Developers
Public API
Every page on this site reads from the same versioned JSON API. Public endpoints are open; member and admin endpoints need a session.
Endpoints
- GET
/api/v1/statsHeadline numbers for the lab.
- GET
/api/v1/researchResearch directions.
- GET
/api/v1/research/:slugOne research direction with its related publications.
- GET
/api/v1/publicationsPublications, newest first, with facets.
params: q, kind (journal|conference|article), year, area, limit
- GET
/api/v1/membersLab members (principal investigator for now).
- GET
/api/v1/pioneersPioneers of cryptography and blockchain, with photo credits.
- GET
/api/v1/newsBlog posts (protocols, paper reviews, incident analyses, news), newest first. POST (member) starts a draft; admins publish directly. mine=1: your own posts; all=1 (admin): every state.
params: kind, limit, mine, all
- GET
/api/v1/news/:slugOne published post (by slug, or by id for its author and admins). PATCH and DELETE …/:id: the author until it is published, admins always.
- POST
/api/v1/news/:id/submitmemberSend your draft for review (emails the admins). POST …/withdraw takes it back.
- POST
/api/v1/news/:id/reviewadmin{ decision: approve | reject, note } — publish today, or send back with a note (emails the author).
- POST
/api/v1/imagesmemberUpload an image for a post (multipart `file`, PNG/JPEG/GIF/WebP, max 4 MB); GET /api/v1/images/:key serves it.
- POST
/api/v1/applicationsApply to join the lab (rate-limited). GET (admin) lists applications; PATCH/DELETE …/:id.
- GET
/api/v1/healthLiveness check.
- POST
/api/v1/auth/loginSign in with an account created by the admin (sets a session cookie).
- POST
/api/v1/auth/logoutmemberSign out.
- POST
/api/v1/auth/change-passwordmemberReplace the temporary password.
- GET
/api/v1/meThe signed-in account, or null for visitors.
- GET
/api/v1/me/tasksmemberOpen tasks assigned to me or to my whole group.
- GET
/api/v1/me/activitymemberWhat others did on my walls since I last looked (the red dot on My wall). POST { scope: "lab" | groupId } marks one as read.
- GET
/api/v1/groupsmemberMy groups (admins see all).
- GET
/api/v1/groups/:idmemberOne group with its members.
- GET
/api/v1/groups/:id/tasksmemberTasks of a group; POST creates one (admin or lead).
- GET
/api/v1/groups/:id/postsmemberThe group wall; POST adds a note (announcements: admin or lead).
- GET
/api/v1/groups/:id/linksmemberOverleaf, GitHub and other links. POST adds one: group-wide (admin or lead) or on a task you work on.
- DELETE
/api/v1/links/:idmemberRemove a link (whoever added it, a lead or the admin).
- GET
/api/v1/groups/:id/attachmentsmemberFiles on the wall. POST multipart `file` (PDF or image, max 10 MB) and optional `taskId`.
- POST
/api/v1/groups/:id/attachments/directmemberStart a direct upload `{ size, mime, taskId? }`: returns a signed URL to PUT the file to, then POST `{ key, name, taskId? }` to /groups/:id/attachments.
- GET
/api/v1/attachments/:idmemberDownload a file (group members only); DELETE removes it.
params: download
- PATCH
/api/v1/tasks/:idmemberUpdate a task. Members may only change the status of their own tasks.
- GET
/api/v1/tasks/:id/commentsmemberComments on a task; POST adds one.
- GET
/api/v1/profiles/mememberYour profile for the editor (admin: /profiles/:userId). PUT saves it: portfolio link or CV sections, template, published.
- GET
/api/v1/meetingsmemberLab meetings with their presenters. POST (admin) schedules one and emails every member; PATCH/DELETE …/:id.
params: when (upcoming|past)
- GET
/api/v1/announcementsmemberLab-wide announcements. POST (admin) posts one and emails every member.
- GET
/api/v1/admin/authorsadminPosts per author: published, waiting, sent back, drafts, latest date.
params: format (json|csv)
- GET
/api/v1/admin/presentersadminWho presented how often and when last, longest-ago first.
- GET
/api/v1/admin/publicationsadminEvery paper with its source and hidden flag. POST adds one; PATCH …/:id edits it or sets { hidden }; DELETE removes one added here.
- GET
/api/v1/admin/usersadminAll accounts; POST creates one and returns a temporary password.
- PATCH
/api/v1/admin/users/:idadminChange role, title or deactivate; DELETE removes the account for good. POST …/reset-password issues a new temporary password.
- POST
/api/v1/admin/groupsadminCreate a group; PATCH …/:id renames, edits or archives, DELETE …/:id removes it with its wall and files, PUT …/:id/members sets members and leads.
- GET
/api/v1/admin/reportsadminMonthly progress per paper group and member.
params: month (YYYY-MM), format (json|csv)
- GET
/api/v1/admin/digestadminPreview this Monday's deadline emails; POST sends them now.
Pick an endpoint and press ▶
Response shape
200 { "data": …, "meta": { count, … } } 4xx { "error": { code, message } }