API Reference
Written April 2026 — read this first
Route tables in this section were written in April; only the bookings, finance and admin pages were re-verified in the September 2026 pass. src/lib/api.ts is the dispatcher, not the boundary — see Where enforcement lives. Line numbers cited anywhere in this section are stale; search by handler name instead.
The Alhuda Travel ERP exposes its entire server API through a single handler monolith at
src/lib/api.ts (28,238 lines). This section documents every
route grouped by domain.
Start with Overview for the dispatch pattern, auth model, permission convention, idempotency rules, and the checklist for adding new routes.
Domains
- Overview — Monolith pattern,
apiFetch, auth, permissions, idempotency, error shape, how to add a route. - Authentication — Login, registration, partner + customer signup, OTP/2FA.
- Bookings, Groups & Sales — Booking CRUD, import, invoices, travel groups, group invoices, quotations, ops approvals, portal routes.
- Finance — Journals, payments, vouchers, GL accounts, periods, invoices, TDS, GST, financial reports.
- Online payment (Razorpay) —
razorpay-order(the app's and the partner web portal's "Pay online"),razorpay-webhook, theOnlinePaymentOrdertable. - Partner payments —
/portals/agent/payments: the partner's Payments page on the web, I have paid and Pay online. - Customers, Partners & Suppliers — Customer CRUD, agent CRUD, supplier CRUD, leads, ledgers.
- Inventory — Hotels, food, ground transfers, airlines, quota blocks, FIT, B2B offers, visa, tickets.
- Dashboard —
dashboard_screen(): the role dashboard and the phone home in one call, badges and unread count included. - Leave and agreements —
src/lib/leave.ts: leave, approvals, Leave admin, the holiday calendar, and the employee agreement (issue, sign, countersign). - Admin, Approvals & System — Users, permissions, audit, communications, finance config, storage, settings.