Skip to main content

Overview

This page documents all available API endpoints in Finanzapp. All endpoints require the X-Requested-With: XMLHttpRequest header and return JSON responses.
Base URL: https://pro.finanzapp.es (Production) or http://localhost/FinanzApp (Development)

Authentication Endpoints

Login

Authenticate a user with email and password.
Endpoint: POST /app/auth/sendLogin.php

Request Parameters

string
required
User’s email address
string
required
User’s password (min 8 chars, 1 uppercase, 1 number)
string
reCAPTCHA token for bot protection

Response

boolean
required
Whether the login was successful
string
Human-readable status message
object
User information (only on success)

Response Examples

200 - Success
200 - Invalid Credentials
403 - Forbidden

Register

Create a new user account.
Endpoint: POST /app/auth/sendRegister.php

Request Parameters

string
required
User’s full name
string
required
User’s email address (must be unique)
string
required
User’s password (min 8 chars, 1 uppercase, 1 number)
string
required
Password confirmation (must match password)
string
required
Terms acceptance (must be “on”)
string
Newsletter subscription (“on” or omit)

Response

boolean
required
Registration success status
string
required
Status message

Response Examples

200 - Success
200 - Email Exists

Google Login

Authenticate using Google OAuth credentials.
Endpoint: POST /app/auth/google-callback-login.php

Request Parameters

string
required
Google JWT credential token

Response

string
required
"exists" if user exists, "inserted" if new user created
object
User profile data from Google

Response Examples

Existing User
New User

Logout

End the current user session.
Endpoint: POST /app/auth/logout.php Source: /home/daytona/workspace/source/app/auth/logout.php

Request Parameters

No parameters required.

Response

boolean
required
Logout success status
string
required
Status message

Response Examples

200 - Success
403 - Invalid Request
405 - Method Not Allowed

User Management

Update User Configuration

Update user profile settings including name, password, avatar, and notification preferences.
Endpoint: POST /app/auth/sendUserConfig.php Authentication Required: Yes (active session)

Request Parameters

string
required
User’s full name
string
URL of selected avatar image (from predefined options)
string
New password (optional, only if changing password)
string
Password confirmation (required if password provided)
string
Newsletter preference (“on” or omit)

Available Avatars

Finanzapp provides 10 predefined avatar options plus a default:

Response

boolean
required
Update success status
string
Status message

Response Examples

200 - Success
200 - Validation Error

Delete Account

Permanently delete the user’s account and all associated data.
Endpoint: POST /app/auth/deleteAccount.php Source: /home/daytona/workspace/source/app/auth/deleteAccount.php Authentication Required: Yes (active session with email)
This action is irreversible. All user data will be permanently deleted from the database.

Request Parameters

No parameters required. Uses the email from the current session.

Implementation Details

The endpoint (source: /home/daytona/workspace/source/app/auth/deleteAccount.php:21-24):

Response

boolean
required
Deletion success status
string
required
Status message

Response Examples

200 - Success
200 - No Active Session
403 - Invalid Request

Password Reset

Request Password Reset

Send a password reset email to the user.
Endpoint: POST /app/auth/sendResetLink.php

Request Parameters

string
required
Email address of the account to reset

Response

boolean
required
Email sent status
string
required
Status message

Response Examples

200 - Success
200 - Email Not Found

Reset Password

Set a new password using a reset token.
Endpoint: POST /app/auth/resetPassword.php

Request Parameters

string
required
Password reset token from email link
string
required
New password (min 8 chars, 1 uppercase, 1 number)
string
required
Password confirmation (must match new_password)

Response

boolean
required
Password reset status
string
required
Status message

Response Examples

200 - Success
200 - Invalid Token
200 - Password Mismatch

Data Management

Receive Data

Generic endpoint for receiving and storing JSON data.
Endpoint: POST /receive-data.php Source: /home/daytona/workspace/source/receive-data.php

Request Parameters

object | array
required
JSON data to store. Can be a single object or array of objects.

Implementation Details

The endpoint writes received JSON data to a file (data.txt) for logging/storage:

Response

boolean
required
Data save status
string
required
Status message

Response Examples

200 - Success
200 - Invalid JSON
403 - Access Denied

Error Responses

All endpoints follow a consistent error response format:

Common Error Codes

Missing or invalid X-Requested-With header
Invalid HTTP method used
No active session or session expired
Invalid or missing required parameters

Validation Errors


Rate Limiting

Currently, there is no explicit rate limiting implemented in the API. For production deployments, consider adding:
  • Request throttling per IP address
  • Login attempt limiting (prevent brute force)
  • CAPTCHA verification on repeated failures
  • API key management for programmatic access

Testing the API

You can test the API endpoints using various tools:

Using Postman

  1. Create a new request
  2. Set method to POST
  3. Add header: X-Requested-With: XMLHttpRequest
  4. For form data: Select “Body” > “form-data” and add parameters
  5. For JSON: Select “Body” > “raw” > “JSON” and paste JSON data

Using Browser Console


Best Practices

All API endpoints validate this header to prevent direct browser access and CSRF attacks.
Check for authentication errors and redirect users to login when sessions expire.
Implement client-side validation to provide immediate feedback and reduce server load.
Always use HTTPS to encrypt sensitive data like passwords during transmission.
Always handle errors gracefully and provide meaningful feedback to users.

Need Help?

API Overview

Learn about API architecture and concepts

Authentication

Detailed authentication documentation