{"result":{"depiction_url":null,"edges":{"hasreference":{"objects":[{"created":"2026-10-07T11:13:29Z","object_id":{"id":1831,"is_a":["text","documentation","reference","module"],"name":"doc_module_mod_oauth2","title":"mod_oauth2","uri":"https:\/\/zotonic.com\/id\/1831"},"seq":1},{"created":"2026-10-07T11:13:29Z","object_id":{"id":1875,"is_a":["text","documentation","reference","controller"],"name":"doc_controller_controller_api","title":"controller_api","uri":"https:\/\/zotonic.com\/id\/1875"},"seq":2}],"predicate":{"id":2774,"is_a":["meta","predicate"],"name":"hasreference","title":{"_type":"trans","tr":{"en":"Documentation reference"}},"uri":"https:\/\/zotonic.com\/id\/hasreference"}},"refers":{"objects":[{"created":"2026-10-07T11:13:08Z","object_id":{"id":1536,"is_a":["text","documentation","developerguide"],"name":"doc_developerguide_access_control","title":{"_type":"trans","tr":{"en":"Keep permission checks at the boundary"}},"uri":"https:\/\/zotonic.com\/id\/1536"},"seq":1000000},{"created":"2026-10-07T11:13:08Z","object_id":{"id":1831,"is_a":["text","documentation","reference","module"],"name":"doc_module_mod_oauth2","title":"mod_oauth2","uri":"https:\/\/zotonic.com\/id\/1831"},"seq":1000000},{"created":"2026-10-07T11:13:08Z","object_id":{"id":1875,"is_a":["text","documentation","reference","controller"],"name":"doc_controller_controller_api","title":"controller_api","uri":"https:\/\/zotonic.com\/id\/1875"},"seq":1000000},{"created":"2026-10-07T11:13:08Z","object_id":{"id":2960,"is_a":["text","documentation","developerguide"],"name":"developer_model_api","title":{"_type":"trans","tr":{"en":"Expose data through a model"}},"uri":"https:\/\/zotonic.com\/id\/2960"},"seq":1000000}],"predicate":{"id":2409,"is_a":["meta","predicate"],"name":"refers","title":{"_type":"trans","tr":{"en":"Refers"}},"uri":"https:\/\/zotonic.com\/id\/refers"}},"subject":{"objects":[{"created":"2026-10-07T11:13:29Z","object_id":{"id":2554,"is_a":["categorization","keyword","keyword_information_type"],"name":"zotonic_topic_how_to_guide","title":"How-to guide","uri":"https:\/\/zotonic.com\/id\/2554"},"seq":1},{"created":"2026-10-07T11:13:29Z","object_id":{"id":2563,"is_a":["categorization","keyword","keyword_audience"],"name":"zotonic_topic_frontend_developer","title":"Frontend developer","uri":"https:\/\/zotonic.com\/id\/2563"},"seq":2},{"created":"2026-10-07T11:13:29Z","object_id":{"id":2599,"is_a":["categorization","keyword","keyword_domain"],"name":"zotonic_topic_api_and_integration","title":"API and integration","uri":"https:\/\/zotonic.com\/id\/2599"},"seq":3},{"created":"2026-10-07T11:13:29Z","object_id":{"id":2676,"is_a":["categorization","keyword","keyword_technology"],"name":"zotonic_topic_http","title":"HTTP","uri":"https:\/\/zotonic.com\/id\/2676"},"seq":4},{"created":"2026-10-07T11:13:29Z","object_id":{"id":2681,"is_a":["categorization","keyword","keyword_technology"],"name":"zotonic_topic_oauth_2_0","title":"OAuth 2.0","uri":"https:\/\/zotonic.com\/id\/2681"},"seq":5}],"predicate":{"id":308,"is_a":["meta","predicate"],"name":"subject","title":{"_type":"trans","tr":{"en":"Keyword"}},"uri":"http:\/\/purl.org\/dc\/elements\/1.1\/subject"}}},"id":2966,"is_a":["text","documentation","developerguide"],"links":[{"rel":"self","target":"https:\/\/zotonic.com\/.zotonic\/websub\/topic\/2966"},{"rel":"hub","target":"https:\/\/zotonic.com\/.zotonic\/websub"}],"medium":null,"medium_url":null,"name":"developer_http_api","page_url":{"en":"https:\/\/zotonic.com\/docs\/2966\/expose-an-operation-through-an-api","x-default":"https:\/\/zotonic.com\/docs\/2966\/expose-an-operation-through-an-api"},"preview_url":null,"resource":{"body":{"_type":"trans","tr":{"en":"<p>Use a read operation for retrieval and an appropriate write operation for changes. Apply authentication and authorization to each operation. Test malformed input and access denial as well as a successful response.<\/p>\n<p>Keep transport details out of shared domain functions so the same operation can serve a template, event handler, or API safely. See <a href=\"\/id\/1831\" class=\"doc-reference doc-reference-module\"><code>module#mod_oauth2<\/code><\/a>, <a href=\"\/id\/2960\">Expose data through a model<\/a>, and <a href=\"\/id\/1536\">Keep permission checks at the boundary<\/a>.<\/p>\n<p>The greeting model provides a read-only first check. On the site&#39;s hostname, request:<\/p>\n<pre class=\"notranslate\"><code class=\"notranslate language-text\">GET \/api\/model\/garden\/get\/greeting\n<\/code><\/pre>\n<p>Expect a JSON success response with the greeting as its result. Confirm the HTTP status and response body. Request an unknown path too; the model should return its <code>unknown_path<\/code> error. This uses the public example from the model task, so no token is required for that particular value.<\/p>\n<p>For protected operations, use the authentication mechanism supported by <a href=\"\/id\/1875\" class=\"doc-reference doc-reference-controller\"><code>controller#controller_api<\/code><\/a>, for example an appropriately scoped OAuth token. Authentication identifies the caller; the model still must authorize access. Keep tokens out of URLs and example files. Read the controller reference for response envelopes, HTTP methods and request-body handling before adding writes.<\/p>"}},"category_id":{"id":317,"is_a":["meta","category"],"name":"developerguide","title":"Developer guide","uri":"https:\/\/zotonic.com\/id\/developerguide"},"content_group_id":{"id":339,"is_a":["meta","content_group"],"name":"default_content_group","title":{"_type":"trans","tr":{"en":"Default Content Group"}},"uri":"https:\/\/zotonic.com\/id\/default_content_group"},"created":"2026-10-07T11:12:56Z","creator_id":{"id":1,"is_a":["person"],"name":"administrator","title":"Site Administrator","uri":"https:\/\/zotonic.com\/id\/1"},"doc_editorial_bundle":true,"doc_editorial_edges":{"hasreference":[1831,1875],"subject":[2554,2563,2599,2676,2681]},"is_authoritative":true,"is_dependent":false,"is_featured":false,"is_protected":false,"is_published":true,"is_unfindable":false,"language":["en"],"modified":"2026-10-07T20:45:39Z","modifier_id":{"id":1,"is_a":["person"],"name":"administrator","title":"Site Administrator","uri":"https:\/\/zotonic.com\/id\/1"},"name":"developer_http_api","pivot_geocode":null,"pivot_location_lat":null,"pivot_location_lng":null,"privacy":0,"publication_end":"9999-06-01T00:00:00Z","publication_start":"2026-10-07T11:12:56Z","slug":"expose-an-operation-through-an-api","summary":{"_type":"trans","tr":{"en":"Start from the site&#39;s existing model API or controller patterns. Specify the method, input fields, response shape, and errors before connecting a browser or external client."}},"title":{"_type":"trans","tr":{"en":"Expose an operation through an API"}},"title_slug":{"_type":"trans","tr":{"en":"expose-an-operation-through-an-api"}},"tz":"UTC","uri":null,"version":23,"visible_for":0},"uri":"https:\/\/zotonic.com\/id\/2966","uri_template":"https:\/\/zotonic.com\/id\/:id","websub":{"hub":"https:\/\/zotonic.com\/.zotonic\/websub","topic":"https:\/\/zotonic.com\/.zotonic\/websub\/topic\/2966"}},"status":"ok"}