Version: 2.0.0
Peak Gateway Internal API
Curated reference for support-relevant management endpoints. It documents the management BFF boundary used by portal operators; it is not an inventory of every private service-to-service route.
Conventions:
- Resource identifiers are opaque strings, not assumed UUIDs.
- Responses use the standard ApiResponse wrapper.
- Portal authorization is permission-based. Direct grants can be platform, agent, organization, or location scoped.
- Processing and merchant-onboarding remain internal-only Cloud Run services.
Authentication
- HTTP: Bearer Auth
Firebase ID token for a staff, agent, organization, or location portal user.
Security Scheme Type: | http |
|---|---|
HTTP Authorization Scheme: | bearer |
Bearer format: | JWT |