API reference
Authentication, sync, and the HTTP endpoints Rondo's apps use.
Everything is on https://rondo.matthewsource.com: /api and /media (accounts, sharing, Discover, media, billing), and /sync (decks, notes and progress). These pages are generated from the OpenAPI contract, which the servers' code is generated from too.
Making an assistant integration?
Use the MCP server for reading and editing decks through an assistant.
Authentication
Sign-in is Ory Kratos's API flows, at https://rondo.matthewsource.com/auth. They end with a session token, which every request sends as a bearer token, with the protocol version:
curl https://rondo.matthewsource.com/api/me \
-H "Authorization: Bearer $RONDO_SESSION_TOKEN" \
-H "Rondo-Protocol: 1"A client the server no longer supports gets 426 with client_outdated.
Decks, notes and progress
Each device keeps its own copy and syncs rows, not objects: there are no per-deck or per-note endpoints. Rows carry a clock v; the newest version of a row wins. Progress is a log of events (reviews, suspensions, flags, …), never overwritten.