-
Notifications
You must be signed in to change notification settings - Fork 1
API Reference
Lavesh Paryani edited this page Sep 26, 2026
·
1 revision
All routes are served under /api by the Express app in backend/. They are listed here in the order
they are mounted in backend/routes/api/index.js. Responses are JSON. Upload routes take
multipart/form-data (field names in brackets).
Authentication: send the JWT from POST /api/auth/login as Authorization: Bearer <token> or as the
token cookie.
| Method | Path | Notes |
|---|---|---|
| POST | /auth/signup |
Create a User account, sends a welcome email |
| POST | /auth/login |
Returns the token and user data, sets the token cookie, sends a login notification |
| POST | /auth/forget-password |
Emails a reset link. Rate limited: 10 per hour per IP |
| GET | /auth/reset-password/validate |
Checks a reset token |
| POST | /auth/reset-password |
Sets a new password. Rate limited: 8 per 15 minutes per IP |
| POST | /auth/update-password |
Change password with the current password; bumps the token version |
| POST | /auth/reactivateUser |
Reactivate an account |
| Method | Path | Notes |
|---|---|---|
| GET | /settings/mock-mode |
Current mock-mode flag (also the keep-warm ping target) |
| GET | /blogs/getpublishedblogs |
Published posts |
| GET | /blogs/:blogid/getblogbyid |
One post by id |
| GET | /blogs/:slug/getblogbyslug |
One post by slug |
| GET | /blogs/:blogid/comments |
Comments on a post |
| POST | /companies/getallcompanies |
Approved companies, with filters and pagination in the body |
| GET | /companies/:companyId/getcompanybyid |
One approved company |
| GET | /events/getallevents |
All events |
| GET | /events/:eventId/geteventbyid |
One event |
| GET | /users/verified-traders |
Verified-trader list |
| GET | /users/:userId |
Public profile |
| GET | /spreads |
Spread data (optionally for one broker) |
| GET | /spreads/comparison |
Spread comparison table |
Everything below this point runs after authentication.middleware.js.
| Method | Path | Notes |
|---|---|---|
| POST | /company/request |
Request a new company listing [logo] |
| GET | /company/:companyId/getcompanybyid |
One company |
| POST | /blogs/addblog |
Create a post [featuredImage, up to 4 images] |
| POST | /blogs/getmyblogs |
The user's posts |
| GET | /blogs/:blogid/getblogbyid |
One of the user's posts |
| PUT | /blogs/:blogid/updateblog |
Update a post |
| DELETE | /blogs/:blogid/deleteblog |
Delete a post |
| POST | /blogs/:blogid/comments |
Add a comment. Rate limited: 6 per 10 minutes |
| DELETE | /blogs/comments/:commentid |
Delete a comment |
| POST | /reviews/addReview |
Add a review [screenshot] |
| PUT | /reviews/:reviewId |
Edit a review [screenshot] |
| DELETE | /reviews/:reviewId |
Delete a review |
| GET | /user/me |
Own profile |
| PATCH | /user/me |
Update profile [profileImage] |
| POST | /user/verified-trader/apply |
Apply for verified status [up to 5 brokerStatements, up to 5 payoutProofs] |
Requires the Admin or Operator role.
| Method | Path | Notes |
|---|---|---|
| POST | /admin/blogs/addblog |
Create a post |
| POST | /admin/blogs/getallblogs |
All posts |
| GET / PUT |
/admin/blogs/:blogid/getblogbyid, /admin/blogs/:blogid/updateblog
|
Read / update a post |
| DELETE |
/admin/blogs/:blogid/deleteblog, /admin/blogs/:blogid/permanentdeleteblog
|
Soft / hard delete |
| POST | /admin/company/addcompany |
Create a company |
| POST | /admin/company/getallcompanies |
All companies, any status |
| GET / PUT / DELETE |
/admin/company/:companyId/getcompanybyid, .../updatecompany, .../deletecompany
|
Manage a company |
| POST / PUT / DELETE |
/admin/company/:companyId/addpromocode, .../updatepromocode/:promoId, .../deletepromocode/:promoId
|
Promo codes |
| POST | /admin/review/addReview |
Add a review |
| GET | /admin/review/:userId/getreviewsbyusers |
Reviews by one user |
| DELETE | /admin/review/:reviewId/deletereview |
Delete a review |
| PUT | /admin/settings/mock-mode |
Turn mock mode on or off |
| GET | /admin/users/getallusers |
User list |
| POST | /admin/users/addAdminUser |
Create a staff account |
| PUT |
/admin/users/:userId/updaterole, /admin/users/:userId/updatestatus
|
Change role / activate or deactivate |
| GET | /admin/users/verified-trader/applications |
Applications with presigned proof links |
| POST | /admin/users/verified-trader/invite |
Invite a trader |
| POST | /admin/users/verified-trader/:userId/schedule-call |
Schedule a verification call |
| POST | /admin/users/verified-trader/:userId/decide |
Approve or reject |
| POST | /admin/event/addevent |
Create an event |
| GET / PUT / DELETE |
/admin/event/:eventId/geteventbyid, .../updateEvent, .../deleteEvent
|
Manage an event |
| POST | /admin/event/:eventId/register |
Event registration (called by the frontend registration modal) |
| POST | /admin/spreads/refresh |
Run the Myfxbook scrape now |
| PUT | /admin/spreads/override |
Manually set spreads for a broker |
GET /ping returns pong. Static files in backend/public/ are served from the root.
XK Trading Floor