Authentication
Admin login and session management
Loading API documentation…
Version 1.0.0
RESTful API for the Chinni Treasure — Little Love luxury e-commerce platform. Supports product catalog browsing, order placement and tracking, admin dashboard analytics, and secure JWT-based administrator authentication.
/api/auth/loginAuthentication
adminLoginapplication/jsonAdmin username
Admin password
{
"username": "admin",
"password": "your-password"
}Login successful. Sets HttpOnly session cookie.
Missing required fields
Invalid credentials
Rate limited — 5 attempts per minute per IP
/api/auth/logoutAuthentication
adminLogoutSession cookie cleared
/api/auth/meAuthentication
getSessionUser is authenticated
No valid session
/api/categoriesCategories
listCategoriesArray of categories
Server error
/api/categoriesCategories
createCategoryapplication/jsonKebab-case slug. Auto-generated from name if omitted.
Category created
Validation error
Unauthorized
Slug already exists
/api/categories/latestCategories
Returns the newest in-stock, active product for every active category. Uses a single nested query to avoid N+1.
latestPerCategoryArray of { category, product } envelopes
Server error
/api/categories/{id}Categories
updateCategoryapplication/jsonCategory updated
Validation error
Unauthorized
Category not found
Slug already exists
/api/categories/{id}Categories
deleteCategoryCategory deleted
Unauthorized
Category not found
Category has active products and cannot be deleted
/api/category/{slug}/productsCategories
categoryProductsPaginated products for the category
Category not found or inactive
Server error
/api/gift-boxesProducts
listGiftBoxesArray of active, in-stock gift-box products
Server error
/api/productsProducts
listProductsPaged envelope of active products with category info
Unauthorized — isActive=all|inactive without an admin session
/api/productsProducts
createProductAdmin session requiredapplication/jsonStock keeping unit
Product name
Current selling price
Original/comparison price (MRP) for showing discounts
Allow customers to attach gift boxes to this product
Product created successfully
Name and price are required
Unauthorized
/api/products/{id}Products
updateProductAdmin session requiredapplication/jsonOriginal/comparison price (MRP) for showing discounts
Allow customers to attach gift boxes to this product. Cannot be enabled on Gift Box category products.
Product updated
Unauthorized
/api/products/{id}Products
deleteProductAdmin session requiredProduct deactivated
Unauthorized
/api/ordersOrders
listOrdersAdmin session requiredPaginated list of orders
Unauthorized
/api/ordersOrders
createOrderapplication/json10-digit phone
2-letter Indian state code
6-digit PIN
Razorpay payment id (pay_…) for razorpay payments, or the bank-transfer reference for manual payments
Which channel recorded transactionId. Razorpay placements are verified against the gateway (paid == stored).
Razorpay order id (order_…) the payment was made against. Required for razorpay payments.
Order created successfully
Missing required fields, insufficient stock, payment not completed, or paid amount does not match the order total
Product not found
Conflict — retry your order
/api/orders/{id}Orders
getOrderFull order with items and status history
Order not found
/api/orders/{id}/statusOrders
updateOrderStatusAdmin session requiredapplication/jsonRequired when status is 'shipped'
For optimistic concurrency control
Order status updated
Tracking ID required for shipped, or invalid transition
Unauthorized
Order not found
Version conflict — order was modified by another request
/api/orders/{id}/trackingOrders
Sets or replaces the tracking ID. Sends `expectedVersion` for optimistic concurrency; a stale value answers 409.
updateOrderTrackingAdmin session requiredapplication/jsonOrder with the new tracking ID
Tracking ID is required
Unauthorized
Order not found
Version conflict — order was modified by another request
/api/create-orderPayments
Amount is in rupees. Rate limited to 5 attempts per IP per window; the Payment module converts to paise and owns the minimum-order policy. The response's `order_id` is what `POST /api/verify-payment` later checks the signature against.
createRazorpayOrderapplication/jsonAmount in rupees
Razorpay order created
Invalid body
Origin check failed
Rate limited
/api/verify-paymentPayments
Server-side HMAC check of the three fields Razorpay returns after checkout. Never treat the client as authoritative — this response is the verdict.
verifyRazorpayPaymentapplication/jsonSignature verified
Missing fields or signature mismatch
Origin check failed
/api/statsAnalytics
getDashboardStatsAdmin session requiredDashboard stats, chart data, and product sales
Unauthorized
/api/trackTracking
trackOrderMatching orders with item details
Provide orderId or phone parameter