Build with Kiwi Cove

Developer Docs

How the Kiwi Cove website integrates with the FiveM server, and how to build against it.

Overview

The website talks to the FiveM server (sfos-core) over a loopback-only HTTP listener behind a TLS reverse proxy. Every call is server-to-server — there is no browser-facing CORS surface, and secrets never reach the client. The site is Next.js (App Router) with Auth.js Discord sign-in.

Auth model

Portal requests carry a shared secret; admin requests additionally carry the actor's account id, derived server-side from the signed-in session and re-checked against the database every request — a stale token can never escalate.

x-sfos-portal-secret: <shared secret>        # every route except public status
x-sfos-actor-account-id: <account id>        # admin routes; server-derived, never client input

Public status

The only unauthenticated endpoint — live on-duty counts, powering the homepage board.

GET /api/portal/status
→ { "ok": true, "data": { "NZP": 3, "FENZ": 1, "CIV": 12, ... }, "updatedAt": "…" }

Environment

PORTAL_API_URL      # the Caddy-fronted API domain, e.g. https://api.yourdomain.tld
PORTAL_API_SECRET   # must equal FXServer's sfos_portal_secret convar

API keys and webhooks for external integrations are managed by staff in the gated developer area.

Webhooks & keys

Register outbound webhooks to receive platform events (e.g. a new announcement or application) and issue scoped API keys for external tooling. These are configured in the staff developer console.

Staff dev tools

Dev board, API keys, webhooks, and integration health.

Open Dev Console