# Addons - X-Radius API

> Base URL: https://x-radius.com/api/v1
> Auth: Authorization: Bearer xrt_...  (a manager API token)
> Envelope: {"data": ...}; lists add {"meta":{page,page_size,total,has_next}}
> Errors: {"error":{"code","message","request_id"}} - branch on code, never on message
> Timestamps: yyyy-MM-dd HH:mm:ss, UTC
> Money: a bare JSON number in major units, with an ISO-4217 currency code beside it
> Idempotency: redeem and activate endpoints take a client-supplied request_id (UUID)
>
> This page: https://x-radius.com/docs/api/addons
> Every group: https://x-radius.com/llms.txt

8 endpoints in 1 resource groups. 0 carry a hand-written reference entry with examples; the remaining 8 are generated from the running router and carry method, path, authentication, permission and rate-limit bucket, but no request or response example.

### Sell add-ons

`GET /api/v1/addons`

- Authentication: manager session (JWT) or API token
- Permission: `prm_users_addon` (Sell add-ons)
- Risk: write

_This endpoint has no hand-written reference entry yet. The method, path, authentication, permission and rate limit above are generated from the running router and are accurate; there is no request or response example._


### View add-ons

`GET /api/v1/admin/addons`

- Authentication: manager session (JWT) or API token
- Permission: `prm_addons_index` (View add-ons)
- Risk: read

_This endpoint has no hand-written reference entry yet. The method, path, authentication, permission and rate limit above are generated from the running router and are accurate; there is no request or response example._


### Manage add-ons

`POST /api/v1/admin/addons`

- Authentication: manager session (JWT) or API token
- Permission: `prm_addons_manage` (Manage add-ons)
- Risk: write
- Rate limit bucket: `t_mutate`

_This endpoint has no hand-written reference entry yet. The method, path, authentication, permission and rate limit above are generated from the running router and are accurate; there is no request or response example._


### Manage add-ons

`POST /api/v1/admin/addons/bulk-delete`

- Authentication: manager session (JWT) or API token
- Permission: `prm_addons_manage` (Manage add-ons)
- Risk: write
- Rate limit bucket: `t_mutate`

_This endpoint has no hand-written reference entry yet. The method, path, authentication, permission and rate limit above are generated from the running router and are accurate; there is no request or response example._


### Manage add-ons

`DELETE /api/v1/admin/addons/{id}`

- Authentication: manager session (JWT) or API token
- Permission: `prm_addons_manage` (Manage add-ons)
- Risk: write
- Rate limit bucket: `t_mutate`

_This endpoint has no hand-written reference entry yet. The method, path, authentication, permission and rate limit above are generated from the running router and are accurate; there is no request or response example._


### Manage add-ons

`PATCH /api/v1/admin/addons/{id}`

- Authentication: manager session (JWT) or API token
- Permission: `prm_addons_manage` (Manage add-ons)
- Risk: write
- Rate limit bucket: `t_mutate`

_This endpoint has no hand-written reference entry yet. The method, path, authentication, permission and rate limit above are generated from the running router and are accurate; there is no request or response example._


### View add-ons

`GET /api/v1/admin/addons/{id}/allowed-profiles`

- Authentication: manager session (JWT) or API token
- Permission: `prm_addons_index` (View add-ons)
- Risk: read

_This endpoint has no hand-written reference entry yet. The method, path, authentication, permission and rate limit above are generated from the running router and are accurate; there is no request or response example._


### Manage add-ons

`PUT /api/v1/admin/addons/{id}/allowed-profiles`

- Authentication: manager session (JWT) or API token
- Permission: `prm_addons_manage` (Manage add-ons)
- Risk: write
- Rate limit bucket: `t_mutate`

_This endpoint has no hand-written reference entry yet. The method, path, authentication, permission and rate limit above are generated from the running router and are accurate; there is no request or response example._


