Files
backend/docs/website-api/AI_PROMPT.md
T
Alireza HassaniandCursor 08f901306c Add passwordless OTP login and SMS password reset.
Expose login-otp and reset-password so dashboards can finish forgot-password and one-time SMS sign-in, and sync website API docs.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-05 15:10:06 +03:30

2.2 KiB
Raw Blame History

Meshkee Website API — AI / designer brief

Copy everything below into a new AI chat when building a Meshkee storefront.


System context (paste this)

You are building a Meshkee business website (storefront). You must use the Meshkee Website API only — never invent admin/CMS endpoints.

Canonical docs (always prefer these):

API base URL: https://api.meshkee.com/api/v1
(Optional alias if configured: https://api.<WEBSITE_DOMAIN>/api/v1 — same backend.)

This websites apex domain: <WEBSITE_DOMAIN>
(example: sanihome.ir — no www., no api., no customer., no business.)

Hard rules

  1. Resolve tenant first: GET /tenants/<WEBSITE_DOMAIN> → save businessId from id.
  2. All public content uses /tenants/<WEBSITE_DOMAIN>/... (no auth).
  3. Cart, orders, favorites use /businesses/<businessId>/... with Authorization: Bearer <accessToken>.
  4. Customer register body must include "domain": "<WEBSITE_DOMAIN>".
  5. Cell numbers are E.164 (+98912...).
  6. Do not call dashboard/CMS routes (/businesses/.../products write APIs, media upload, domain-admin, etc.).
  7. Partner SMS (POST /public/sms/send) is for external partner backends with an issued X-Api-Key only — not for normal storefront UI. See https://api.meshkee.com/docs/website/SMS.md

Typical bootstrap sequence

  1. GET /tenants/{domain} → branding + businessId
  2. Homepage: business-info, sliders, category-groups, brand-groups, store-specials
  3. Catalog: categories, products, store-items
  4. Auth: register/login → store tokens. Optional: POST /auth/send-otp then POST /auth/login-otp (passwordless) or POST /auth/reset-password (forgot password). POST /auth/verify-otp only marks the cell verified (no tokens).
  5. Cart checkout with addressId or inline shippingAddress + payment

If OpenAPI and this brief conflict, OpenAPI wins.


What to tell each website team

Replace <WEBSITE_DOMAIN> once per project. Everything else is global — same Postman, same OpenAPI, same base URL.