Disconnect the connected custom domain (admin)
/api/organization/website/domainRemoves the domain from this Vercel project, then the book_custom_domains row. Idempotent: 200 with no error if nothing was connected in the first place, the end state ("no domain connected") is what the caller wants either way.
Authorization
sessionCookie The dashboard's Supabase Auth session cookie, set at sign-in. Large sessions are split across
numbered chunks (…auth-token.0, .1), so treat this as a cookie family rather than one name.
Every request re-validates it against the Auth server (getUser()), never by decoding the cookie
locally: a JWT nothing has checked is not a credential. Tenancy is then read from the verified
app_metadata.company_id claim and enforced by row-level security; it is never read from request
input, on any route, ever.
role (admin / staff) is deliberately not in RLS. It gates specific actions in route code,
the operations marked admin below, so hiding a button in the UI is cosmetic only, and a route's
own check is the enforcement.
In: cookie
Response Body
application/json
application/json
application/json
application/json
application/json
curl -X DELETE "https://example.com/api/organization/website/domain"{ "ok": true}Re-check this company's connected domain against Vercel (admin) PATCH
The poll the UI drives every ~30s while a connected domain sits unverified, waiting on the operator's own DNS change to propagate. Vercel has no webhook for "DNS propagated" or "cert issued" (see src/lib/vercel/domains.ts), so re-checking on demand against Vercel's own verify + config endpoints is the documented pattern. No-op success is not possible here: 404 if nothing is connected yet.
This website's traffic (self-hosted, cookieless) GET
The "Your website" card's one data source: a self-hosted Umami instance (analytics.solvintia.com), one Umami "website" per company for clean per-tenant isolation (no cross-tenant prefix-summing to get wrong). Cookieless by design, see the Cookie Policy entry this shipped alongside for the exact claim. Lazily provisions the company's Umami website on first call if it has none yet (ensureUmamiWebsiteId, src/lib/booking/umami-website-admin.ts) rather than requiring a separate setup step. Included on Pro (src/lib/plan.ts, `analytics`), checked before any Umami call; readable by any member once past that gate, since this is a display of the business's own public traffic, not a setting.