SoundRipAPI Studio
{{ specVersion }}
{{ v.label }}{{ v.meta }}
Endpoints
expandcollapse
▶{{ a.code }}{{ a.name }}{{ a.meta }}
▶{{ g.name }}{{ g.screens }}{{ g.count }}
{{ o.method }}{{ o.short }}
{{ v.label }}{{ v.meta }}
{{ runAllLabel }}
{{ runAllSummary }}
{{ loadingText }}
Live areas · {{ liveAreaNames }}

{{ entCount }} endpoints, {{ scenarioCount }} scenarios, {{ flowCount }} flows.

Pick an endpoint on the left to read it and call it on the right. Everything here is generated from soundrip.api.json — the same file the mock, the tests and Claude's brief are built from.
Environment
{{ envLabel }}
{{ envDesc }}
Last full run
{{ runAllSummary }}
Every scenario, every flow, the realtime round-trips and the security sweep. Mock is reset first.
Test accounts
marisol@vega.studio · member
night@porter.fm · live broadcaster
lee@drift.fm · unconfirmed
tobi@adeyemi.ng · disposable
password: hunter22!
For the mobile team
Host this folder (node server.mjs) and point the app's base URL at /v1. The mock keeps state, sends "emails" to /__mock/inbox, and behaves exactly like the contract says.
For the backend
Switch to Local, run the same tests against the real server. A red check is a precise bug report: endpoint, scenario, field.
For Claude Code
Export → CLAUDE.md, one tasks/<AREA>.md per area and errors.json into the backend repo. Claude builds down the task list and uses the CLI (npm run contract) as its definition of done.
Request log
{{ l.status }}{{ l.method }} {{ l.path }}{{ l.ms }} ms{{ l.env }}
{{ op.area }}/{{ op.tier }}/{{ op.operationId }}
{{ op.method }}{{ op.path }}
{{ op.summary }}
{{ op.description }}
{{ s.code }} {{ s.title }} Auth: {{ op.auth }} Rate limit: {{ op.rate }}
Securityrole · {{ op.secRole }}confirmed email · {{ op.secConfirmed }}strict body · {{ op.secStrict }}rate key · {{ op.secRate }}{{ op.secPii }}
{{ op.reqTitle }}
{{ f.name }} {{ f.req }}{{ f.type }}{{ f.rule }}
Responses
{{ r.status }}{{ r.desc }}{{ r.schema }}
{{ r.example }}
Errors → UI state
{{ e.status }}{{ e.code }}{{ e.message }}{{ e.ui }}
Implementation notes · for whoever builds it
•{{ n }}
Acceptance checklist
{{ runOpLabel }}
{{ c.mark }}{{ c.text }}{{ c.detail }}
Scenarios run in order against the current environment with your saved tokens; "Run all tests" in the sidebar resets the mock first and runs everything.
Registry

{{ errCount }} error codes.

Every non-2xx response is { error: { code, message, …details } }. A code not in this list fails the contract test.
StatusCodeMessageScreensUI state
{{ e.status }}{{ e.code }}{{ e.message }}{{ e.screens }}{{ e.ui }}
Models

{{ modelCount }} shared schemas.

{{ m.name }}{{ m.desc }}
{{ f.name }} {{ f.req }}{{ f.type }}
{{ m.example }}
Flows

{{ flowCount }} end-to-end runs.

Each flow resets the mock, then chains real calls — tokens and inbox links are carried from step to step. Runs against {{ envLabel }}.
{{ f.name }}
{{ f.description }} {{ f.screens }}
{{ f.summary }}
{{ f.runLabel }}
{{ s.mark }}{{ s.screen }}{{ s.label }}{{ s.op }} {{ s.status }} {{ s.detail }}{{ s.ms }}
For the app team

{{ screenCount }} screens, each with its calls, events and errors.

Same codes as Prototype v3. For every screen: what to call when it opens, what each tap calls, which realtime events it reacts to, and what to show for each error code. {{ clientOnlyCount }} screens need no API at all and say so.
{{ a.code }} · {{ a.name }} {{ a.count }}
{{ s.code }}{{ s.title }}{{ s.apiLabel }}{{ s.note }}
On open
•{{ o }}
Then: {{ s.then }}
Actions
{{ a.k }}→{{ a.v }}
Realtime
{{ a.k }}{{ a.v }}
Errors
{{ a.k }}{{ a.v }}
—{{ r }}
Security standard · API + Flutter

Every rule is written down; the automatable ones run on every test.

{{ secSummary }}
Automated sweep · {{ secSweepCount }} endpoints
{{ secSweepSummary }}
{{ secRunLabel }}
For each endpoint: no token → 401 · forged token → 401 · unknown body field → 422 · non-owner → 403 · no dob / password in the response.
✗ {{ f.key }} {{ f.detail }}
{{ sec.title }}
•{{ i }}
Per-endpoint matrix
EndpointRoleConfirmedStrict bodyRate key
{{ r.method }} {{ r.path }}{{ r.role }}{{ r.confirmed }}{{ r.strict }}{{ r.rate }}
For the backend team & Claude

Everything that is not an endpoint.

Data model, the services around the API, background jobs, security rules, observability, environments and the definition of done. Exported as BACKEND.md next to CLAUDE.md.
Entities
{{ x.name }}{{ x.desc }}
Services
{{ x.name }}
{{ x.desc }}
{{ l.title }}
•{{ i }}
Realtime · WebSocket {{ rtUrl }}

REST writes, realtime reads.

One socket per app session. Subscribe to home, user or stream:{id}; every write you make in the playground shows up here as an event. Simulate the broadcaster to see the six on-air states.
{{ rtStatus }}{{ rtWho }}
{{ rtTokenLabel }}
{{ rtBtnLabel }}
Subscribe
Unsubscribe
Ping
Typing
{{ q.label }}
Simulate the broadcaster · {{ rtSimStream }}mock only
{{ x.label }}
Event log · {{ rtCount }}
clear
Nothing yet. Connect, subscribe to stream:str_np_live, then send a chat message from the playground or press a simulate button.
{{ e.time }}{{ e.seq }}{{ e.type }}{{ e.channel }}{{ e.data }}
Realtime tests
{{ rtTestLabel }}
{{ rtTestSummary }}
{{ t.mark }}{{ t.label }}
{{ t.detail }}
Client → server
{{ o.op }} {{ o.fields }}
→ {{ o.reply }}
Channels
{{ c.name }} · {{ c.auth }}
{{ c.events }}
Event catalogue · server → client
{{ ev.type }}{{ ev.screens }}
{{ ev.channel }}{{ ev.description }}
{{ ev.example }}
Implementation notes
•{{ n }}
Export

Handoff files, generated from the contract.

Drop these into the backend repo. Claude Code reads CLAUDE.md first, then works down one tasks file per area; the CLI proves each box.
Backend stack · D5
CLAUDE.md is written in the idiom of the selected stack. The contract and tests do not change.
Download handoff · {{ handoffCount }} files
{{ k.label }}
Or from a terminal: node export.mjs --out ../soundrip-backend --stack <id> --base https://api-staging.soundrip.app — writes CLAUDE.md, api/ (contract, errors, tasks, MOBILE, BACKEND, SECURITY, seed, Postman + 3 environments) and tests/contract/.
{{ t.label }}
{{ copyLabel }}
Download {{ exportFile }}
{{ exportText }}
Playground
{{ e.label }}
{{ envStatus }}
In-browser mock. Same engine the hosted server runs; state lives in this tab.
Scenario
{{ s.label }} {{ s.status }}
{{ requires }}
{{ op.method }}
Headers · JSON
Body · JSON
{{ authHint }}
{{ sendLabel }}
Response{{ respStatus }} · {{ respMs }} ms
{{ respBody }}
{{ c.mark }}{{ c.name }}{{ c.detail }}
Session vars
clear
access_token · {{ varAccess }}
refresh_token · {{ varRefresh }}
user · {{ varUser }}
{{ inboxLabel }}
Reset mock
No emails yet. Sign up or request a reset.
{{ m.subject }}{{ m.when }}
to {{ m.to }}
{{ m.link }} ↗