All endpoints require X-User-Id header (except auth, static, and webhook routes).
Base URL: http://localhost:3000
Method
Path
Description
POST
/auth/login
Email/password login
GET
/auth/google
Initiate Google OAuth flow
GET
/auth/google/callback
Google OAuth callback
Method
Path
Description
GET
/users
List all users
POST
/users
Create user
PATCH
/users/:userId/account
Update name, password, job_title
Method
Path
Description
POST
/presence/heartbeat
Report user online (body: { user_id })
GET
/presence/online
Get online and today's users with geo
Method
Path
Description
GET
/projects
List non-archived projects
POST
/projects
Create project
GET
/projects/:projectId
Get project with boards
PATCH
/projects/:projectId
Update project name/description
Method
Path
Description
GET
/projects/:projectId/boards
List boards in project
POST
/projects/:projectId/boards
Create board
GET
/boards/:boardId
Get board with columns and tasks
Method
Path
Description
POST
/boards/:boardId/columns
Create column
PATCH
/columns/:columnId
Update name, position, width
DELETE
/columns/:columnId
Delete column (query: taskAction, targetColumnId)
POST
/columns/:columnId/archive-tasks
Archive tasks (body: { mode })
POST
/columns/:columnId/duplicate
Duplicate column
POST
/columns/:columnId/sort-tasks
Sort tasks (body: { sortBy, direction })
Method
Path
Description
POST
/columns/:columnId/tasks
Create task
GET
/tasks/:taskId
Get task with messages and labels
GET
/tasks/:taskId/full
Full task DTO (assignees, stickers, labels, messages)
PATCH
/tasks/:taskId
Update task fields
DELETE
/tasks/:taskId
Delete task
POST
/tasks/:taskId/move
Move task to column (body: { column_id, position })
POST
/tasks/:taskId/subtasks
Create subtask (body: { title })
POST
/tasks/:taskId/duplicate
Duplicate task
Method
Path
Description
POST
/tasks/:taskId/assignees
Add/update assignee
DELETE
/tasks/:taskId/assignees/:userId
Remove assignee
Method
Path
Description
POST
/tasks/:taskId/labels
Add label
DELETE
/tasks/:taskId/labels/:label
Remove label
Method
Path
Description
GET
/tasks/:taskId/stickers
List stickers
POST
/tasks/:taskId/stickers
Add/replace sticker
PATCH
/tasks/:taskId/stickers/:stickerId
Update sticker
DELETE
/tasks/:taskId/stickers/:stickerId
Delete sticker
Method
Path
Description
GET
/tasks/:taskId/messages
List task messages
POST
/tasks/:taskId/messages
Post message (body: { user_id, body })
Method
Path
Description
GET
/messages/group
List all group messages
POST
/messages/group
Post group message (body: { user_id, body })
Method
Path
Description
GET
/messages/direct
List DMs (query: user1, user2)
POST
/messages/direct
Send DM (body: { from_id, to_id, body })
Method
Path
Description
DELETE
/messages/task/:msgId
Soft-delete task message
DELETE
/messages/direct/:msgId
Soft-delete direct message
DELETE
/messages/group/:msgId
Soft-delete group message
GET
/messages/deleted/task/:msgId
View deleted task message (audit)
GET
/messages/deleted/direct/:msgId
View deleted direct message (audit)
GET
/messages/deleted/group/:msgId
View deleted group message (audit)
POST
/messages/:msgId/hide
Hide message for current user only
Method
Path
Description
POST
/upload
Legacy disk upload (returns URL)
POST
/files/upload
Encrypted upload to DB (body: file, task_id, message_id, message_type)
GET
/files/:fileId
File metadata
GET
/files/:fileId/download
Download decrypted file
GET
/files/:fileId/view
Inline view (Content-Disposition: inline)
DELETE
/files/:fileId
Soft-delete file for everyone
POST
/files/:fileId/hide
Hide file for current user
Method
Path
Description
GET
/companies
List companies
POST
/companies
Create company
PATCH
/companies/:id
Update company
DELETE
/companies/:id
Delete company
GET
/companies/:companyId/members
List company members
Method
Path
Description
GET
/departments
List departments (query: company_id)
POST
/departments
Create department
PATCH
/departments/:id
Update department
Method
Path
Description
GET
/job-titles
List job titles (query: company_id)
POST
/job-titles
Create job title
PATCH
/job-titles/:id
Update job title
Method
Path
Description
GET
/projects/:projectId/members
List project members (v_project_member_context view)
Method
Path
Description
GET
/projects/:projectId/gantt-tasks
Tasks with start/due dates for Gantt
GET
/projects/:projectId/calendar-tasks
Tasks with due_date for calendar
GET
/projects/:projectId/task-assignees
All assignees across project tasks
GET
/projects/:projectId/workload
Per-user task load statistics
GET
/projects/:projectId/tasks-table
Table view DTO with assignees/stickers
Method
Path
Description
GET
/projects/:projectId/activity-events
Project activity feed (query: type, task_id, actor_id, limit, offset)
GET
/activity-events
Global activity feed (legacy)
Method
Path
Description
GET
/chat-events
Message deletion audit log (query: scope, limit, offset)
Method
Path
Description
GET
/search
Full-text search (query: q)
Method
Path
Description
POST
/email/send
Send email (body: { to, subject, text, html })
Method
Path
Description
GET
/integrations
List all integrations
PATCH
/integrations/:id
Toggle integration enabled/config
POST
/integrations/yandex-alice/webhook
Alice webhook (no auth required)
GET
/integrations/yandex-alice/sessions
List Alice sessions
GET
/integrations/yandex-alice/sessions/:id/messages
Session message history
PATCH
/integrations/yandex-alice/sessions/:id/link
Link session to project/task/user
Alice Bot Chat Participant
Method
Path
Description
POST
/chats/bots/alice/add
Add Alice to chat scope
POST
/chats/bots/alice/remove
Remove Alice from chat scope
Method
Path
Description
GET
/health
Service health check
Method
Path
Description
GET
/
Serve index.html (SPA)
GET
/login
Serve login.html
GET
/assets/*
Static assets
GET
/uploads/*
Legacy uploaded files