Developer Docs
How the Kiwi Cove website integrates with the FiveM server, and how to build against it.
Overview
The website talks to the FiveM server (sfos-core) over a loopback-only HTTP listener behind a TLS reverse proxy. Every call is server-to-server — there is no browser-facing CORS surface, and secrets never reach the client. The site is Next.js (App Router) with Auth.js Discord sign-in.
Auth model
Portal requests carry a shared secret; admin requests additionally carry the actor's account id, derived server-side from the signed-in session and re-checked against the database every request — a stale token can never escalate.
x-sfos-portal-secret: <shared secret> # every route except public status x-sfos-actor-account-id: <account id> # admin routes; server-derived, never client input
Public status
The only unauthenticated endpoint — live on-duty counts, powering the homepage board.
GET /api/portal/status
→ { "ok": true, "data": { "NZP": 3, "FENZ": 1, "CIV": 12, ... }, "updatedAt": "…" }Environment
PORTAL_API_URL # the Caddy-fronted API domain, e.g. https://api.yourdomain.tld PORTAL_API_SECRET # must equal FXServer's sfos_portal_secret convar
API keys and webhooks for external integrations are managed by staff in the gated developer area.
Webhooks & keys
Register outbound webhooks to receive platform events (e.g. a new announcement or application) and issue scoped API keys for external tooling. These are configured in the staff developer console.
Staff dev tools
Dev board, API keys, webhooks, and integration health.