Developers

Public API

Every page on this site reads from the same versioned JSON API. Public endpoints are open; member and admin endpoints need a session.

41

Endpoints

  • GET/api/v1/stats

    Headline numbers for the lab.

  • GET/api/v1/research

    Research directions.

  • GET/api/v1/research/:slug

    One research direction with its related publications.

  • GET/api/v1/publications

    Publications, newest first, with facets.

    params: q, kind (journal|conference|article), year, area, limit

  • GET/api/v1/members

    Lab members (principal investigator for now).

  • GET/api/v1/pioneers

    Pioneers of cryptography and blockchain, with photo credits.

  • GET/api/v1/news

    Blog posts (protocols, paper reviews, incident analyses, news), newest first. POST (member) starts a draft; admins publish directly. mine=1: your own posts; all=1 (admin): every state.

    params: kind, limit, mine, all

  • GET/api/v1/news/:slug

    One published post (by slug, or by id for its author and admins). PATCH and DELETE …/:id: the author until it is published, admins always.

  • POST/api/v1/news/:id/submitmember

    Send your draft for review (emails the admins). POST …/withdraw takes it back.

  • POST/api/v1/news/:id/reviewadmin

    { decision: approve | reject, note } — publish today, or send back with a note (emails the author).

  • POST/api/v1/imagesmember

    Upload an image for a post (multipart `file`, PNG/JPEG/GIF/WebP, max 4 MB); GET /api/v1/images/:key serves it.

  • POST/api/v1/applications

    Apply to join the lab (rate-limited). GET (admin) lists applications; PATCH/DELETE …/:id.

  • GET/api/v1/health

    Liveness check.

  • POST/api/v1/auth/login

    Sign in with an account created by the admin (sets a session cookie).

  • POST/api/v1/auth/logoutmember

    Sign out.

  • POST/api/v1/auth/change-passwordmember

    Replace the temporary password.

  • GET/api/v1/me

    The signed-in account, or null for visitors.

  • GET/api/v1/me/tasksmember

    Open tasks assigned to me or to my whole group.

  • GET/api/v1/me/activitymember

    What others did on my walls since I last looked (the red dot on My wall). POST { scope: "lab" | groupId } marks one as read.

  • GET/api/v1/groupsmember

    My groups (admins see all).

  • GET/api/v1/groups/:idmember

    One group with its members.

  • GET/api/v1/groups/:id/tasksmember

    Tasks of a group; POST creates one (admin or lead).

  • GET/api/v1/groups/:id/postsmember

    The group wall; POST adds a note (announcements: admin or lead).

  • GET/api/v1/groups/:id/linksmember

    Overleaf, GitHub and other links. POST adds one: group-wide (admin or lead) or on a task you work on.

  • DELETE/api/v1/links/:idmember

    Remove a link (whoever added it, a lead or the admin).

  • GET/api/v1/groups/:id/attachmentsmember

    Files on the wall. POST multipart `file` (PDF or image, max 10 MB) and optional `taskId`.

  • POST/api/v1/groups/:id/attachments/directmember

    Start a direct upload `{ size, mime, taskId? }`: returns a signed URL to PUT the file to, then POST `{ key, name, taskId? }` to /groups/:id/attachments.

  • GET/api/v1/attachments/:idmember

    Download a file (group members only); DELETE removes it.

    params: download

  • PATCH/api/v1/tasks/:idmember

    Update a task. Members may only change the status of their own tasks.

  • GET/api/v1/tasks/:id/commentsmember

    Comments on a task; POST adds one.

  • GET/api/v1/profiles/memember

    Your profile for the editor (admin: /profiles/:userId). PUT saves it: portfolio link or CV sections, template, published.

  • GET/api/v1/meetingsmember

    Lab meetings with their presenters. POST (admin) schedules one and emails every member; PATCH/DELETE …/:id.

    params: when (upcoming|past)

  • GET/api/v1/announcementsmember

    Lab-wide announcements. POST (admin) posts one and emails every member.

  • GET/api/v1/admin/authorsadmin

    Posts per author: published, waiting, sent back, drafts, latest date.

    params: format (json|csv)

  • GET/api/v1/admin/presentersadmin

    Who presented how often and when last, longest-ago first.

  • GET/api/v1/admin/publicationsadmin

    Every paper with its source and hidden flag. POST adds one; PATCH …/:id edits it or sets { hidden }; DELETE removes one added here.

  • GET/api/v1/admin/usersadmin

    All accounts; POST creates one and returns a temporary password.

  • PATCH/api/v1/admin/users/:idadmin

    Change role, title or deactivate; DELETE removes the account for good. POST …/reset-password issues a new temporary password.

  • POST/api/v1/admin/groupsadmin

    Create a group; PATCH …/:id renames, edits or archives, DELETE …/:id removes it with its wall and files, PUT …/:id/members sets members and leads.

  • GET/api/v1/admin/reportsadmin

    Monthly progress per paper group and member.

    params: month (YYYY-MM), format (json|csv)

  • GET/api/v1/admin/digestadmin

    Preview this Monday's deadline emails; POST sends them now.

try it
GET
Pick an endpoint and press ▶

Response shape

200 { "data": …, "meta": { count, … } }
4xx { "error": { code, message } }