# Maxor API
Base URL: https://maxor.uk

## Authentication
Use Discord signup on the website. It verifies server membership and issues a login/API key once. Copy it from Key & API. Direct POST /api/customer/create is disabled.
POST /api/customer/login with {"key":"mxr-..."}; GET /api/customer/session; POST /api/customer/logout.
Use the secure browser session or Authorization: Bearer YOUR_KEY. POST requests require Origin: https://maxor.uk.
Never share a key: it can spend your account balance.

## Market
GET /api/public/store-info and /api/public/prices?range=1h|1d|max.
Prices and stock come from Maxor's own dashboard and observed history.

## Deposits
GET /api/customer/payments/methods lists supported coin/network codes, limits and launch readiness.
POST /api/customer/payments/wallet with {"currency":"ltc"} returns your saved address. No deposit amount is required.
Saved addresses are scoped to your customer account and network. Never send to an address from another coin/network. Include any required extra_id, especially for XRP.
GET /api/customer/payments/wallets; POST /api/customer/payments/wallet/status with {"id":"wal_..."}.
New direct Litecoin wallets have a $1 minimum per transaction. Three confirmations and a recorded treasury transfer are required before crediting USD at the verified LTC rate. Other currencies and existing provider addresses use NOWPayments settlement after provider fees. Deposit maximum: $500; larger or uncertain deposits require support review.
Deposits remain disabled until delivery and payment launch verification is complete.

## Buy and sell
POST /api/customer/orders/buy with {"id":"ord_32_lowercase_hex_characters","ign":"MinecraftName","coins":1000000000} spends USD balance and requests in-game delivery.
POST /api/customer/orders/status with {"id":"ord_..."}. Always reuse the same order ID for retries.
Exact in-game confirmation is required for completion. Uncertain deliveries require staff review; they are never automatically sent twice. Confirmed cancellation before delivery refunds the reserved balance once.
POST /api/customer/sell/quote with {"id":"sel_32_lowercase_hex_characters","coins":1000000000}; POST /api/customer/sell/status with {"id":"sel_..."}.
Selling requires a linked Discord account. Supply ign and address in the website quote request, or use the details previously saved through Discord. A live funded bot returns an expiring /pay command and LTC quote.
Rates are controlled by the dashboard. Availability depends on configured game bots, funds and pause controls.

## Account tools
GET /api/customer/activity returns deposits, purchases and legacy invoices owned by this account.
GET/POST /api/customer/preferences reads or saves contact and notification settings.
POST /api/customer/key/new rotates the key and revokes other sessions.
POST /api/customer/notify/test and /api/customer/notify/check support Discord webhook tests and price/cost checks. Completed balance orders can send opted-in Discord webhooks through a persistent retry queue, including when the browser is closed. A retry after an interrupted delivery can duplicate a notification; it cannot duplicate the trade.
Link Discord using the site's OAuth flow; identity is verified by Discord, never by an entered Discord ID.

## Availability
Recovery and uncertain payment reviews require staff support: https://discord.gg/donutdirect.
Limit orders, held game money, normal balance withdrawals, closed-page push and OBS recording are unavailable. Browser price/cost alerts run while the page is open. No real payment or in-game launch test has been completed yet.
