live
optionalReturns the signed-in user, refreshing the short-lived auth token when needed.
No input. Send {}.
Version 1.0.0 · Base URL https://pedmono.worker.nitlix.com · docs.json · health
Session cookies set by auth_login / auth_register / auth_nitlix. Send requests with credentials included. Auth levels: public (anyone), optional (works signed out, more when signed in), user (signed in), admin.
curl -X POST https://pedmono.worker.nitlix.com/rpc -H 'Content-Type: application/json' \
-d '{"event":"post_search","input":{"q":"hello","sort":"likes","page":1}}'
| POST | /rpc | Every RPC event. Body: { "event": "<name>", "input": { ... } }. Answers { "data": { "ok": true, "data": ... } } or { "data": { "ok": false, "data": "<message>", "code"?: "..." } }. |
| GET | /health | Version and the live status of the database, both R2 buckets, email and Nitlix sign-in. 503 when degraded. |
| GET | /docs | This page. /docs.json is the same, machine readable. |
| GET | /cover/:postId?v=&share= | A post's cover image from the private bucket. Private posts need a session cookie or a share token. |
| GET | /image-proxy?url= | Signed in only. Fetches a remote image so the browser can resize it (avatar or cover from a URL). |
| GET | /auth/nitlix | Starts a Nitlix sign-in and redirects back to the site's /auth/callback with a ticket for auth_nitlix. |
liveReturns the signed-in user, refreshing the short-lived auth token when needed.
No input. Send {}.
auth_registerCreates an account with a username, email and password, then signs it in.
| Field | Type | Rules |
|---|---|---|
username | string | |
email | string | |
password | string | min length 8, max length 128 |
rememberoptional | boolean | default false |
auth_loginSigns in with email and password. remember keeps the session for 30 days, otherwise it ends with the browser session.
| Field | Type | Rules |
|---|---|---|
email | string | |
password | string | min length 1, max length 128 |
rememberoptional | boolean | default false |
auth_nitlixCompletes a Nitlix sign-in. Redeems the one-time ticket against the state cookie set by GET /auth/nitlix, linking or creating the account.
| Field | Type | Rules |
|---|---|---|
ticket | string | min length 1, max length 512 |
rememberoptional | boolean | default true |
sign_outEnds the current session and clears the auth cookies.
No input. Send {}.
auth_reset_requestEmails a password reset link. Limited to 3 per account per hour. Always answers the same way, so it can't be used to discover accounts.
| Field | Type | Rules |
|---|---|---|
email | string |
auth_reset_checkChecks a reset link before the new password is typed.
| Field | Type | Rules |
|---|---|---|
code | string | min length 1, max length 128 |
auth_reset_completeSets a new password from a reset link and signs out every existing session.
| Field | Type | Rules |
|---|---|---|
code | string | min length 1, max length 128 |
password | string | min length 8, max length 128 |
password_changeChanges the password (or sets one for Nitlix-only accounts) and signs out every other session.
| Field | Type | Rules |
|---|---|---|
currentPasswordoptional | string | max length 128 |
newPassword | string | min length 8, max length 128 |
session_listLists the signed-in user's active sessions, newest first.
No input. Send {}.
session_revokeSigns out one of the user's sessions.
| Field | Type | Rules |
|---|---|---|
id | string | min length 1, max length 64 |
profile_updateUpdates any of username, email, bio and preferences. Omitted fields stay as they are.
| Field | Type | Rules |
|---|---|---|
usernameoptional | string | |
emailoptional | string | |
biooptional | string | max length 500 |
preferencesoptional | object |
upload_prepareStep 1 of an upload. Reserves unverified objects and returns presigned R2 URLs to PUT WebP bytes to (Content-Type: image/webp). Confirm with upload_verify.
| Field | Type | Rules |
|---|---|---|
purpose | "avatar" | "cover_image" | |
items | object[] | max 8 items |
upload_verifyStep 2 of an upload. The worker HEADs each object in R2, checks its real size and type, and marks it verified. A new avatar set replaces the previous one.
| Field | Type | Rules |
|---|---|---|
ids | string[] | max 8 items |
avatar_removeRemoves the user's avatar in every size.
No input. Send {}.
user_profileA user's public profile by username. List their posts with post_search and author.
| Field | Type | Rules |
|---|---|---|
username | string |
webhook_updateSets (or clears, with url: null) the webhook notified with a signed comment.created event whenever someone comments on one of your posts.
| Field | Type | Rules |
|---|---|---|
url | string | null | max length 2048 |
rotateSecretoptional | boolean | default false |
webhook_testSends a signed webhook.test event to the configured webhook and reports how it answered.
No input. Send {}.
post_searchSearches posts by title, content or tag, with sorting and pagination. Results only include posts the caller can see: public posts, their own, and (for admins) posts they made private. mine needs a session.
| Field | Type | Rules |
|---|---|---|
qoptional | string | max length 200, default "" |
inoptional | "all" | "title" | "content" | "tag" | default "all" |
tagoptional | string | max length 64 |
typeoptional | "public" | "private" | "all" | default "public" |
sortoptional | "new" | "old" | "likes" | "comments" | "title" | default "new" |
authoroptional | string | |
mineoptional | boolean | default false |
pageoptional | integer | min 1, max 10000, default 1 |
perPageoptional | integer | min 1, max 50, default 12 |
post_getA post by id with its comments. Private posts are only visible to their author, or to the admin who made them private.
| Field | Type | Rules |
|---|---|---|
id | string | min length 1, max length 64 |
post_get_sharedOpens a post through a temporary access link, even if it's private and the reader is signed out.
| Field | Type | Rules |
|---|---|---|
token | string | min length 3, max length 200 |
post_createCreates a post. content is HTML and is sanitised against a whitelist. coverId is a verified cover_image upload. Limited by the author's max posts.
| Field | Type | Rules |
|---|---|---|
title | string | min length 1, max length 200 |
content | string | max length 100000 |
tagsoptional | string[] | max 20 items |
typeoptional | "public" | "private" | default "public" |
coverIdoptional | string | null | min length 1, max length 64 |
post_updateEdits any field of a post by id. Authors can edit their own posts. Admins can edit public posts and make them private; they keep access to posts they made private, but not to posts their author made private. coverId: null removes the cover.
| Field | Type | Rules |
|---|---|---|
id | string | min length 1, max length 64 |
titleoptional | string | min length 1, max length 200 |
contentoptional | string | max length 100000 |
tagsoptional | string[] | max 20 items |
typeoptional | "public" | "private" | |
coverIdoptional | string | null | min length 1, max length 64 |
post_deleteDeletes one of your posts along with its comments, likes, share links and cover image.
| Field | Type | Rules |
|---|---|---|
id | string | min length 1, max length 64 |
post_likeLikes or unlikes a post you can see. A user can like a post once; repeating a like changes nothing.
| Field | Type | Rules |
|---|---|---|
id | string | min length 1, max length 64 |
liked | boolean |
post_exportExports all of your posts. JSON embeds each cover image as base64 so the file can be re-imported anywhere; CSV is a flat table for spreadsheets.
| Field | Type | Rules |
|---|---|---|
format | "json" | "csv" |
post_importImports posts from JSON (an array, or this API's own export) or XML. Every post is created new; ids in the file are ignored. Invalid entries are skipped and reported.
| Field | Type | Rules |
|---|---|---|
format | "json" | "xml" | |
content | string | min length 1, max length 26214400 |
share_createCreates a temporary access link to a post you can see. It opens the post for anyone until it expires, is revoked, or you lose access to the post.
| Field | Type | Rules |
|---|---|---|
postId | string | min length 1, max length 64 |
hours | number |
share_listActive share links for a post: all of them for its author, otherwise just the ones you made.
| Field | Type | Rules |
|---|---|---|
postId | string | min length 1, max length 64 |
share_revokeRevokes a share link. Its creator or the post's author can do this.
| Field | Type | Rules |
|---|---|---|
id | string | min length 1, max length 64 |
comment_createComments on any post you can read. The author's webhook (and email, if they opted in) is notified.
| Field | Type | Rules |
|---|---|---|
postId | string | min length 1, max length 64 |
content | string | min length 1, max length 2000 |
comment_updateEdits one of your comments.
| Field | Type | Rules |
|---|---|---|
id | string | min length 1, max length 64 |
content | string | min length 1, max length 2000 |
comment_deleteDeletes a comment. Its author can, and so can the post's author and admins who can see the post, to moderate.
| Field | Type | Rules |
|---|---|---|
id | string | min length 1, max length 64 |
admin_usersUsers by id, username or email, with their post counts and limits.
| Field | Type | Rules |
|---|---|---|
qoptional | string | max length 100, default "" |
pageoptional | integer | min 1, max 10000, default 1 |
admin_promotePromotes a user to admin by their user id.
| Field | Type | Rules |
|---|---|---|
userId | string | min length 1, max length 64 |
admin_set_max_postsSets how many posts a user may have. Leave out userId to apply it to every user at once.
| Field | Type | Rules |
|---|---|---|
userIdoptional | string | min length 1, max length 64 |
maxPosts | integer | min 0, max 100000 |
admin_logsActivity log, newest first. Filter by user (id or username), action (exact, or a prefix ending in . like post.), IP prefix, user agent and an ISO date range.
| Field | Type | Rules |
|---|---|---|
useroptional | string | max length 64 |
actionoptional | string | max length 64 |
ipoptional | string | max length 64 |
userAgentoptional | string | max length 200 |
fromoptional | string | date-time |
tooptional | string | date-time |
pageoptional | integer | min 1, max 10000, default 1 |
admin_logs_exportThe same filters as admin_logs, as a CSV file of up to 10000 rows.
| Field | Type | Rules |
|---|---|---|
useroptional | string | max length 64 |
actionoptional | string | max length 64 |
ipoptional | string | max length 64 |
userAgentoptional | string | max length 200 |
fromoptional | string | date-time |
tooptional | string | date-time |