API
Kumir developers
Native iOS/Android and partner integrations use versioned /api/v1. The machine-readable contract is OpenAPI 3.1 at GET /api/v1/openapi. Do not invent Stripe, APNs, FCM, or OAuth keys — missing providers return 501 or log-only, never a fake success.
Auth: POST /api/v1/auth/login returns an HS256 access token (1 hour) and a rotating refresh token (30 days). Send Authorization: Bearer … and X-Fameo-Channel: ios|android. Health probes /api/v1/health and /ready stay unauthenticated.
me
GET /api/v1/me
GET me · Bearer
POST /api/v1/me/delete
POST me · delete · Bearer
GET /api/v1/me/export
Download a JSON copy of the signed-in account (no secrets) · Bearer
POST /api/v1/me/password
POST me · password · Bearer
GET /api/v1/me/phone
Phone verification status (masked) · Bearer
POST /api/v1/me/phone
Request a hashed SMS OTP for phone verification · Bearer
POST /api/v1/me/phone/verify
Verify a phone OTP — never invents phoneVerifiedAt · Bearer
GET /api/v1/me/settings
GET me · settings · Bearer
PATCH /api/v1/me/settings
PATCH me · settings · Bearer