# A34 API quick reference

All routes use `/aichat34/api/` and a dedicated `aichat34-api` Worker with D1 binding `AICHAT34_DB`.

Core routes: `/auth/me`, `/auth/google`, `/auth/logout`, `/chat`, `/custom-games/list`, `/custom-games/detail`, `/custom-games/create`, `/custom-games/delete`, `/cgame2/list`, `/cgame2/previews`, `/cgame2/detail`, `/cgame2/save`, `/cgame2/delete`, `/cgame2/plans`, `/share/*`, `/generate-image`, `/payment/*`, `/credits/spend`, `/admin/conversations`, `/admin/conversations/refund`, `/admin/cgame2/plans`.

The Studio 2 catalog uses `/cgame2/list?mode=cards` for compact card metadata and one cover image. `/cgame2/previews?gameId=...&stage=1` returns up to two expression illustrations and four scene-slot states. Scene images and labels are omitted until the supplied stage reaches each slot's unlock episode (1, 4, 8, and 14); clients should call it when a card approaches the viewport and refresh after local progress advances. `/cgame2/detail?gameId=...` returns the complete published game for play/edit.

Lounge routes: `GET|POST /lounge/profile`, `GET|POST|DELETE /lounge/posts`, `POST /lounge/like`, `POST /lounge/report`. The feed is public; writing, liking, reporting, replies, and deleting require the A34 session. The public display name is an author-selected nickname, separate from their Google/service username. Deletion is author-only and soft-deletes content. Admin report review is available at `GET /admin/lounge/reports` and `POST /admin/lounge/moderate`, restricted to the three allowlisted Google subjects. Migrations `0011_lounge_posts.sql` and `0012_lounge_nicknames.sql` create the A34-only tables and nickname field.

Authentication uses the `a34sid` HttpOnly cookie. User/game/chat/credit tables are created empty in a new A34-only D1 database; only the public game catalog migration is copied. No A31 account IDs, private chat history, credits, payment rows or secrets are migrated.

`OPENROUTER_API_KEY` is a Cloudflare Worker Secret and is never included in source files. If it is not configured, the AI path should fail safely without charging credits. Payment endpoints require their own credentials and must not be enabled until configured.


The refund endpoint accepts a saved conversation record ID, requires one of the three allowlisted verified Google identities, returns that record's recorded spend once, and writes both a credit ledger entry and an operator access audit. Conversation content is available only for users who opted in to 90-day storage.

Studio draft endpoints use the authenticated `a34sid` session to save and manage only the caller's text plans; owner IDs in request bodies are ignored. Images are not included. The administrator plan-list endpoint uses the three verified Google subject IDs and records each query in `conversation_admin_access`.
