API reference
All application endpoints use https://zombies.necodex.dev/api/v1. Requests and ordinary responses are JSON. Webhooks acknowledge with 204, while the authorized audio stream redirects to a temporary media URL.
Response contract
// Success
{ "data": { /* resource */ }, "requestId": "optional-id" }
// Error
{ "error": { "code": "SAFE_CODE", "message": "Safe message", "details": {}, "requestId": "…" } }Authorization is server-side.
Use the bearerAuth security scheme for session-protected routes. A resource card can be rendered as locked for upsell, but its stream, RSVP, post, chat, and admin actions must receive server authorization.
Auth
GET
/api/v1/healthService healthPOST
/api/v1/auth/loginCreate an opaque session from email and passwordPOST
/api/v1/auth/registerCreate a Human account and opaque sessionPOST
/api/v1/vip/applySubmit a Zombie VIP applicationHome
GET
/api/v1/homePublic home composition; optional bearer token personalizes locks and RSVP stateContent
GET
/api/v1/contentList published content; access is the entitlement source of truth and tags are descriptive metadataGET
/api/v1/preview/audioShared-preview generated audio fixture. It exists only when PREVIEW_MODE=true and is the redirect target of an authorized stream request.Events
GET
/api/v1/eventsList events with optional tier-aware booking availabilityGET
/api/v1/preview/luma/eventsGet secret-free normalized Luma preview sync dataCommunity
GET
/api/v1/spacesList community spaces, including VIP locksLive
GET
/api/v1/liveGet current live-stream state with optional VIP lock metadataPodcast
GET
/api/v1/podcastGet local Spotify-shaped preview show metadata; replace with a provider adapter when configuredBilling
GET
/api/v1/billing/statusGet server-authoritative subscription statusPOST
/api/v1/billing/checkoutCreate a hosted Stripe Checkout session after VIP approvalPOST
/api/v1/billing/mobile-payment-sheetCreate an Android or eligible iOS PaymentSheet subscription flowPOST
/api/v1/billing/portalCreate a Stripe customer-portal sessionAdmin
POST
/api/v1/admin/contentCreate or update contentGET
/api/v1/admin/applicationsList VIP applicationsPOST
/api/v1/admin/applications/{id}/approveApprove an application and create Stripe CheckoutPOST
/api/v1/admin/applications/{id}/rejectReject an applicationPOST
/api/v1/admin/events/{id}/checkinCheck in an attendee or promote a waitlisted RSVPDELETE
/api/v1/admin/messages/{id}Remove a messagePATCH
/api/v1/admin/messages/{id}Pin or unpin a messageGET
/api/v1/admin/reportsList moderation reportsPATCH
/api/v1/admin/reportsResolve a reportPOST
/api/v1/admin/live/startMark a YouTube stream livePOST
/api/v1/admin/live/endEnd a live streamPOST
/api/v1/admin/live/{id}/syncSynchronize live status and viewers from YouTubeGET
/api/v1/admin/metricsGet revenue, subscription, and retention metricsGET
/api/v1/admin/integrationsGet secret-free external integration readinessWebhooks
POST
/api/v1/webhooks/stripeReceive verified Stripe eventsPOST
/api/v1/webhooks/lumaReceive Luma events after configured signature verification