Revert one template slot to the default (admin)
/api/notification-templatesDeletes the override row. Deliberately NOT plan-gated: an org that has downgraded must always be able to get back to the stock templates.
Authorization
sessionCookie The dashboard's Supabase Auth session cookie, set at sign-in. Large sessions are split across
numbered chunks (…auth-token.0, .1), so treat this as a cookie family rather than one name.
Every request re-validates it against the Auth server (getUser()), never by decoding the cookie
locally: a JWT nothing has checked is not a credential. Tenancy is then read from the verified
app_metadata.company_id claim and enforced by row-level security; it is never read from request
input, on any route, ever.
role (admin / staff) is deliberately not in RLS. It gates specific actions in route code,
the operations marked admin below, so hiding a button in the UI is cosmetic only, and a route's
own check is the enforcement.
In: cookie
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
curl -X DELETE "https://example.com/api/notification-templates" \ -H "Content-Type: application/json" \ -d '{ "type": "confirmation", "channel": "email" }'{ "ok": true}Read notification templates GET
The only GET among the session-authenticated routes; everything else the dashboard reads comes through server components, not the API. Returns the stock templates alongside the org's overrides so the editor can show both and offer "revert to default" without a second source of truth on the client.
Customise one template slot (admin, paid) PUT
Upserts one (type, channel) slot. Written with service-role because the table has no INSERT/UPDATE policy for `authenticated` at all; this route is the plan gate, so it has to be the only writer. Unknown `{{variables}}` are rejected at the write boundary rather than degrading to a blank word at render time. That is the difference between "your template is wrong" and "your guests got a broken email".