Khelau — Mobile Developer API Documentation
Base URL:
https://your-domain.com/api
Auth: Laravel Sanctum — Bearer token in
Authorizationheader
Content-Type:
application/json
API Prefix: All routes live under
/api/
Module Index
| Module | File | Description |
|---|---|---|
| Authentication | 01-auth.md | Register, login, OTP, social auth, devices |
| Venues | 02-venues.md | Venue search, details, images, nearby |
| Courts | 03-courts.md | Court info, availability, pricing, schedule |
| Bookings | 04-bookings.md | Create, view, cancel futsal court bookings |
| Payments | 05-payments.md | eSewa, Khalti, FonePay, cash, refunds |
| Wallet | 06-wallet.md | Wallet balance, top-up, transactions |
| Coupons | 07-coupons.md | Validate discount codes at checkout |
| Reviews | 08-reviews.md | Submit and read venue reviews |
| Tournaments | 09-tournaments.md | Browse tournaments, register a team |
| Indoor Games | 10-indoor-games.md | Book PS/chess/table-tennis/carrom etc. |
| Profile and Notifications | 11-profile-notifications.md | Profile, avatar, push token, notifications |
| Error Reference | 00-errors.md | Standard HTTP error codes and shapes |
Authentication Quick-Start
All protected endpoints require:
Authorization: Bearer <token>Obtain the token from POST /api/auth/login or POST /api/auth/otp/verify.
Tokens do not expire automatically — revoke per-device via DELETE /api/auth/devices/{tokenId}.
Standard Response Envelope
Success — single resource
{
"data": { ... }
}Success — collection
{
"data": [ ... ],
"links": { "first": "...", "last": "...", "prev": null, "next": "..." },
"meta": { "current_page": 1, "total": 42, "per_page": 15 }
}Error
{
"message": "Human-readable error description."
}Validation Error (422)
{
"message": "The given data was invalid.",
"errors": {
"field_name": ["Error detail."]
}
}Rate Limits
| Endpoint group | Limit |
|---|---|
POST /api/auth/register | 10 requests / 1 min |
POST /api/auth/login | Configurable (throttle:login) |
POST /api/auth/otp/* | Configurable (throttle:otp) |
All other endpoints: default 60 req / min.
Roles Reference
| Role | Description |
|---|---|
customer | Regular app users |
venue_owner | Owns a venue / SaaS tenant |
manager | Venue manager (staff) |
staff | Venue front-desk |
super_admin | Platform admin |
Most mobile customer flows require only the customer role. Staff-facing endpoints are clearly marked in each module doc.