Alhuda ERP API Specification (REST)
Superseded — kept for history only
This page was written in January 2026 and is not a description of how the system works today. It is kept so the reasoning behind early decisions stays readable. Current behaviour is described in the API reference. Do not build from this page.
Base: /api
Auth responses use JWT/session cookies.
Common Errors
- 400: Validation error
- 401: Not authenticated
- 403: Not authorized
- 404: Not found
- 409: Conflict (capacity reached, duplicate IDs)
- 422: Business rule violation
Auth
POST /auth/login
Request:
Response:GET /auth/me
Response:
Inventory
GET /airlines
Response:
POST /quota-blocks
Request:
{
"airlineId": "uuid",
"flightNo": "SV123",
"departureDate": "2025-01-01",
"origin": "DEL",
"destination": "JED",
"totalSeats": 100,
"price": 1200,
"currency": "SAR"
}
POST /slots/generate
Request:
Response:Groups
POST /groups
Request:
{
"groupCode": "GRP-2025-001",
"name": "Umrah Jan Group",
"departureDate": "2025-01-10",
"returnDate": "2025-01-20",
"capacity": 40
}
POST /groups/:id/assign-slots
Request:
Rules: - Total assigned slots <= group capacity.POST /groups/:id/assign-customer
Request:
Rules: - Group must have capacity.Sales
POST /customers
Request:
POST /quotations
Request:
{
"customerId": "uuid",
"agentId": "uuid",
"currency": "INR",
"total": 100000,
"discount": 5000,
"items": [ { "description": "Hotel", "quantity": 1, "unitPrice": 60000 } ]
}
POST /bookings
Request:
Operations
POST /bookings/:id/ops-approve
Request:
Rule: finance policy must be met.POST /bookings/:id/ops-reject
Request:
Finance
POST /payments
Request:
POST /bookings/:id/finance-approve
Request:
Visa
POST /visa
Request:
PATCH /visa/:id/status
Request:
POST /visa/:id/upload
Request:
Tickets
PATCH /tickets/:id/name-update
Request:
POST /tickets/:id/issue
Rule: finance clearance OR GM exception proof.
POST /tickets/:id/exception-approve
Request:
Reports
GET /reports/group-manifest
Filters: groupId, departureDate
GET /reports/dues
Filters: agentId, groupId, agingBucket
GET /reports/visa-pipeline
Filters: status, departureRange