Documentation

    Concepts, value, and typical clone scenarios — less code.

    Welcome to Ring
    Quick Reference
    Getting Started
    Prerequisites
    Installation
    First Success Validation
    Next Steps
    Features
    Multi-Vendor Store
    Inventory & Stock
    Vendor Management
    Commissions & Settlements
    SubscriptionConductor
    PaymentConductor
    Payments Overview
    Public Pools & DAO Jars
    WayForPay Payment Integration
    Wallet & Credit System
    WalletConductor
    Affiliate & Referral Enablement
    Referral Codes (Refcodes)
    NFT Exhibition Marketplace
    Solana NFT Gates
    Token Staking System
    Owner Project Lab
    Entities
    Opportunities
    Real-Time Messaging
    Ring Tasks
    WebRTC Calls & STUNner TURN
    Peer Games
    News Module
    Member Blogs
    Public Profile Pages
    Ring File Cabinet
    Username Reservation System
    Scientific Editor
    Notifications
    Push Notifications with FCM (Ring-Powered)
    Email AI-CRM
    Ring Mailer & RingdomX Mail
    Tunnel Protocol
    VideoConductor
    MediaConductor
    Generative Gallery
    Authentication
    Security & Compliance
    Admin console
    Admin Wiki
    Manage via Telegram
    Locale System
    Mobile Experience
    Performance Optimization Patterns
    Examples
    Quick Start
    Basic Setup
    White Label
    Custom Branding
    Web3 Integration
    Real World
    Advanced Features
    Customization
    Quick Start — Your First Ring Clone
    Customization Guide
    Branding
    Themes
    Features
    Localization
    Token Economics Setup
    Payment Gateway Integration
    Reference Ring deployments
    Web3
    Token launch jurisdictions
    Wallet
    Wallet Security Tips
    Integrations
    Ethereum wallets (Wagmi v3)
    RingFileBase (object storage API)
    Ring CDN (RingFileBase edge)
    Deployment
    Self-hosted deployment
    Vercel
    Docker
    Environment Configuration
    Monitoring & Analytics
    Performance Optimization
    Backup & Recovery
    Architecture
    Data Model
    Security
    Real Time
    Discovery Mutation Sync
    PaymentConductor architecture
    WalletConductor architecture
    Development
    Ring MCP Server

    Quick entry (CTOs · auditors · agents)

    Welcome — mission & audiences
    Quick Reference
    Getting started
    Architecture & Auth.js
    Backend modes & databases (DB_BACKEND_MODE)
    Self-hosted
    Ring MCP Tools
    Ring MCP Server
    Token economics
    Token launch jurisdictions
    Deploy (Docker · k8s)
    Security & compliance reads
    ringdom.org — LegioX homebase
    Source — MIT license (GitHub)

    Documentation

    Concepts, value, and typical clone scenarios — less code.

    Welcome to Ring
    Quick Reference
    Getting Started
    Prerequisites
    Installation
    First Success Validation
    Next Steps
    Features
    Multi-Vendor Store
    Inventory & Stock
    Vendor Management
    Commissions & Settlements
    SubscriptionConductor
    PaymentConductor
    Payments Overview
    Public Pools & DAO Jars
    WayForPay Payment Integration
    Wallet & Credit System
    WalletConductor
    Affiliate & Referral Enablement
    Referral Codes (Refcodes)
    NFT Exhibition Marketplace
    Solana NFT Gates
    Token Staking System
    Owner Project Lab
    Entities
    Opportunities
    Real-Time Messaging
    Ring Tasks
    WebRTC Calls & STUNner TURN
    Peer Games
    News Module
    Member Blogs
    Public Profile Pages
    Ring File Cabinet
    Username Reservation System
    Scientific Editor
    Notifications
    Push Notifications with FCM (Ring-Powered)
    Email AI-CRM
    Ring Mailer & RingdomX Mail
    Tunnel Protocol
    VideoConductor
    MediaConductor
    Generative Gallery
    Authentication
    Security & Compliance
    Admin console
    Admin Wiki
    Manage via Telegram
    Locale System
    Mobile Experience
    Performance Optimization Patterns
    Examples
    Quick Start
    Basic Setup
    White Label
    Custom Branding
    Web3 Integration
    Real World
    Advanced Features
    Customization
    Quick Start — Your First Ring Clone
    Customization Guide
    Branding
    Themes
    Features
    Localization
    Token Economics Setup
    Payment Gateway Integration
    Reference Ring deployments
    Web3
    Token launch jurisdictions
    Wallet
    Wallet Security Tips
    Integrations
    Ethereum wallets (Wagmi v3)
    RingFileBase (object storage API)
    Ring CDN (RingFileBase edge)
    Deployment
    Self-hosted deployment
    Vercel
    Docker
    Environment Configuration
    Monitoring & Analytics
    Performance Optimization
    Backup & Recovery
    Architecture
    Data Model
    Security
    Real Time
    Discovery Mutation Sync
    PaymentConductor architecture
    WalletConductor architecture
    Development
    Ring MCP Server

    Quick entry (CTOs · auditors · agents)

    Welcome — mission & audiences
    Quick Reference
    Getting started
    Architecture & Auth.js
    Backend modes & databases (DB_BACKEND_MODE)
    Self-hosted
    Ring MCP Tools
    Ring MCP Server
    Token economics
    Token launch jurisdictions
    Deploy (Docker · k8s)
    Security & compliance reads
    ringdom.org — LegioX homebase
    Source — MIT license (GitHub)

    Documentation

    Concepts, value, and typical clone scenarios — less code.

    Welcome to Ring
    Quick Reference
    Getting Started
    Prerequisites
    Installation
    First Success Validation
    Next Steps
    Features
    Multi-Vendor Store
    Inventory & Stock
    Vendor Management
    Commissions & Settlements
    SubscriptionConductor
    PaymentConductor
    Payments Overview
    Public Pools & DAO Jars
    WayForPay Payment Integration
    Wallet & Credit System
    WalletConductor
    Affiliate & Referral Enablement
    Referral Codes (Refcodes)
    NFT Exhibition Marketplace
    Solana NFT Gates
    Token Staking System
    Owner Project Lab
    Entities
    Opportunities
    Real-Time Messaging
    Ring Tasks
    WebRTC Calls & STUNner TURN
    Peer Games
    News Module
    Member Blogs
    Public Profile Pages
    Ring File Cabinet
    Username Reservation System
    Scientific Editor
    Notifications
    Push Notifications with FCM (Ring-Powered)
    Email AI-CRM
    Ring Mailer & RingdomX Mail
    Tunnel Protocol
    VideoConductor
    MediaConductor
    Generative Gallery
    Authentication
    Security & Compliance
    Admin console
    Admin Wiki
    Manage via Telegram
    Locale System
    Mobile Experience
    Performance Optimization Patterns
    Examples
    Quick Start
    Basic Setup
    White Label
    Custom Branding
    Web3 Integration
    Real World
    Advanced Features
    Customization
    Quick Start — Your First Ring Clone
    Customization Guide
    Branding
    Themes
    Features
    Localization
    Token Economics Setup
    Payment Gateway Integration
    Reference Ring deployments
    Web3
    Token launch jurisdictions
    Wallet
    Wallet Security Tips
    Integrations
    Ethereum wallets (Wagmi v3)
    RingFileBase (object storage API)
    Ring CDN (RingFileBase edge)
    Deployment
    Self-hosted deployment
    Vercel
    Docker
    Environment Configuration
    Monitoring & Analytics
    Performance Optimization
    Backup & Recovery
    Architecture
    Data Model
    Security
    Real Time
    Discovery Mutation Sync
    PaymentConductor architecture
    WalletConductor architecture
    Development
    Ring MCP Server

    Quick entry (CTOs · auditors · agents)

    Welcome — mission & audiences
    Quick Reference
    Getting started
    Architecture & Auth.js
    Backend modes & databases (DB_BACKEND_MODE)
    Self-hosted
    Ring MCP Tools
    Ring MCP Server
    Token economics
    Token launch jurisdictions
    Deploy (Docker · k8s)
    Security & compliance reads
    ringdom.org — LegioX homebase
    Source — MIT license (GitHub)
    1. Docs
    2. /API Reference

    Updated Jul 10, 20265 min listen

    Ring Platform Logo

    Завантаження документації...

    Підготовка контенту платформи Ring

    1. Docs
    2. /API Reference

    Updated Jul 10, 20265 min listen

    Ring Platform Logo

    Завантаження документації...

    Підготовка контенту платформи Ring

    1. Docs
    2. /API Reference

    Updated Jul 10, 20265 min listen

    Ring Platform Logo

    Завантаження документації...

    Підготовка контенту платформи Ring

    API Reference

    Ring Platform exposes ~244 App Router route handlers under /api/* — the live surface your clone, mobile clients, cron jobs, webhooks, and MCP agents call. This page is the map: founders browse capabilities; developers get auth rules, domain docs, and verified path families.

    Use the Founder / Developer tabs in the docs sidebar. Founders get a visual API tree; developers get contracts, secrets, and deep links into domain pages.

    What the API is (in plain language)

    An API endpoint is a named door on your Ring server. The browser, Telegram bot, payment gateway, or an AI agent knocks on that door with a short request; Ring answers with data or performs an action (send a message, take a payment, list products).

    You do not need to write code to understand the map:

    • Families group related doors (Store, Wallet, Messaging, Admin…).
    • Methods say what kind of knock is allowed — usually GET (read) or POST (do something).
    • MCP doors (/api/mcp/v1/*) are the same business domains, shaped for AI agents and automation.

    Explore the tree

    Tap a leaf in the upper tree. The lower panel shows a short summary and the HTTP methods for that door.

    Capability map (founder view)

    FamilyWhat it unlocksStart here
    Auth & identitySign-in, sessions, wallet loginAuthentication
    Messaging & callsChats, typing, call invitesMessaging
    NotificationsInbox + mobile push (FCM)Notifications
    Entities & opportunitiesOrgs, projects, matchingEntities · Opportunities
    Store & shippingCatalog, checkout, Nova PoshtaStore
    Membership & paymentsSubscriptions, WayForPay / StripePayments
    Wallet & credits

    Cart state lives in the browser (ring_cart) — there is no public “cart REST API”. Checkout and payments are the store money path.

    Surface truth (2026-07-10)

    Verified against the Next.js App Router build list for ring-platform.org:

    MetricValue
    Route handlers under /api~244
    Largest familiesmcp/v1/* (~42), admin/* (~41), wallet/* (16), cron/* (13), store/* + shipping/vendor (17), tunnel/* (11)
    Static cached example○ /api/platform-stats (others are dynamic ƒ)

    Deep domain pages (not every leaf is duplicated here):

    DomainDocPrimary paths
    Authentication

    New to Ring? Getting Started · API integration examples · for developers index.

    API Reference

    Ring Platform exposes ~244 App Router route handlers under /api/* — the live surface your clone, mobile clients, cron jobs, webhooks, and MCP agents call. This page is the map: founders browse capabilities; developers get auth rules, domain docs, and verified path families.

    Use the Founder / Developer tabs in the docs sidebar. Founders get a visual API tree; developers get contracts, secrets, and deep links into domain pages.

    What the API is (in plain language)

    An API endpoint is a named door on your Ring server. The browser, Telegram bot, payment gateway, or an AI agent knocks on that door with a short request; Ring answers with data or performs an action (send a message, take a payment, list products).

    You do not need to write code to understand the map:

    • Families group related doors (Store, Wallet, Messaging, Admin…).
    • Methods say what kind of knock is allowed — usually GET (read) or POST (do something).
    • MCP doors (/api/mcp/v1/*) are the same business domains, shaped for AI agents and automation.

    Explore the tree

    Tap a leaf in the upper tree. The lower panel shows a short summary and the HTTP methods for that door.

    Capability map (founder view)

    FamilyWhat it unlocksStart here
    Auth & identitySign-in, sessions, wallet loginAuthentication
    Messaging & callsChats, typing, call invitesMessaging
    NotificationsInbox + mobile push (FCM)Notifications
    Entities & opportunitiesOrgs, projects, matchingEntities · Opportunities
    Store & shippingCatalog, checkout, Nova PoshtaStore
    Membership & paymentsSubscriptions, WayForPay / StripePayments
    Wallet & credits

    Cart state lives in the browser (ring_cart) — there is no public “cart REST API”. Checkout and payments are the store money path.

    Surface truth (2026-07-10)

    Verified against the Next.js App Router build list for ring-platform.org:

    MetricValue
    Route handlers under /api~244
    Largest familiesmcp/v1/* (~42), admin/* (~41), wallet/* (16), cron/* (13), store/* + shipping/vendor (17), tunnel/* (11)
    Static cached example○ /api/platform-stats (others are dynamic ƒ)

    Deep domain pages (not every leaf is duplicated here):

    DomainDocPrimary paths
    Authentication

    New to Ring? Getting Started · API integration examples · for developers index.

    API Reference

    Ring Platform exposes ~244 App Router route handlers under /api/* — the live surface your clone, mobile clients, cron jobs, webhooks, and MCP agents call. This page is the map: founders browse capabilities; developers get auth rules, domain docs, and verified path families.

    Use the Founder / Developer tabs in the docs sidebar. Founders get a visual API tree; developers get contracts, secrets, and deep links into domain pages.

    What the API is (in plain language)

    An API endpoint is a named door on your Ring server. The browser, Telegram bot, payment gateway, or an AI agent knocks on that door with a short request; Ring answers with data or performs an action (send a message, take a payment, list products).

    You do not need to write code to understand the map:

    • Families group related doors (Store, Wallet, Messaging, Admin…).
    • Methods say what kind of knock is allowed — usually GET (read) or POST (do something).
    • MCP doors (/api/mcp/v1/*) are the same business domains, shaped for AI agents and automation.

    Explore the tree

    Tap a leaf in the upper tree. The lower panel shows a short summary and the HTTP methods for that door.

    Capability map (founder view)

    FamilyWhat it unlocksStart here
    Auth & identitySign-in, sessions, wallet loginAuthentication
    Messaging & callsChats, typing, call invitesMessaging
    NotificationsInbox + mobile push (FCM)Notifications
    Entities & opportunitiesOrgs, projects, matchingEntities · Opportunities
    Store & shippingCatalog, checkout, Nova PoshtaStore
    Membership & paymentsSubscriptions, WayForPay / StripePayments
    Wallet & credits

    Cart state lives in the browser (ring_cart) — there is no public “cart REST API”. Checkout and payments are the store money path.

    Surface truth (2026-07-10)

    Verified against the Next.js App Router build list for ring-platform.org:

    MetricValue
    Route handlers under /api~244
    Largest familiesmcp/v1/* (~42), admin/* (~41), wallet/* (16), cron/* (13), store/* + shipping/vendor (17), tunnel/* (11)
    Static cached example○ /api/platform-stats (others are dynamic ƒ)

    Deep domain pages (not every leaf is duplicated here):

    DomainDocPrimary paths
    Authentication

    New to Ring? Getting Started · API integration examples · for developers index.

    Credit top-up, transfers, tokens
    Wallet
    Admin & opsUsers, email CRM, fraud, processesAdmin · Email AI-CRM
    MCP agent APISame domains for agentsRing MCP
    Realtime tunnelLive subscribe / publishTunnel protocol
    Authentication
    /api/auth/[...nextauth], username check, crypto nonce, Telegram callback
    EntitiesEntities/api/entities, /create, /[id]/*
    OpportunitiesOpportunities/api/opportunities, create/update/search/upload
    MessagingMessaging/api/conversations/*, /api/messages/*, /api/webrtc/ice-servers
    NotificationsNotifications/api/notifications/*, FCM register/test
    WalletWallet/api/wallet/* credit, desk, token, transfer
    StoreStore/api/store/* products, checkout, orders, payments
    AdminAdmin/api/admin/* users, payments, moderation, web3, processes
    Email AI-CRMEmail AI-CRM/api/admin/email/*, /api/webhooks/email/inbound, cron email
    TunnelTunnel protocol/api/tunnel/*
    MCPRing MCP/api/mcp/v1/*
    PaymentsPaymentConductormembership + store + WayForPay/Stripe webhooks

    Authentication model

    ClientAuth
    Browser / same-origin ReactAuth.js v5 session cookie (credentials: 'include'). No manual Bearer in client UI code.
    CronAuthorization: Bearer <CRON_SECRET>
    Webhooks (WayForPay, Stripe, email inbound, Telegram bot)Provider signature / shared secret per route
    MCP agentsAuthorization: Bearer <RING_MCP_ACCESS_KEY> on /api/mcp/v1/*

    Quick start

    Base URL = your clone origin + /api (local: http://localhost:3000/api).

    Integration patterns: API integration examples.

    Family inventory (route counts)

    Family~RoutesNotes
    MCP (/api/mcp/v1)42Agent mirror of core domains + generative media
    Admin41Users, email CRM, fraud, matcher, processes, public pools, web3
    Wallet16Ensure, credit, desk, token, transfer
    Cron13Settlements, subscriptions, email, cleanup, train
    Store + vendor + shipping + ERP17Checkout, WayForPay, reviews, Nova Poshta, stock init
    Tunnel11Token, subscribe, SSE, poll, publish, heartbeat
    News + publications + collab16Newsroom, RSS, promotion webhook, publications
    Conversations + messages + comments + WebRTC14Chat, reactions, ICE
    Entities + opportunities + confidential16Core Ring graph
    Membership + payment webhooks + prices11Card/credit/PayPal/token + WFP/Stripe
    Auth + account + set-user-role7Auth.js + helpers
    Notifications + FCM7Inbox + push
    Analytics + platform + health/info/uploads12Beacons, stats, probes
    Web3 / NFT / refcodes / pools10Listings, pools, referral mint/track
    Verification3Procedures + documents
    Profile / users / settings / ring contacts9People plane
    Misc (images, citations, agents provision, telegram, test-db, balance)~8Generative + ops helpers

    Visual browse (same widget as Founder tab):

    Security checklist

    • Auth.js v5 sessions (cookie in browser; JWT strategy server-side)
    • Role-based access (VISITOR → ADMIN) on admin and privileged routes
    • Rate limiting on sensitive routes (e.g. notifications)
    • Webhook / cron / MCP routes require explicit Bearer or provider verification — never expose secrets in MDX

    Realtime

    In-app live updates use Tunnel Protocol (native WSS on k8s; SSE/poll fallback). See Tunnel protocol and Realtime architecture.

    Credit top-up, transfers, tokens
    Wallet
    Admin & opsUsers, email CRM, fraud, processesAdmin · Email AI-CRM
    MCP agent APISame domains for agentsRing MCP
    Realtime tunnelLive subscribe / publishTunnel protocol
    Authentication
    /api/auth/[...nextauth], username check, crypto nonce, Telegram callback
    EntitiesEntities/api/entities, /create, /[id]/*
    OpportunitiesOpportunities/api/opportunities, create/update/search/upload
    MessagingMessaging/api/conversations/*, /api/messages/*, /api/webrtc/ice-servers
    NotificationsNotifications/api/notifications/*, FCM register/test
    WalletWallet/api/wallet/* credit, desk, token, transfer
    StoreStore/api/store/* products, checkout, orders, payments
    AdminAdmin/api/admin/* users, payments, moderation, web3, processes
    Email AI-CRMEmail AI-CRM/api/admin/email/*, /api/webhooks/email/inbound, cron email
    TunnelTunnel protocol/api/tunnel/*
    MCPRing MCP/api/mcp/v1/*
    PaymentsPaymentConductormembership + store + WayForPay/Stripe webhooks

    Authentication model

    ClientAuth
    Browser / same-origin ReactAuth.js v5 session cookie (credentials: 'include'). No manual Bearer in client UI code.
    CronAuthorization: Bearer <CRON_SECRET>
    Webhooks (WayForPay, Stripe, email inbound, Telegram bot)Provider signature / shared secret per route
    MCP agentsAuthorization: Bearer <RING_MCP_ACCESS_KEY> on /api/mcp/v1/*

    Quick start

    Base URL = your clone origin + /api (local: http://localhost:3000/api).

    Integration patterns: API integration examples.

    Family inventory (route counts)

    Family~RoutesNotes
    MCP (/api/mcp/v1)42Agent mirror of core domains + generative media
    Admin41Users, email CRM, fraud, matcher, processes, public pools, web3
    Wallet16Ensure, credit, desk, token, transfer
    Cron13Settlements, subscriptions, email, cleanup, train
    Store + vendor + shipping + ERP17Checkout, WayForPay, reviews, Nova Poshta, stock init
    Tunnel11Token, subscribe, SSE, poll, publish, heartbeat
    News + publications + collab16Newsroom, RSS, promotion webhook, publications
    Conversations + messages + comments + WebRTC14Chat, reactions, ICE
    Entities + opportunities + confidential16Core Ring graph
    Membership + payment webhooks + prices11Card/credit/PayPal/token + WFP/Stripe
    Auth + account + set-user-role7Auth.js + helpers
    Notifications + FCM7Inbox + push
    Analytics + platform + health/info/uploads12Beacons, stats, probes
    Web3 / NFT / refcodes / pools10Listings, pools, referral mint/track
    Verification3Procedures + documents
    Profile / users / settings / ring contacts9People plane
    Misc (images, citations, agents provision, telegram, test-db, balance)~8Generative + ops helpers

    Visual browse (same widget as Founder tab):

    Security checklist

    • Auth.js v5 sessions (cookie in browser; JWT strategy server-side)
    • Role-based access (VISITOR → ADMIN) on admin and privileged routes
    • Rate limiting on sensitive routes (e.g. notifications)
    • Webhook / cron / MCP routes require explicit Bearer or provider verification — never expose secrets in MDX

    Realtime

    In-app live updates use Tunnel Protocol (native WSS on k8s; SSE/poll fallback). See Tunnel protocol and Realtime architecture.

    Credit top-up, transfers, tokens
    Wallet
    Admin & opsUsers, email CRM, fraud, processesAdmin · Email AI-CRM
    MCP agent APISame domains for agentsRing MCP
    Realtime tunnelLive subscribe / publishTunnel protocol
    Authentication
    /api/auth/[...nextauth], username check, crypto nonce, Telegram callback
    EntitiesEntities/api/entities, /create, /[id]/*
    OpportunitiesOpportunities/api/opportunities, create/update/search/upload
    MessagingMessaging/api/conversations/*, /api/messages/*, /api/webrtc/ice-servers
    NotificationsNotifications/api/notifications/*, FCM register/test
    WalletWallet/api/wallet/* credit, desk, token, transfer
    StoreStore/api/store/* products, checkout, orders, payments
    AdminAdmin/api/admin/* users, payments, moderation, web3, processes
    Email AI-CRMEmail AI-CRM/api/admin/email/*, /api/webhooks/email/inbound, cron email
    TunnelTunnel protocol/api/tunnel/*
    MCPRing MCP/api/mcp/v1/*
    PaymentsPaymentConductormembership + store + WayForPay/Stripe webhooks

    Authentication model

    ClientAuth
    Browser / same-origin ReactAuth.js v5 session cookie (credentials: 'include'). No manual Bearer in client UI code.
    CronAuthorization: Bearer <CRON_SECRET>
    Webhooks (WayForPay, Stripe, email inbound, Telegram bot)Provider signature / shared secret per route
    MCP agentsAuthorization: Bearer <RING_MCP_ACCESS_KEY> on /api/mcp/v1/*

    Quick start

    Base URL = your clone origin + /api (local: http://localhost:3000/api).

    Integration patterns: API integration examples.

    Family inventory (route counts)

    Family~RoutesNotes
    MCP (/api/mcp/v1)42Agent mirror of core domains + generative media
    Admin41Users, email CRM, fraud, matcher, processes, public pools, web3
    Wallet16Ensure, credit, desk, token, transfer
    Cron13Settlements, subscriptions, email, cleanup, train
    Store + vendor + shipping + ERP17Checkout, WayForPay, reviews, Nova Poshta, stock init
    Tunnel11Token, subscribe, SSE, poll, publish, heartbeat
    News + publications + collab16Newsroom, RSS, promotion webhook, publications
    Conversations + messages + comments + WebRTC14Chat, reactions, ICE
    Entities + opportunities + confidential16Core Ring graph
    Membership + payment webhooks + prices11Card/credit/PayPal/token + WFP/Stripe
    Auth + account + set-user-role7Auth.js + helpers
    Notifications + FCM7Inbox + push
    Analytics + platform + health/info/uploads12Beacons, stats, probes
    Web3 / NFT / refcodes / pools10Listings, pools, referral mint/track
    Verification3Procedures + documents
    Profile / users / settings / ring contacts9People plane
    Misc (images, citations, agents provision, telegram, test-db, balance)~8Generative + ops helpers

    Visual browse (same widget as Founder tab):

    Security checklist

    • Auth.js v5 sessions (cookie in browser; JWT strategy server-side)
    • Role-based access (VISITOR → ADMIN) on admin and privileged routes
    • Rate limiting on sensitive routes (e.g. notifications)
    • Webhook / cron / MCP routes require explicit Bearer or provider verification — never expose secrets in MDX

    Realtime

    In-app live updates use Tunnel Protocol (native WSS on k8s; SSE/poll fallback). See Tunnel protocol and Realtime architecture.