The OpenAPI 3.0 document is available at /api/v1/openapi.json; the browser viewer is /api/docs.
Public endpoints cover site/compliance information, contact, businesses, POIs, routes, news, territorial events, funding, highlights, weather, promotions and videos. GET /api/v1/events and GET /api/v1/events/{slug} return published event dates, localised editorial copy, locality, status, official source and safe image attribution. GET /api/v1/explore provides the configurable territorial centre/bounds, typed map points, result counts and meaningful recent changes. GET /api/v1/seo/metadata provides safe resolved title, description, canonical, language alternatives, social metadata and indexability for a public route key. Bearer-authenticated endpoints cover the current user, route plans, reviews and MAAT. /api/v1/admin/* additionally requires administrator authorisation and provides settings, content, stakeholder, user and SEO management.
GET /api/v1/regional-links returns enabled, localised territory-resource metadata, independent homepage/footer visibility flags and accessible local icon metadata. GET /api/v1/footer-resources returns zero or one eligible footer-visible resource and excludes homepage-only records. Review resources include original language, translation availability and reviewable type; original account email and internal synthetic classification are not exposed publicly.
Route resources include localised summary/path description, day-grouped ordered waypoints, linked-entity references, route legs, routed GeoJSON, distance, separate travel/visit/buffer/total duration, routing status, mobility and evidence-limited accessibility notes, source review metadata and local media paths. Authenticated owners can recalculate personal plans; administrators can recalculate editorial routes. Importers must not expose staging identifiers, provider credentials, account data or reconciliation reports through public resources.
User administration responses include account state and relationship counts but never password material, reset tokens or remember tokens. Public contact metadata excludes postal addresses, mail destinations and transport settings.
Protected administrator statistics accept rolling/custom ranges, range=six_complete, and source=operational|demonstration. Demonstration selection is accepted only in local/testing environments; production always resolves to operational data. User filters include source, locale, review ownership and plan ownership. POI administration exposes featured rank, publication and safe provenance metadata. Funding payloads expose opportunity type, effective status, dates, amount, days remaining and official source without exposing internal settings.
Protected SEO endpoints expose global settings, per-target locale overrides, redirects and audit summaries. Writes require administrator authorisation, validate supported locales and target types, reject redirect loops and private destinations, and never expose search-engine account credentials. Canonical and social URLs are resolved against the configured production base URL; local/test rendering remains noindex, nofollow.
Use ?lang=es, ?lang=en or ?lang=pt; Spanish is the documented record-level fallback. Public catalogues exclude synthetic, inactive and unpublished records by default. Validation errors use Laravel's 422 structure and paginated lists use standard data, links and meta fields.
Use the documented login/token flow to obtain a bearer token and send Authorization: Bearer CHANGE_ME plus Accept: application/json. /api/v1/admin/* requires an active, approved administrator. Public responses never include passwords, hashes, reset/invitation tokens, internal contact destinations or account email addresses. Apply server-side rate limits to login, reset, integration-test and recalculation actions.
curl --fail --header 'Accept: application/json' \
'https://example.org/api/v1/routes?lang=en&page=1'
curl --fail --header 'Accept: application/json' \
'https://example.org/api/v1/explore?lang=en&type=poi'
curl --fail --header 'Accept: application/json' \
'https://example.org/api/v1/seo/metadata?lang=en&route=explore'
curl --fail --header 'Accept: application/json' \
'https://example.org/api/v1/openapi.json'Treat the generated OpenAPI document as the endpoint contract. Run the OpenAPI coverage test after adding or removing an API route.
Public news responses include content status, localised alt text and attribution. /assets/image-provenance exposes safe source/licence metadata without server paths. Protected /admin/media-assets endpoints provide the full operational provenance and usage view to administrators only.
ARISE is Archaeological Routes for Inclusive Synergy & Entrepreneurship in Sierra y Mancha Conquense, developed by Obsidian Innovation Institute - Associação and Xilbi Sistemas de Informacion SL within the scope of the PoliRuralPlus project (Grant Agreement No 101136910).
The project PoliRuralPlus has received funding from the European Union’s Horizon Europe research and innovation programme under grant agreement No 101136910.
Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the European Union or European Research Executive Agency (REA). Neither the European Union nor the granting authority can be held responsible for them.
First-party ARISE software and documentation are licensed under
Apache-2.0. See LICENSE for the authoritative terms and NOTICE for
project attribution. Third-party material retains its own terms.