Funcionalidades e Endpoints HTTP
Este documento lista todas as funcionalidades do produto e todos os endpoints HTTP da API, agrupados por domínio. É gerado automaticamente a partir da fonte única de verdade — workers/src/routes/registry.ts — então nunca fica defasado em relação ao código. Não edite à mão: mudanças em rotas são refletidas ao rodar pnpm docs:endpoints.
A API expõe 102 operações em 82 caminhos distintos, agrupadas em 25 domínios.
Funcionalidades
| Funcionalidade | Domínios | O que faz |
|---|---|---|
| Chamada e Presença | Attendance, Check-in, Class Sessions | Marcação de presença e chamada, com check-in/out por código de convite. |
| Alunos | Students, Photos, Occurrences | CRUD de alunos (soft-delete com justificativa), fotos em R2 e ocorrências. |
| Turmas, Aulas e Vagas | Classes, Class Slots, Waiting List, Capacity | Turmas por faixa etária, slots e sessões de aula, lista de espera e capacidade. |
| Núcleos | Nuclei | Núcleos (pequenos grupos) em 7 regiões fixas. |
| Portaria e Retirada | Check-in, Authorized Pickup | Check-in, autorização de retirada com OTP e responsáveis autorizados. |
| Eventos e Inscrições | Events | Eventos públicos, inscrição de alunos/responsáveis e gestão administrativa. |
| Onboarding de Alunos | Onboarding | Auto-cadastro de alunos via convite com hash, consentimento LGPD e verificação OTP. |
| Relatórios | Reports | Relatórios de frequência e análise para usuários com permissão de relatórios. |
| Usuários, Papéis e Credenciais | Users, Roles, Credentials | Ciclo de vida de usuários, papéis (RBAC) e gestão de credenciais. |
| Notificações | Notifications | Notificações e anúncios entregues por canal (ex.: painel TV). |
| Sincronização Offline | Sync | Sincronização offline: wrapper batch e evento único atômico via D1.batch(). |
| Consentimentos LGPD | Consent | Registro de consentimentos (imagem e dados), com revogação e trilha de auditoria. |
| Armazenamento de Arquivos | Storage | Proxy de armazenamento para uploads e leituras (R2). |
| Autenticação e Saúde do Serviço | Auth, Health, License | Login, refresh e revogação de sessão; health check e licenciamento de módulos. |
Endpoints por domínio
Attendance
| Método | Rota | Autenticação | O que faz | Códigos |
|---|---|---|---|---|
GET | /api/v1/attendance/feed | Público | Live attendance event feed (SSE) | 200 |
Auth
| Método | Rota | Autenticação | O que faz | Códigos |
|---|---|---|---|---|
POST | /api/v1/auth/login | Público | Authenticate user · rate limit 5/min | 200, 401 |
POST | /api/v1/auth/refresh | Público | Refresh access token · rate limit 10/min | 200, 401 |
POST | /api/v1/auth/revoke | Autenticado | Revoke session | 204, 401 |
POST | /api/v1/session/validate | Autenticado | Validate session · rate limit 30/min | 200, 401 |
Authorized Pickup
| Método | Rota | Autenticação | O que faz | Códigos |
|---|---|---|---|---|
GET | /api/v1/students/:studentId/authorized-pickups | ADMIN | List authorized pickup adults for a child · rate limit 60/min | 200, 401, 403, 404 |
POST | /api/v1/authorized-pickups/:pickupId/deactivate | ADMIN | Deactivate (soft-delete) an authorized pickup entry · rate limit 10/min | 200, 400, 401, 403, 404, 409 |
DELETE | /api/v1/authorized-pickups/:pickupId | ADMIN | Erase an authorized pickup entry (LGPD) · rate limit 10/min | 200, 400, 401, 403, 404, 409 |
POST | /api/v1/students/:studentId/authorized-pickups/add | Permissão students.add | Add an adult to the pickup list (basic account + phone OTP) · rate limit 30/min | 200, 400, 403, 404, 409 |
POST | /api/v1/authorized-pickups/verify-otp | Permissão students.add | Verify the add-flow phone OTP and create the ACTIVE pickup entry · rate limit 60/min | 200, 400, 401, 403, 404, 409, 410, 429 |
POST | /api/v1/students/:studentId/pickup-authorizations | Permissão students.add | Authorize an adult for the day (temporary, parent-present) · rate limit 30/min | 201, 400, 401, 403, 404 |
GET | /api/v1/students/:studentId/pickup-authorizations | Permissão students.add | List currently valid temporary pickup authorizations for a child · rate limit 60/min | 200, 401, 403, 404 |
POST | /api/v1/pickup-authorizations/:authorizationId/revoke | Permissão students.add | Revoke a temporary pickup authorization · rate limit 10/min | 200, 400, 401, 403, 404, 409 |
Capacity
| Método | Rota | Autenticação | O que faz | Códigos |
|---|---|---|---|---|
GET | /api/v1/capacity/snapshot | Público | Capacity snapshot JSON | 200 |
GET | /api/v1/capacity/feed | Público | Live capacity dashboard feed (SSE) | 200 |
PATCH | /api/v1/class-slots/:id | ADMIN | Update slot capacity | 200, 400, 403, 404, 409 |
Check-in
| Método | Rota | Autenticação | O que faz | Códigos |
|---|---|---|---|---|
POST | /api/v1/check-in | ADMIN, CHAMADOR | Register child check-in · rate limit 60/min | 201, 400, 401, 403, 404, 409 |
POST | /api/v1/check-out | ADMIN, CHAMADOR | Check out child with daily code · rate limit 60/min | 200, 400, 401, 403, 404, 409, 423 |
POST | /api/v1/check-out/emergency | ADMIN, CHAMADOR | Emergency checkout (bypass code) · rate limit 30/min | 200, 400, 401, 403, 404, 409 |
GET | /api/v1/check-in/active | ADMIN, CHAMADOR | Get active check-in · rate limit 60/min | 200, 400, 401, 403, 404 |
POST | /api/v1/check-in/by-code | ADMIN, CHAMADOR | Resolve active check-in by daily code · rate limit 120/min | 200, 404, 400, 401, 403 |
GET | /api/v1/church/check-in-config | ADMIN, CHAMADOR | Get church check-in configuration · rate limit 60/min | 200, 401, 403 |
PUT | /api/v1/church/check-in-config | ADMIN | Update church check-in configuration · rate limit 30/min | 200, 400, 401, 403, 409 |
GET | /api/v1/church/daily-secret | ADMIN, CHAMADOR | Get today's daily check-in secret | 200, 401 |
Class Sessions
| Método | Rota | Autenticação | O que faz | Códigos |
|---|---|---|---|---|
GET | /api/v1/class-sessions | Autenticado | List class sessions · rate limit 60/min | 200, 401 |
POST | /api/v1/class-sessions | ADMIN, CADASTRO | Create class session · rate limit 30/min | 201, 400, 401, 403, 409 |
Class Slots
| Método | Rota | Autenticação | O que faz | Códigos |
|---|---|---|---|---|
GET | /api/v1/class-slots | Autenticado | List class slots · rate limit 60/min | 200, 401 |
POST | /api/v1/class-slots | ADMIN, CADASTRO | Create class slot · rate limit 30/min | 201, 400, 401, 403, 409 |
PATCH | /api/v1/class-slots/:slotId | ADMIN, CADASTRO | Update class slot · rate limit 30/min | 200, 400, 401, 403, 404, 409 |
DELETE | /api/v1/class-slots/:slotId | ADMIN | Delete class slot (soft) · rate limit 10/min | 200, 400, 401, 403, 404, 409 |
Classes
| Método | Rota | Autenticação | O que faz | Códigos |
|---|---|---|---|---|
GET | /api/v1/classes | Autenticado | List classes · rate limit 60/min | 200, 401 |
POST | /api/v1/classes | ADMIN | Create class · rate limit 30/min | 201, 400, 401, 403, 409 |
PATCH | /api/v1/classes/:classId | ADMIN | Update class · rate limit 30/min | 200, 400, 401, 403, 404, 409 |
POST | /api/v1/classes/:classId/delete | ADMIN | Delete class (soft) · rate limit 10/min | 200, 400, 401, 403, 404, 409 |
POST | /api/v1/classes/:classId/waiting-list | ADMIN, RESPONSAVEL | Join class waiting list | 201, 400, 403, 409 |
DELETE | /api/v1/classes/:classId/waiting-list/:id | Autenticado | Leave class waiting list | 200, 400, 403, 404, 409 |
GET | /api/v1/classes/:classId/waiting-list | ADMIN | List class waiting list | 200, 403 |
GET | /api/v1/classes/alternatives | Autenticado | Find alternative classes with available capacity | 200, 400, 404 |
Consent
| Método | Rota | Autenticação | O que faz | Códigos |
|---|---|---|---|---|
POST | /api/v1/image-consents | ADMIN, CADASTRO | Register an image consent acceptance · rate limit 30/min | 201, 400, 401, 403, 409 |
GET | /api/v1/image-consents | ADMIN, CADASTRO | Get a subject's consent state and history · rate limit 60/min | 200, 400, 401, 403 |
POST | /api/v1/image-consents/:consentId/revoke | ADMIN | Revoke an image consent acceptance · rate limit 10/min | 200, 400, 401, 403, 404, 409 |
Credentials
| Método | Rota | Autenticação | O que faz | Códigos |
|---|---|---|---|---|
GET | /api/v1/credentials | ADMIN, CHAMADOR | Get active credential for a student | 200, 400, 401 |
POST | /api/v1/credentials | ADMIN, CADASTRO | Issue a credential for a student | 201, 400, 401, 403, 404, 409 |
POST | /api/v1/credentials/lookup | ADMIN, CHAMADOR | Lookup student by credential value | 200, 400, 401, 404 |
Events
| Método | Rota | Autenticação | O que faz | Códigos |
|---|---|---|---|---|
GET | /api/v1/events | Público | List public events | 200 |
GET | /api/v1/events/:eventId | Público | Get event details | 200, 404 |
POST | /api/v1/events/:eventId/register | Público | Register for event · rate limit 5/min | 201, 400, 409 |
GET | /api/v1/events/:eventId/register/:regId | Público | Get registration status | 200, 404 |
POST | /api/v1/events/:eventId/proof | Público | Upload payment proof · rate limit 3/min | 201, 400, 409, 500 |
POST | /api/v1/events | ADMIN, CADASTRO | Create event | 201, 400, 401, 403, 409 |
PUT | /api/v1/events/:eventId | ADMIN, CADASTRO | Update event | 200, 400, 401, 403, 404, 409 |
DELETE | /api/v1/events/:eventId | ADMIN | Delete event | 200, 400, 401, 403, 404, 409 |
POST | /api/v1/events/:eventId/clone | ADMIN, CADASTRO | Clone event | 201, 400, 401, 403, 404, 409 |
GET | /api/v1/events/:eventId/registrations | ADMIN, CADASTRO | List registrations | 200, 401, 403, 404 |
POST | /api/v1/events/:eventId/registrations/:regId/approve | ADMIN | Approve registration | 200, 400, 401, 403, 404, 409 |
POST | /api/v1/events/:eventId/registrations/:regId/reject | ADMIN | Reject registration | 200, 400, 401, 403, 404, 409 |
Health
| Método | Rota | Autenticação | O que faz | Códigos |
|---|---|---|---|---|
GET | /api/v1/health | Público | Health check | 200 |
GET | /.well-known/security.txt | Público | Security contact information (RFC 9116) | 200 |
License
| Método | Rota | Autenticação | O que faz | Códigos |
|---|---|---|---|---|
GET | /api/v1/license | Público | License entitlements | 200 |
Notifications
| Método | Rota | Autenticação | O que faz | Códigos |
|---|---|---|---|---|
POST | /api/v1/notifications | ADMIN, CADASTRO | Create notification (alert for TV screen) · rate limit 30/min | 201, 400, 401, 403, 409, 429 |
GET | /api/v1/notifications/feed | Público | SSE feed for TV screen · rate limit 5/min | 200, 401 |
GET | /api/v1/notifications/history | ADMIN, CADASTRO | Today's notification history · rate limit 30/min | 200, 401, 403 |
POST | /api/v1/notifications/:id/read | ADMIN, CADASTRO | Mark notification as read · rate limit 30/min | 200, 400, 401, 403, 409 |
Nuclei
| Método | Rota | Autenticação | O que faz | Códigos |
|---|---|---|---|---|
GET | /api/v1/nuclei | Autenticado | List nuclei · rate limit 60/min | 200, 401 |
POST | /api/v1/nuclei | ADMIN | Create nucleus · rate limit 30/min | 201, 400, 401, 403, 409 |
PATCH | /api/v1/nuclei/:nucleusId | ADMIN | Update nucleus · rate limit 30/min | 200, 400, 401, 403, 404, 409 |
POST | /api/v1/nuclei/:nucleusId/delete | ADMIN | Delete nucleus (soft) · rate limit 10/min | 200, 400, 401, 403, 404, 409 |
Occurrences
| Método | Rota | Autenticação | O que faz | Códigos |
|---|---|---|---|---|
POST | /api/v1/occurrences | Autenticado | Create occurrence · rate limit 30/min | 201, 400, 401, 403, 404 |
GET | /api/v1/occurrences | Autenticado | List occurrences · rate limit 60/min | 200, 401, 403 |
GET | /api/v1/occurrences/:occurrenceId | Autenticado | Get occurrence detail · rate limit 60/min | 200, 400, 401, 403, 404 |
POST | /api/v1/occurrences/:occurrenceId/resolve | Autenticado | Resolve occurrence with a mandatory solution · rate limit 30/min | 200, 400, 401, 403, 404, 409 |
POST | /api/v1/occurrences/:occurrenceId/telao | Autenticado | Trigger the TV screen for an occurrence (ADMIN) · rate limit 30/min | 200, 400, 401, 403, 404, 409 |
Onboarding
| Método | Rota | Autenticação | O que faz | Códigos |
|---|---|---|---|---|
GET | /api/v1/onboarding/:hash | Público | Validar link de onboarding · rate limit 10/min | 200, 404, 410, 429 |
POST | /api/v1/onboarding/:hash/request-otp | Público | Solicitar código OTP · rate limit 3/min | 200, 400, 404, 409, 410 |
POST | /api/v1/onboarding/:hash/verify-otp | Público | Verificar código OTP · rate limit 10/min | 200, 400, 401, 404, 409, 410, 429 |
POST | /api/v1/onboarding/:hash/submit | Público | Submeter dados do aluno · rate limit 3/min | 201, 400, 401, 404, 409, 410 |
POST | /api/v1/onboarding/links | ADMIN, CADASTRO | Gerar link de onboarding | 201, 400, 401, 403, 409 |
GET | /api/v1/onboarding/drafts | ADMIN, CADASTRO | Listar rascunhos pendentes | 200, 401, 403 |
GET | /api/v1/onboarding/drafts/:id | ADMIN, CADASTRO | Ver detalhes do rascunho | 200, 401, 403, 404 |
POST | /api/v1/onboarding/drafts/:id/approve | ADMIN, CADASTRO | Aprovar rascunho | 200, 400, 401, 403, 404, 409 |
POST | /api/v1/onboarding/drafts/:id/reject | ADMIN, CADASTRO | Rejeitar rascunho | 200, 400, 401, 403, 404, 409 |
Photos
| Método | Rota | Autenticação | O que faz | Códigos |
|---|---|---|---|---|
POST | /api/v1/students/:studentId/photos | ADMIN, CADASTRO | Upload a student face photo · rate limit 30/min | 201, 400, 401, 403, 404, 500 |
DELETE | /api/v1/students/:studentId/photos | ADMIN, CADASTRO | Delete student face photos · rate limit 30/min | 200, 400, 401, 403, 404, 500 |
POST | /api/v1/users/:userId/photos | ADMIN, CADASTRO | Upload an adult (guardian) face photo · rate limit 30/min | 201, 400, 401, 403, 404, 500 |
DELETE | /api/v1/users/:userId/photos | ADMIN, CADASTRO | Delete adult (guardian) face photos · rate limit 30/min | 200, 400, 401, 403, 404, 500 |
Reports
| Método | Rota | Autenticação | O que faz | Códigos |
|---|---|---|---|---|
GET | /api/v1/reports/events | Autenticado | Reports event data (attendance + student audit) · rate limit 60/min | 200, 401 |
Roles
| Método | Rota | Autenticação | O que faz | Códigos |
|---|---|---|---|---|
GET | /api/v1/roles | ADMIN | List roles · rate limit 60/min | 200, 401, 403 |
POST | /api/v1/roles | ADMIN | Create role · rate limit 30/min | 201, 400, 401, 403, 409 |
PATCH | /api/v1/roles/:roleName | ADMIN | Update role permissions · rate limit 30/min | 200, 400, 401, 403, 404, 409 |
DELETE | /api/v1/roles/:roleName | ADMIN | Delete role · rate limit 10/min | 200, 400, 401, 403, 404, 409 |
Storage
| Método | Rota | Autenticação | O que faz | Códigos |
|---|---|---|---|---|
POST | /api/v1/storage/proxy | Autenticado | Proxy SQL to D1 · rate limit 300/min | 200, 400, 401, 403, 409, 429 |
Students
| Método | Rota | Autenticação | O que faz | Códigos |
|---|---|---|---|---|
GET | /api/v1/students | Autenticado | List students · rate limit 60/min | 200, 401 |
POST | /api/v1/students | ADMIN, CADASTRO | Create student · rate limit 30/min | 201, 400, 401, 403, 409 |
PATCH | /api/v1/students/:studentId | ADMIN, CADASTRO | Update student · rate limit 30/min | 200, 400, 401, 403, 404, 409 |
POST | /api/v1/students/:studentId/delete | ADMIN | Delete student (soft) · rate limit 10/min | 200, 400, 401, 403, 404, 409 |
Sync
| Método | Rota | Autenticação | O que faz | Códigos |
|---|---|---|---|---|
POST | /api/v1/sync/event | Autenticado | Processa 1 evento de sync atomicamente via D1.batch() · rate limit 60/min | 200, 400, 401, 409, 422 |
POST | /api/v1/sync/events | Autenticado | Batch sync events · rate limit 60/min | 200, 400, 401, 422 |
Users
| Método | Rota | Autenticação | O que faz | Códigos |
|---|---|---|---|---|
GET | /api/v1/users | ADMIN | List users · rate limit 60/min | 200, 401, 403 |
POST | /api/v1/users | ADMIN | Create user · rate limit 30/min | 201, 400, 401, 403, 409 |
PATCH | /api/v1/users/:userId | ADMIN | Update user · rate limit 30/min | 200, 400, 401, 403, 404, 409 |
POST | /api/v1/users/:userId/reset-password | ADMIN | Reset user password · rate limit 10/min | 200, 400, 401, 403, 404, 409 |
POST | /api/v1/users/:userId/deactivate | ADMIN | Deactivate user · rate limit 10/min | 200, 400, 401, 403, 409 |
Fonte: workers/src/routes/registry.ts — regenerado por pnpm docs:endpoints em 2026-09-13.