the post's author can do this.

FieldTypeRules
idstringmin length 1, max length 64

Comments

comment_create

user

Comments on any post you can read. The author's webhook (and email, if they opted in) is notified.

FieldTypeRules
postIdstringmin length 1, max length 64
contentstringmin length 1, max length 2000

comment_update

user

Edits one of your comments.

FieldTypeRules
idstringmin length 1, max length 64
contentstringmin length 1, max length 2000

comment_delete

user

Deletes a comment. Its author can, and so can the post's author and admins who can see the post, to moderate.

FieldTypeRules
idstringmin length 1, max length 64

Admin

admin_users

admin

Users by id, username or email, with their post counts and limits.

FieldTypeRules
qoptionalstringmax length 100, default ""
pageoptionalintegermin 1, max 10000, default 1

admin_promote

admin

Promotes a user to admin by their user id.

FieldTypeRules
userIdstringmin length 1, max length 64

admin_set_max_posts

admin

Sets how many posts a user may have. Leave out userId to apply it to every user at once.

FieldTypeRules
userIdoptionalstringmin length 1, max length 64
maxPostsintegermin 0, max 100000

admin_logs

admin

Activity log, newest first. Filter by user (id or username), action (exact, or a prefix ending in . like post.), IP prefix, user agent and an ISO date range.

FieldTypeRules
useroptionalstringmax length 64
actionoptionalstringmax length 64
ipoptionalstringmax length 64
userAgentoptionalstringmax length 200
fromoptionalstringdate-time
tooptionalstringdate-time
pageoptionalintegermin 1, max 10000, default 1

admin_logs_export

admin

The same filters as admin_logs, as a CSV file of up to 10000 rows.

FieldTypeRules
useroptionalstringmax length 64
actionoptionalstringmax length 64
ipoptionalstringmax length 64
userAgentoptionalstringmax length 200
fromoptionalstringdate-time
tooptionalstringdate-time