GET
/api/health
Returns a minimal JSON readiness payload for uptime checks and external health monitoring.
- Public endpoint
- Returns JSON
- No authentication required
These endpoints are safe for public discovery and are advertised from the homepage via RFC 8288 `Link` headers and the RFC 9727 `/.well-known/api-catalog` document.
/.well-known/api-catalog publishes a Linkset catalog for public API discovery./.well-known/agent-skills/index.json publishes an Agent Skills Discovery RFC v0.2.0 index for the skills this site makes available to compatible agents./openapi.json publishes the OpenAPI service description referenced by the API catalog./.well-known/mcp/server-card.json publishes an MCP Server Card for agent discovery, including the Peptaura server identity, supported protocol version, transport endpoint, and advertised capabilities./.well-known/mcp-server-card serves the same MCP Server Card on the newer compatibility path used by the active SEP draft./mcp exposes a public Streamable HTTP MCP transport that currently supports initialization, ping, and empty tool/resource/prompt discovery responses for agent clients./.well-known/http-message-signatures-directory publishes the site's Web Bot Auth JWKS for signed bot and agent requests./.well-known/openid-configuration redirects to the canonical Supabase Auth OpenID Connect discovery document used for agent and OAuth client authentication./.well-known/oauth-authorization-server redirects OAuth-oriented clients to the same live Supabase Auth discovery document currently served for OpenID Connect./.well-known/oauth-protected-resource publishes RFC 9728 protected resource metadata with this site's resource identifier, the Supabase Auth issuer, and the supported OAuth/OIDC scopes agents should request./llms.txt provides additional site-level machine-readable context for agents.Accept: text/markdown to the production hostname to receive a markdown representation with a Content-Type: text/markdown response and an x-markdown-tokens header when Cloudflare provides one./docs/lab-integration.md is the partner guide for approved testing laboratories. It documents the optional outbound POST that Peptaura sends to the lab's own HTTPS receiver after a lab payout is confirmed, the authenticated /lab result-upload flow, and the lab-scoped inbound partner API: GET /api/lab/v1/orders/{clientOrderReference} order lookup and POST /api/lab/v1/orders/{clientOrderReference}/results multipart report submission. The inbound endpoints require a lab-issued Bearer credential and expose only that lab's own paid orders — they are partner surfaces, not unauthenticated public endpoints like the ones below.
Inbound endpoints any client may call. They are distinct from the outbound laboratory delivery described in the guide above.
GET
/api/healthReturns a minimal JSON readiness payload for uptime checks and external health monitoring.
GET
/api/coasReturns the paginated public COA directory using the same supplier, compound, dosage, document URL, date, batch number, purity, test type, and provenance badge fields shown on /coas.
GET
/pages/product-feedReturns the public product feed used for machine-readable catalog ingestion and indexing.