The API behind Flyby AI — authentication, trips, expenses, conversations, travel policy and search. Built on Flask and SQLite, serving the React app on port 8080 from port 8659.
Everything the frontend calls, grouped by what it does.
Sign-up, sign-in, token refresh and password recovery. One account works in both the app and this console.
POST /auth/v1/signupPOST /auth/v1/token password & refresh grantsGET /auth/v1/userPOST /auth/v1/recoverOne query layer over every table. Each request is scoped to the signed-in user server-side.
POST /rest/v1/<table>/selectPOST /rest/v1/<table>/insertPOST /rest/v1/<table>/updatePOST /rest/v1/rpc/<name>Trips, expenses, conversations, notifications, itineraries and traveler preferences.
GET|PUT /api/tripsGET|PUT /api/expensesGET|PUT /api/chatsGET|PUT /api/preferencesTwo-step verification, travel inventory search, and voice transcription.
GET /functions/v1/search-travelPOST /functions/v1/twofa-send-smsPOST /functions/v1/twofa-verify-smsPOST /functions/v1/transcribeAvatars and receipts. Uploads land in the uploader's own folder, enforced from the session.
POST /storage/v1/object/<bucket>/<key>GET /storage/v1/object/public/…DELETE /storage/v1/object/<bucket>Health checks and the account console for administrators.
GET /health service + databaseGET /api/healthGET /users/table admin onlypython main.py and the
frontend with make from the flyby folder, then open
http://localhost:8080. The seeded accounts are
admin@flyby.ai and demo@flyby.ai — the password comes from
DEFAULT_PASSWORD in the backend .env.