This is a reference implementation for security testing. The server owns all money, prices, and rewards — clients can only request actions.
▶ Play GLOBAL (web client) Staff admin panel
● Service healthy — /healthz
| Method | Path | Auth | Purpose |
|---|---|---|---|
| POST | /auth/register | none | Create account + character |
| POST | /auth/login | none | Get access + refresh tokens |
| POST | /auth/refresh | none | Rotate refresh token |
| POST | /auth/password | Bearer | Change password (revokes sessions) |
| POST | /auth/recover + /auth/recover/confirm | none | Password recovery (simulated email) |
| POST | /auth/verify-email + /auth/verify-email/confirm | Bearer/none | Email verification (simulated) |
| GET/DELETE | /auth/sessions[/:id] | Bearer | List / revoke own sessions |
| GET | /me | Bearer | Account + balance |
| POST | /me/delete | Bearer | Self-service account deletion |
| GET | /me/transactions | Bearer | Own ledger entries |
| GET | /me/properties | Bearer | Owned properties |
| GET | /economy/balance | Bearer | Read own balance |
| POST | /economy/transfer | Bearer | Send credits (idempotent, velocity-limited) |
| POST | /economy/purchase-property | Bearer | Buy at server-set price |
| POST | /economy/complete-job | Bearer | Server-decided reward |
| GET | /properties/available | none | List properties + prices |
| POST | /reports | Bearer | Report a player (rate-limited) |
| POST | /admin/grants | Bearer (admin) | Grant; large amounts need dual control |
| GET/POST | /admin/grants/pending, /admin/grants/:id/approve|reject | Bearer (admin) | Approve/reject pending grants |
| GET | /admin/accounts[/:id] | Bearer (admin) | Account search + detail |
| POST | /admin/accounts/:id/status|role | Bearer (admin) | Suspend/delete accounts, change roles |
| GET/POST | /admin/reports, /admin/reports/:id/resolve | Bearer (admin/mod) | Moderation queue |
| POST | /admin/reconcile | Bearer (admin) | Verify balances == ledger sums |
| GET | /admin/anomalies | Bearer (admin) | Anti-cheat detection output |
| GET | /admin/transactions | Bearer (admin) | Global ledger view |
| POST | /admin/grant | Bearer (admin) | Legacy grant (dual-control applies) |
| GET | /admin/audit | Bearer (admin/mod) | Read audit log |
| GET | /metrics | Bearer (admin) | Service metrics |
curl -sS ${location.origin}/healthzcurl -sS -X POST ${location.origin}/auth/register -H 'content-type: application/json' -d '{"email":"you@example.com","password":"correct-horse-battery","name":"You"}'
⚠ Testbed note: recovery/verification tokens are returned in the API response instead of being emailed (simulated delivery) so the flows can be tested end-to-end.