Authentication and accounts

POST /api/register creates an account. Usernames are 3–32 characters using letters, numbers, _, and -; passwords are 8–72 characters.

POST /api/login creates an HttpOnly rtcord_session cookie. Send it on authenticated requests. POST /api/logout clears the current session.

Account endpoints expose the current standing and warnings, email attachment and verification, and password-reset request and completion. Account standing levels are:

  • 0 — all good;

  • 1 — cannot accept invites or join servers;

  • 2 — cannot create group chats or send direct/group messages;

  • 3 — cannot send messages;

  • 4 — suspended from normal authenticated APIs, while account pages remain available.

See API.md for exact payloads and status details.