API reference
The field-level contract is the OpenAPI document generated by the API. This site does not copy the 489 routes or their DTOs.
Versioning
URI versioning is on in src/main.ts. The default version is 1. A route is /v1 plus the controller path unless the controller sets VERSION_NEUTRAL.
Health is version-neutral: GET /health. Voice webhooks are version-neutral. Metrics are served at /metrics.
Authentication
Send the access JWT on routes that are not @PublicRoute. Refresh uses GET /v1/auth/refresh-token with the refresh bearer scheme. The route is public at the access-guard layer and protected by JwtRefreshGuard.
Permission checks are per handler. If OpenAPI or the controller has no @RequirePermissions, the permissions guard allows any authenticated user. That is easy to miss. See Authentication.
Warehouse calls should send x-warehouse-id only to select inside the warehouses the membership already allows.
Where to read the operations
A working index of controllers, produced while analysing the repo, is documentation-analysis/api-inventory.md in the workspace. It is not maintained as the contract. When it disagrees with Swagger on request fields, Swagger wins. When it disagrees with code on side effects, the code wins.