appserver ↔ dash-app — API comparison

Left: Flask-RESTful apprunner/app_server + FastAPI appserver4/{cim,dim,monitor}.
Right: FastAPI dash-app/services/*. External path prefixes shown from nginx.conf.

~140
Endpoints in dash-app
~85
Endpoints in appserver
47
Mapped (both sides)
62
New in dash-app
33
Dropped from appserver

Mapped endpoints present in both

Same functional surface, generally with a rename or namespace move. Where dash-app has both a modern (/config/infra/*, /config/ops/*) and a compat (/config/admin/*) path, both are listed — the compat one preserves the appserver contract byte-for-byte for old clients.

Auth & account

appserverdash-appNotes
POST /admin/login POST /config/common/login
POST /config/admin/login
Cognito replaced by local bcrypt + JWT. Compat path kept for old ICD clients.
POST /admin/update_password
POST /change_password
POST /config/common/update_password Old-password verify + hash-and-store.

Company / user / infra

appserverdash-appNotes
GET /admin/company
POST /admin/company
DEL /admin/company
GET /config/infra/company
POST /config/infra/company
DEL /config/infra/company/{id}
+ compat /config/admin/company
DORI_ADMIN sees every tenant; others see just their own row. UUID-minted company_id matches appserver dar_model.Company().add().
GET /admin/user
POST /admin/user
DEL /admin/user
GET /config/infra/user
POST /config/infra/user
DEL /config/infra/user/{id}
GET/POST/DEL /config/common/user
+ compat /config/admin/user
Split: /infra/user = platform-admin cross-tenant, /common/user = tenant-scoped.
GET /admin/credentials
POST /admin/credentials
DEL /admin/credentials
GET /config/infra/credentials
POST /config/infra/credentials
+ compat /config/admin/credentials
Delete removed — creds are overwritten instead.
GET /admin/mlc
POST /admin/mlc
DEL /admin/mlc
GET /admin/mlclist
GET /config/infra/mlc
POST /config/infra/mlc
DEL /config/infra/mlc/{id}
+ compat /config/admin/mlc
/mlclist collapsed into GET /mlc.
GET /client
POST /client
DEL /client
GET /config/infra/client
POST /config/infra/client
DEL /config/infra/client/{id}
Namespaced under /infra/.
GET /client_user
POST /client_user
DEL /client_user
GET /config/ops/client_user Write side folded into POST /config/infra/client body (attach users at create time).

Ops — location / device / subscriber

appserverdash-appNotes
GET /admin/location
POST /admin/location
DEL /admin/location
GET /config/ops/locations
POST /config/ops/locations
DEL /config/ops/locations/{id}
+ compat /config/admin/locations
UUID-minted location_id matches dar_model.Location().add().
GET /admin/camera
POST /admin/camera
DEL /admin/camera
GET /admin/monitor
POST /admin/monitor
DEL /admin/monitor
GET /config/ops/device
POST /config/ops/device
DEL /config/ops/device/{id}
+ compat /config/device
alembic 003 folded d_monitor into device. Capture-worker fields are now nullable columns on the device row.
GET /admin/subscription
POST /admin/subscription
DEL /admin/subscription
GET /admin/subscriptionslist
GET /config/ops/subscriber
POST /config/ops/subscriber
GET /config/ops/subscriptions
POST /config/ops/subscriptions
Renamed & split: /subscriber = the person, /subscriptions = event-type ↔ subscriber wiring.
GET /user_camera
POST /user_camera
DEL /user_camera
GET /dmf/user_camera
POST /dmf/user_camera
Moved into DMF (media flow) service.
GET /list_employees GET /config/ops/employees
+ compat /config/list_employees

Events / analytics

appserverdash-appNotes
POST /events
POST /get_last_events
POST /analytics/get_events
POST /analytics/get_last_events
Moved to dedicated analytics service.
POST /clove_dental/list_status
POST /clove_dental/update_status
POST /analytics/clove_dental/list_status
POST /analytics/clove_dental/update_status
Tenant path preserved for existing Clove clients.
POST /clove_dental/get_events_combined
POST /clove_dental/get_events_combined_counts
POST /analytics/clove_dental/get_events_combined
POST /analytics/get_events_combined
POST /analytics/clove_dental/get_events_combined_counts
POST /analytics/event_counts
Generic aliases (/get_events_combined, /event_counts) added for non-tenant callers.
POST /get_raw_snippets POST /analytics/get_raw_snippets
GET /get_image GET /analytics/get_image
POST /clove_dental/clove_trigger_events POST /jobs/clove_dental/clove_trigger_events
POST /jobs/start_trigger
Trigger flow moved to job_app; /start_trigger is the generic alias.

Job runner

appserverdash-appNotes
POST /live/start_job POST /jobs/start_job
POST /jobs/start_live_job
Both aliases behind one handler.
POST /live/stop_job POST /jobs/stop_job
POST /jobs/stop_live_jobs
GET /auth_callback GET /jobs/auth_callback Cognito OAuth callback stub kept, no Cognito integration behind it.

CIM / DIM / Monitor (appserver4 ↔ dash-app)

appserver4dash-appNotes
POST /event (cim)POST /cim/event/
POST /message (cim)POST /cim/message/
POST /cim/messages/
Batch variant added.
POST /event_callbackPOST /cim/event_callback/
POST /kit_callbackPOST /cim/kit_callback/
POST /publishPOST /cim/publish/
POST /upload_pluginPOST /cim/upload_pluginDIM's copy was dropped.
POST /gmail_testPOST /cim/gmail_test/
GET /echo/{thing}GET /cim/echo/{thing}, /monitor/echo/{thing}, plus /dmf/echo, /dim/echo, etc.
POST /system_event (monitor)POST /monitor/system_event/
POST /config/infra/system_event
Duplicate handler on config_app for legacy pushes.
WS /ws/notifications/{device} (dim)WS /dim/ws/notifications/{device}
WS /dmf/ws/notifications/{device}
DMF has its own notification channel too.

New in dash-app no appserver counterpart

Endpoints that didn't exist in appserver — either brand-new features or subsystems that appserver handled outside the HTTP layer (WMS, DMF, MLC config junction, service bundles).

Platform-admin: MLC config + service bundles

MethodPathPurpose
GET/config/infra/mlc_configList MLC tuning configs (predictdb creds, NMS, sampling).
POST/config/infra/mlc_configCreate MLC config row (platform-level, not tenant-scoped).
PATCH/config/infra/mlc_config/{id}Partial update.
DEL/config/infra/mlc_config/{id}
GET/config/infra/mlc_config/{id}/companiesList companies assigned to this config.
POST/config/infra/mlc_config/{id}/companiesAttach companies (junction row insert).
DEL/config/infra/mlc_config/{id}/companies/{company_id}Detach one company.
GET/config/infra/service_bundleList service bundles.
POST/config/infra/service_bundleCreate bundle.
DEL/config/infra/service_bundle/{id}
GET/config/infra/company_configTenant-wide key/value config.
POST/config/infra/company_configUpsert config keys.

App — parts & dynamic kits

MethodPathPurpose
GET/config/app/partList parts (SKU catalog).
POST/config/app/partCreate part.
DEL/config/app/part/{part_id}
POST/config/app/part_imageAttach reference image to a part.
GET/config/app/dynamic_kitList dynamic kits.
POST/config/app/dynamic_kitCreate kit + its part rows.
DEL/config/app/dynamic_kit/{kit_id}
POST/config/app/dynamic_kit_updateUpdate kit & recompute part list.

Ops additions

MethodPathPurpose
GET/config/ops/event_typeEvent-type catalog (public).

Jobs additions

MethodPathPurpose
DEL/jobs/v2/job/{request_id}Cancel a queued/running job.
GET/jobs/getjobslistJob history for the tenant.
POST/jobs/start_batch_jobKick off a bulk-processing job.
POST/jobs/stop_batch_job
POST/jobs/file_uploadDirect file upload endpoint.
POST/jobs/upload_snippet
POST/jobs/upload_thumbnail
GET / POST / DEL/jobs/dynamic_kit, /jobs/dynamic_kit_updateJob-side dynamic kit mgmt (mirror of /config/app/dynamic_kit).
POST/jobs/v2/add_benchmark_resultPost benchmark run outcome.
POST/jobs/call_back_serverGeneric callback receiver.

Analytics additions

MethodPathPurpose
POST/analytics/search_eventsFull-text / filter search across events.
GET / POST/analytics/event_notePer-event operator notes.
GET/analytics/v2/get_fileSigned-URL file fetch.

DMF — Data / Media Flow (entire service)

MethodPathPurpose
POST/dmf/capture_image, /dmf/capture_video, /dmf/mediaEnqueue capture on a camera.
GET/dmf/mediaList captured media for the tenant.
DEL/dmf/mediaBulk delete.
GET / POST/dmf/imagesImage roster / bulk register.
GET/dmf/image_detailPer-image predictions + metadata.
POST/dmf/image_comment, /dmf/kit_comment, /dmf/prediction_commentReviewer annotations.
GET/dmf/labelsLabel catalog.
GET/dmf/location, /dmf/part, /dmf/streamRead-only projections for the DMF UI.
POST/dmf/part, /dmf/part_imagePart write side (mirrors /config/app/part).
POST/dmf/loginStandalone DMF login for the labeling UI.
GET/dmf/job, /dmf/job_mediaJob-side inspection.
GET/dmf/cvat, /dmf/cvat_orgsCVAT project sync.
POST/dmf/cvat_uploadPush labeled data to CVAT.
GET/dmf/export, /dmf/export_doriDataset export (COCO / Dori format).

Warehouse service (entire service)

MethodPathPurpose
POST/warehouse/pallet_result/Ingest a pallet-scan result.
POST/warehouse/pallet_result/listQuery pallet results with filters.
POST/warehouse/pallet_result/{id}/ackAcknowledge a result.
GET/warehouse/dashboard/stats, /throughput, /suppliers, /docksWMS dashboard aggregations.

DIM additions

MethodPathPurpose
GET/dim/statsConnected-device stats for the DIM UI.

Dropped from appserver not migrated

Endpoints on appserver that have no counterpart in dash-app. Many were sunset when the subsystem was retired (Cognito auth, safety-index, ZoneMinder scaffolding); others were runtime-debug endpoints that never made the cut.

Cognito auth flow — replaced by local bcrypt/JWT

Methodappserver pathReason
POST/confirm_signupCognito-specific.
POST/confirm_loginCognito-specific.
POST/resend_confirmation_codeCognito-specific.
POST/forgot_passwordNot ported — internal password reset only.
POST/confirm_forgot_passwordSame.
GET/refresh_tokenJWT is short-lived; clients re-login.
GET/check_credentialsRolled into /login.

Safety-index / incident / alerts subsystem

Methodappserver pathReason
POST/list_safety_indexesSafety-index feature retired.
POST/list_incidentsIncident concept folded into generic events.
POST/update_incident
POST/get_incident_countsSuperseded by /analytics/event_counts.
POST/list_alertsAlerts UI dropped.
GET/incident
POST/get_tickets_countsTicketing not migrated.
POST/get_alerts_countsSuperseded by /analytics/event_counts.

Runtime debug / benchmark endpoints

Methodappserver pathReason
POST/raw_get_eventsDebug-only; no client depends on it.
POST/raw_get_events_summarySame.
POST/get_runtime_eventsMLC runtime moved to internal pub/sub.
POST/get_runtime_predictionsSame.
POST/benchmark_eventsPartly replaced by /jobs/v2/add_benchmark_result.
POST/get_event_snippetsReplaced by /analytics/get_raw_snippets.
POST/get_annotationsAnnotation store moved to DMF.
POST/get_file_imagesReplaced by /dmf/images.
GET/get_infoLegacy debug ping.
GET/get_documentationDocs no longer served from the API.

Camera / MLC config utilities

Methodappserver pathReason
POST/update_camera_configCamera config is now columns on device; updated via POST /config/ops/device.
GET/POST/mlc_camera_configSuperseded by the /config/infra/mlc_config junction API.
GET/POST/post_process_codePost-process code now shipped in service-bundle rows.
POST/dashboard_streamReplaced by WebSocket at /dim/ws/notifications/{device}.

Admin scaffolding — dropped subsystems

Methodappserver pathReason
GET/POST/DEL/admin/floormapFloormap UI feature dropped.
GET/POST/DEL/admin/vmsVMS integration dropped.
GET/POST/DEL/admin/monitorFolded into device (alembic 003).
GET/admin/zmmonitorslistZoneMinder integration removed.
GET/admin/mlclistRolled into GET /config/infra/mlc.
GET/admin/subscriptionslistRolled into GET /config/ops/subscriber.

Notes & methodology