ONHOST.UK

Application API

Use the documented JSON routes that ship with ONHOST CMS and rely on session, CSRF and provider verification controls.

## API model ONHOST CMS exposes JSON endpoints under `/api`. Customer dashboard and administration actions use the authenticated session plus CSRF protection. Payment providers use their dedicated webhook endpoints and must be verified server-side. ## Public endpoints ``` GET /api/bootstrap GET /api/store/products GET /api/store/products/{slug} GET /api/store/currencies GET /api/docs/articles GET /api/docs/articles/{slug} ``` ## Customer endpoints ``` GET /api/dashboard/orders GET /api/dashboard/invoices GET /api/dashboard/downloads POST /api/dashboard/downloads/{id}/signed-url POST /api/dashboard/downloads/{id}/license GET /api/dashboard/tickets POST /api/dashboard/tickets ``` The dashboard download APIs require an authenticated customer and a current CSRF token for state-changing operations. A customer should always request a new signed URL instead of reusing a saved link. ## Licensing endpoints ``` POST /api/license/activate POST /api/license/validate POST /api/license/deactivate ``` Protected packages send a product slug, licence key, domain, installation fingerprint and nonce. These endpoints return JSON and a signed lease when the licence is valid. They return a clear 4xx or 503 response when a key is invalid, a module is disabled, or the signing service is temporarily unavailable; they should never return an HTML error page to a product runtime. ## Error handling Read the JSON `message`, `title`, `hints` and `supportCode` fields. Do not expose development errors to end users. For a persistent 5xx response, retain the support code and timestamp, then check the PHP error log and affected provider configuration.