Integrations
Clients call Silicon Zombies endpoints, not providers directly. The backend owns secrets, verifies webhooks, stores normalized state, and returns safe client-facing data.
Stripe billing
VIP access follows a fixed sequence: Human registration → VIP application → Admin approval → payment → verified webhook grants VIP. Use hosted checkout or the eligible mobile PaymentSheet flow.
/billing/* · /webhooks/stripeLuma events
Luma owns event registration and email. The backend enforces the VIP-first window, synchronizes RSVPs and waitlists, and verifies inbound webhook signatures.
/events · /preview/luma/events · /webhooks/lumaYouTube Live
The client embeds the stored YouTube video ID. YouTube native chat is not used; VIP live chat is a separately authorized service.
/live · /live/:id/chat-ticketMedia delivery
Audio requests are authorized at play time. Production redirects to a short-lived private media URL; preview redirects to generated fixture audio.
/content/:id/streamPreview mode boundary
When preview mode is enabled, the platform returns deterministic adapters instead of calling Stripe, Luma, Spotify, S3, or API Gateway. The response shapes remain useful for client integration. When a provider is configured for production, the public endpoint and authorization rules stay the same.
Provider API keys, webhook secrets, database URLs, and private-media credentials are server-only configuration. Webhook signature verification happens before the event mutates membership or reservations.