# Brandlit integrator docs

Plain HTTP integration for Brandlit Studio.

| Doc | What |
|-----|------|
| [OpenAPI JSON](/openapi.json) · [YAML](/openapi.yaml) | OpenAPI 3.0.3 public API reference |
| [curl cookbook](/docs/CURL-COOKBOOK.md) | Copy-paste curl happy paths |
| [CLI README](/docs/CLI-README.md) | `brandlit` CLI v1.0.0: zero-dependency Node; connect login, projects save/publish, domain attach/verify |

**Base URL:** https://brandlit.blacklabelbots.com

## Auth in one line

Cookie jar: guest `bl_uid` (or header `X-Brandlit-Uid`), then Connect device code or email sign-in sets `bl_session`. No machine Bearer tokens yet.

## Fastest path: the CLI

```bash
brandlit connect login --open
ID=$(brandlit projects create --name Demo | jq -r .project.id)
brandlit projects save "$ID" --file index.html
brandlit projects publish "$ID"
```

## Happy path (raw HTTP)

1. `GET /api/auth/me` (sets a guest cookie)
2. `GET /api/auth/grokbot/start`, approve, then poll until `approved` (sets `bl_session`)
3. `POST /api/projects`, then `…/save`, then `…/publish`
4. `POST /api/grok` with `{ utterance, snapshot? }`
5. `GET /api/domain/instructions`, then attach and verify your own domain with a DNS CNAME
6. `GET /api/billing/products` for the current catalog (read-only)

## Known limits

| Area | Status |
|------|--------|
| `brandlit` CLI | Shipped (v1.0.0). Cookie-jar auth; no checkout or domain purchase by design |
| `Authorization: Bearer` machine tokens | Not available yet; CLI and curl use the cookie jar |
| OAuth callback `/api/auth/grokbot/callback` | Returns 501; use the device-code flow |
| Password reset email | May return a copyable reset link instead of sending email |
| Domain purchase | Partial; attaching your own domain with a CNAME is the reliable path |
| Prices | Read `/api/billing/products`; do not hard-code amounts |
