Application API
Use the documented JSON routes that ship with ONHOST CMS and rely on session, CSRF and provider verification controls.
## API model
ONHOST CMS exposes JSON endpoints under `/api`. Customer dashboard and administration actions use the authenticated session plus CSRF protection. Payment providers use their dedicated webhook endpoints and must be verified server-side.
## Public endpoints
```
GET /api/bootstrap
GET /api/store/products
GET /api/store/products/{slug}
GET /api/store/currencies
GET /api/docs/articles
GET /api/docs/articles/{slug}
```
## Customer endpoints
```
GET /api/dashboard/orders
GET /api/dashboard/invoices
GET /api/dashboard/downloads
POST /api/dashboard/downloads/{id}/signed-url
POST /api/dashboard/downloads/{id}/license
GET /api/dashboard/tickets
POST /api/dashboard/tickets
```
The dashboard download APIs require an authenticated customer and a current CSRF token for state-changing operations. A customer should always request a new signed URL instead of reusing a saved link.
## Licensing endpoints
```
POST /api/license/activate
POST /api/license/validate
POST /api/license/deactivate
```
Protected packages send a product slug, licence key, domain, installation fingerprint and nonce. These endpoints return JSON and a signed lease when the licence is valid. They return a clear 4xx or 503 response when a key is invalid, a module is disabled, or the signing service is temporarily unavailable; they should never return an HTML error page to a product runtime.
## Error handling
Read the JSON `message`, `title`, `hints` and `supportCode` fields. Do not expose development errors to end users. For a persistent 5xx response, retain the support code and timestamp, then check the PHP error log and affected provider configuration.