Profile and Notifications
Base paths:
/api/profile— user profile management/api/notifications— in-app notification inbox/api/notifications/device-token— push token registration
All endpoints require authentication.
Profile Endpoints
GET /api/profile [Auth required]
Get the authenticated user's profile.
Response 200:
{
"data": {
"id": 12,
"name": "Jane Doe",
"email": "jane@example.com",
"phone": "9800000000",
"avatar": "https://your-domain.com/storage/avatars/jane.jpg",
"wallet_balance": "1250.00",
"is_active": true,
"email_verified": true,
"phone_verified": true,
"roles": ["customer"],
"permissions": [],
"created_at": "2025-01-01 10:00:00"
}
}PUT /api/profile [Auth required]
Update the authenticated user's profile fields.
Request body (all fields optional):
{
"name": "Jane Updated",
"phone": "9801111111"
}| Field | Type | Description |
|---|---|---|
name | string | Display name |
phone | string | Phone number |
Response 200: Updated UserResource.
POST /api/profile/password [Auth required]
Change the account password.
Request body:
{
"current_password": "oldpass",
"password": "newpass123",
"password_confirmation": "newpass123"
}| Field | Type | Required | Description |
|---|---|---|---|
current_password | string | Yes | Existing password |
password | string | Yes | New password (min 8 characters) |
password_confirmation | string | Yes | Must match password |
Response 200:
{ "message": "Password updated." }POST /api/profile/avatar [Auth required]
Upload a new profile picture.
Content-Type: multipart/form-data
Form fields:
| Field | Type | Required | Description |
|---|---|---|---|
avatar | file | Yes | Image file (jpg, png, webp — max 2 MB) |
Response 200: Updated UserResource with new avatar URL.
Notification Endpoints
GET /api/notifications [Auth required]
Get the user's notification inbox (paginated, 20 per page).
Response 200:
{
"data": [
{
"id": "uuid-...",
"type": "App\\Notifications\\BookingConfirmed",
"data": {
"message": "Your booking BK-2025-0042 has been confirmed.",
"booking_id": 42
},
"read_at": null,
"created_at": "2025-06-15 08:30:00"
}
],
"links": { ... },
"meta": { ... }
}Tips:
read_at: nullmeans the notification is unread — show a badge.- Count unread items by filtering
datawhereread_at === null.
PATCH /api/notifications/{id}/read [Auth required]
Mark a single notification as read.
Path parameter: id — the UUID of the notification.
Response 200:
{ "message": "Marked as read." }POST /api/notifications/read-all [Auth required]
Mark all unread notifications as read.
Response 200:
{ "message": "All marked as read." }PUT /api/notifications/device-token [Auth required]
Register / update the device's FCM push token.
Call this endpoint every time the app receives a new FCM token (on login, token refresh).
Request body:
{
"token": "fcm-device-token-string-here..."
}| Field | Type | Required | Description |
|---|---|---|---|
token | string | Yes | Firebase Cloud Messaging device token (max 4096 chars) |
Response 200:
{ "message": "Device token saved." }GET /api/notifications/firebase-config [Auth required]
Get the Firebase configuration object needed to initialise the Firebase SDK on the client.
Response 200:
{
"api_key": "...",
"auth_domain": "...",
"project_id": "...",
"storage_bucket": "...",
"messaging_sender_id": "...",
"app_id": "...",
"vapid_key": "..."
}Only needed if you initialise Firebase on the client side (e.g. Flutter Web). Native mobile apps use the native Firebase SDK with the
google-services.json/GoogleService-Info.plistfiles provided separately.
Push Notification Types
| Notification class | When triggered |
|---|---|
BookingConfirmed | Payment received and booking confirmed |
BookingCancelled | Booking cancelled |
BookingReminder | Day-before reminder |
IndoorGameBookingConfirmed | Indoor game booking confirmed |
TournamentRegistered | Team registered in a tournament |
The
datafield inside each notification varies by type but always includes a human-readablemessagestring you can display directly.
FCM Integration — Mobile Quick-Guide
App launch
└─ Request notification permission
└─ Get FCM token
└─ PUT /api/notifications/device-token (update on every new token)
App foreground
└─ Show in-app notification banner
App background / killed
└─ OS delivers push from FCM
└─ On tap: navigate to relevant screen using payload data
Notification inbox screen
└─ GET /api/notifications
└─ On open: PATCH /api/notifications/{id}/read
└─ "Mark all read" button: POST /api/notifications/read-all