Skip to content

Routing and limits

Versioned JSON endpoints live below:

https://3dreamstudio.com.br/api/v1

Authentication commands use /api/v1/auth; account resources use /api/v1/users; link resources use /api/v1/links. The older-looking /api/v1/login path does not exist and returns 404 ROUTE_NOT_FOUND.

Two browser-facing routes deliberately sit outside the API prefix:

  • GET /r/{code} returns a 302 redirect for a short code.
  • GET / and HEAD / return a 301 redirect to https://app.3dreamstudio.com.br/.

Send request bodies as UTF-8 JSON with Content-Type: application/json. The server rejects malformed JSON with 422 INVALID_FORM_BODY and unsupported body media types with 415 UNSUPPORTED_MEDIA_TYPE.

The global request-body limit is 65,536 bytes (64 KiB). An oversized body returns 413 REQUEST_BODY_TOO_LARGE before an endpoint processes it.

Limit Value
Links per account 50
URL size 4096 UTF-8 bytes
Short-code length 8 Base62 characters
Password length on registration 8–128 Unicode characters
Username length 2–32 ASCII characters
Display-name length 2–32 Unicode characters

POST /api/v1/users and POST /api/v1/auth/login share a rate limit for each client IP address:

  • sustained rate: 5 requests per second;
  • burst: 5 requests; and
  • unused rate-limit state may reset over time.

Responses from those two routes include X-RateLimit-Limit and X-RateLimit-Remaining. A denied request also includes Retry-After and returns 429 RATE_LIMIT_EXCEEDED.

Rate-limit headers describe the request’s observed limit state. Clients must honor 429 and Retry-After instead of treating the reported remainder as a reserved quota.

Every response includes X-Request-Id. If the request supplies that header, the service reuses it; otherwise it generates a 32-character value. Record the ID when troubleshooting a failed request.

The service allows browser requests from any origin and permits requested preflight headers such as Authorization and Content-Type. Credentialed CORS is disabled: browsers do not send cookies or HTTP credentials to this API.

The permissive origin policy is compatible with bearer headers but does not make a token public. Applications remain responsible for protecting tokens.