API Documentation — Overview
This section documents the backend endpoints the IQV API Middleware dashboard (frontend) actually calls, verified from source (dashboard/src/routes/api.tsx, dashboard/src/services/*.tsx, dashboard/src/utils/http.tsx, dashboard/src/utils/index.tsx). It contains no invented or hypothetical endpoints.
Base URL
| Environment | Base URL | Source |
|---|---|---|
| Production | https://platform.iqvizyon.com (overridable via VITE_PLATFORM_API_BASE_URL) |
PLATFORM_API_BASE_URL, dashboard/src/utils/index.tsx |
| Development | /iqv-platform-api (Vite's local dev-server proxy, routes to the same backend without CORS) |
API_BASE_URL, dashboard/src/utils/index.tsx + dashboard/vite.config.ts |
Note attachment files use a separate, public MinIO object store address: https://minio.iqvizyon.com (MINIO_PUBLIC_BASE_URL) — independent of the API origin.
Environment Variables
| Variable | Purpose |
|---|---|
VITE_PLATFORM_API_BASE_URL |
The real backend's base URL — platform.iqvizyon.com (used in production) |
VITE_DEMO_MODE |
true/false — enables the legacy/demo ReqRes login flow instead of the real backend |
VITE_REQRES_API_KEY |
API key used only for the demo ReqRes login flow |
Actual secret values are not included in this documentation — only variable names and their purposes are documented.
Endpoint Groups
| Group | Page |
|---|---|
| Authentication | Authentication |
| Platform modules and ordering | Platform Modules |
| Notes and reminders | Notes and Reminders |
| Sharing by email | Mail Box |
| User list and audit log | Users and Audit Log |
Authentication Method
Every request (except /login) carries a JWT bearer token, automatically attached by the central Axios client's request interceptor (dashboard/src/utils/http.tsx): Authorization: Bearer <token>.
The token is looked up in this order: (1) Redux state (admin.token), (2) localStorage.token, (3) localStorage.auth_tokens (parsed JSON, for legacy compatibility). A 401/403 response (except from the login request) triggers automatic logout — see Authentication for details.
Legacy/Demo API (Out of Scope)
The apiRoutes object in dashboard/src/routes/api.tsx defines a legacy/demo login flow (login, logout, users, reviews) against https://reqres.in/api, used only when VITE_DEMO_MODE=true. This is a leftover demo integration from the starter template, unrelated to real application data, and is out of scope for this documentation.