Skip to content

API Reference

Written April 2026 — read this first

Route tables in this section were written in April; only the bookings, finance and admin pages were re-verified in the September 2026 pass. src/lib/api.ts is the dispatcher, not the boundary — see Where enforcement lives. Line numbers cited anywhere in this section are stale; search by handler name instead.

The Alhuda Travel ERP exposes its entire server API through a single handler monolith at src/lib/api.ts (28,238 lines). This section documents every route grouped by domain.

Start with Overview for the dispatch pattern, auth model, permission convention, idempotency rules, and the checklist for adding new routes.

Domains

  • Overview — Monolith pattern, apiFetch, auth, permissions, idempotency, error shape, how to add a route.
  • Authentication — Login, registration, partner + customer signup, OTP/2FA.
  • Bookings, Groups & Sales — Booking CRUD, import, invoices, travel groups, group invoices, quotations, ops approvals, portal routes.
  • Finance — Journals, payments, vouchers, GL accounts, periods, invoices, TDS, GST, financial reports.
  • Online payment (Razorpay) — razorpay-order (the app's and the partner web portal's "Pay online"), razorpay-webhook, the OnlinePaymentOrder table.
  • Partner payments — /portals/agent/payments: the partner's Payments page on the web, I have paid and Pay online.
  • Customers, Partners & Suppliers — Customer CRUD, agent CRUD, supplier CRUD, leads, ledgers.
  • Inventory — Hotels, food, ground transfers, airlines, quota blocks, FIT, B2B offers, visa, tickets.
  • Dashboard — dashboard_screen(): the role dashboard and the phone home in one call, badges and unread count included.
  • Leave and agreements — src/lib/leave.ts: leave, approvals, Leave admin, the holiday calendar, and the employee agreement (issue, sign, countersign).
  • Admin, Approvals & System — Users, permissions, audit, communications, finance config, storage, settings.