Getting Started

First Request

No auth required β€” just hit the health endpoint:

curl https://api.tw3002.net/health

Response:

{
  "status": "ok",
  "version": "1.0.4"
}

Response Format

Every response is JSON. The API uses two top-level shapes:

Success:

{
  "success": true,
  ...data
}

Error:

{
  "error": "human-readable message"
}

HTTP Status Codes

CodeMeaning
200OK
400Bad request (missing/invalid params)
401Unauthorized (missing/invalid token)
403Forbidden (insufficient action points, not in sector, etc.)
404Not found
405Method not allowed
409Conflict (fighter encounter required)
429Rate limit exceeded
500Internal server error

Rate Limits

These limits apply to external API callers (scripts, curl, third-party tools). Official game-client requests from https://play.tw3002.net, https://playtradewars.net, http://localhost:5173, and other configured game origins are not counted against gameplay, authenticated-read, or public buckets. Registration, verification, and admin routes stay IP-limited for every caller.

CategoryLimitWindowApplies to
Auth (register/verify)5per IP per minuteEvery caller
Gameplay (POST)60per player per minuteExternal callers
Reads (auth GET)60per player per minuteExternal callers
Public reads60per IP per minuteExternal callers
Admin10per IP per minuteEvery caller

External-caller responses include rate limit headers:

X-RateLimit-Limit: 60
X-RateLimit-Remaining: 59
X-RateLimit-Reset: 1717342800

If you hit a limit, you get 429 with a Retry-After header:

Retry-After: 45

Action Budget Headers

Gameplay responses include action point headers:

X-ActionPoints-Remaining: 47

If you’re out of points:

X-ActionPoints-Remaining: 0
X-ActionPoints-NextRefill: 5

Next Steps