# ZUMRI Cross-Cutting Services API All paths also exist below `/api`; clients should use `/api/v1`. Protected routes accept the Phase 1 access cookie or bearer token. Examples use placeholders and never expose storage keys. ## Media - `POST /api/v1/upload` — multipart field `file`, optional text field `use_for`; creates a private owner-bound upload. - `GET /api/v1/upload/signed-url/:id` — returns `{ id, url, expiresIn }` after ownership/permission checks. - `DELETE /api/v1/upload/:id` — marks an owned/authorized upload deleted and removes its object best-effort. - `GET /api/v1/profile/me/avatar` and `/background` — signed self profile media access. Legacy owner-checked ID routes remain. ## Notifications - `POST /api/v1/notification` — `notifications.manage`; body includes headline, description, `USER|ANNOUNCEMENT`, and `userIds` for USER messages. - `GET /api/v1/notification/announcements` - `GET /api/v1/notification/me` - `PATCH /api/v1/notification/:notificationId/read` - `PATCH /api/v1/notification/read-all` ## Documents - `GET /api/v1/document/types` - `GET /api/v1/document/saved` - `POST /api/v1/document/draft` - `POST /api/v1/document/generate` with `{ "document":"", "documentType":"pdf", "documentData":{} }`; returns HTTP 202 and persisted status. - `GET /api/v1/document/jobs/:jobId` - `GET /api/v1/document/:docId` - `GET /api/v1/document/:docId/download` — returns a short-lived URL; it does not delete the artifact. - `DELETE /api/v1/document/job/:jobId` The legacy reference-number GET returns 410 because reads must not consume sequences. References are assigned as part of resource creation.