Dynamic backend
Backend API needed for real account and license sync.
Core endpoints
POST /api/auth/oauth/startstarts OAuth with signed state and PKCE.POST /api/auth/oauth/callbackcreates a secure HttpOnly session.POST /api/stripe/create-checkout-sessioncreates Checkout on the server.POST /api/stripe/webhookverifies Stripe signatures and creates licenses.POST /api/licenses/verifyreturns plan limits to Chrome.POST /api/extension/syncsaves profile, usage, questions, pages, Continue clicks, and confirmations.POST /api/notifications/subscribestores iPhone push consent.
Security rules
Keep Stripe keys, OAuth secrets, Gmail tokens, push private keys, and webhook secrets server-side only. The Chrome extension should send signed, minimal snapshots tied to the user license and installation id.