REST API

Base URL https://api.ikomment.com/v1. JSON everywhere; errors use the envelope { code, message, requestId } with codes like ik.comment.too_long. Mutating POSTs accept an Idempotency-Key header. Cursor pagination uses opaque tokens — never offsets.

Authentication

Public / widget

GET    /config/:siteKey
GET    /threads/:siteKey?url=&title=
GET    /threads/:id/comments?sort=newest|oldest|top&cursor=&limit=
POST   /threads/:id/comments          { body_md, parent_id?, author_name?, author_email?, form_issued_at, form_signature }
PATCH  /comments/:id                  { body_md }
DELETE /comments/:id
POST   /comments/:id/vote             { value: 1 | -1 }
POST   /comments/:id/react            { emoji }
POST   /comments/:id/report           { reason: spam|abuse|off_topic|other, note? }
GET    /comments/:id
GET    /threads/:id/seo               (bot-rendered HTML + JSON-LD, flag-gated)

Site admin

GET/POST/PATCH/DELETE /sites
GET/PATCH             /sites/:id/settings
GET/PATCH             /sites/:id/flags
POST                  /sites/:id/rotate-key
GET/POST/DELETE       /sites/:id/api-keys
GET/POST/PATCH/DELETE /sites/:id/word-filters
GET/PATCH             /sites/:id/mail-templates/:key
GET/POST/PATCH/DELETE /sites/:id/webhooks
GET/POST              /sites/:id/badges
POST                  /sites/:id/badges/:commentId/award|remove
GET                   /sites/:id/usage?days=30
POST                  /sites/:id/purge-cache

Moderation

GET  /moderation/queue?site_id=&status=pending|approved|spam
POST /moderation/comments/:id/approve|spam|delete|pin
POST /moderation/batch                         { ids: [...], action }
GET  /reports?site_id=&status=open
POST /reports/:id/resolve                      { action: approve|spam|delete|dismiss }
GET  /audit?site_id=
GET  /spam/health?site_id=
POST /spam/retrain?site_id=

Users, data ops, billing, ops

GET  /users/me            PATCH /users/me
GET  /users/me/notifications
GET/PATCH /users/me/preferences
POST /notifications/optout/:token
POST /imports (multipart)      GET /imports/:id
POST /exports                  GET /exports/:id/download
POST /privacy/export           POST /privacy/delete
POST /billing/checkout|portal  POST /webhooks/stripe
GET  /health /version /status