

# Authentication and deployment assumptions [#authentication-and-deployment-assumptions]

Use this page before wiring a public client to the HTTP API. It records the
current deployment assumptions without turning them into a field-level endpoint
reference.

## Current assumptions [#current-assumptions]

The API app is `apps/api`. It serves the reusable HTTP contract from
`@taxkit/api-http`. The standalone process uses `127.0.0.1:4000` by default;
the native local API and website pair has addresses supplied by its launcher.

There is no public authentication contract in this documentation slice. Treat
authentication, tenant routing and public hosting as application-owned until a
future API deployment spec defines them.

## Local routes [#local-routes]

For the native API and website pair, run `bun run dev` from the repository
root. The launcher prints both local addresses. See the
[API app README](https://github.com/crcorbett/taxkit/blob/a151e51e8a30247526fa93412df046955846eca4/apps/api/README.md) for this route and its build
requirements.

For the retained standalone API process, use:

```sh
bun run --filter=api start
curl http://127.0.0.1:4000/api/health
curl http://127.0.0.1:4000/api/docs/openapi.json
```

To run that standalone process through Portless, use:

```sh
bun run --filter=api dev
curl https://api.taxkit.localhost/api/health
```

## Caller responsibilities [#caller-responsibilities]

* Send `content-type: application/json` for calculate requests.
* Pass canonical calculator facts in the request body.
* Keep application authentication outside the calculator payload.
* Read endpoint fields from the generated [OpenAPI reference](/api/openapi-reference).
* Handle `CalculatorApiErrorEnvelope` for expected calculator service errors.

## Related pages [#related-pages]

* [API overview](/api/overview)
* [Endpoints](/api/endpoints)
* [Errors](/api/errors)
