API
the web client is just the first API consumer
IdlePiracy is built API-first. There's no separate "official" client with private access to anything — the web client talks to the exact same public REST API that anyone can call, the same way Torn and Screeps treat automation: a supported way to play.
Every account gets its own API key under Settings → API. Full market order-book data is exposed through the API on purpose — public data makes the trading game deeper and gives the community room to build tooling around it.
v0.1 — read endpoints
GET /api/v1/character # gold, location, ship, current voyage/action
GET /api/v1/character/inventory # hold + sea chest
GET /api/v1/character/officers # assigned + reserve, effective bonuses
GET /api/v1/character/tutorial # the Harbormaster's Ledger
GET /api/v1/world/ports # static world data + routes
GET /api/v1/world/ships # the six hull tiers
GET /api/v1/world/enemies # hunt-focus tiers
GET /api/v1/ports/{port}/trader # NPC buy/sell prices + daily stock
GET /api/v1/taverns/{port} # today's officer offers
GET /api/v1/world/feed # public world-first events
GET /api/v1/logbook?since=...
There's no skill sheet to read any more — GET /character returns your gold, location,
ship, and current action, not a table of levels. Progression lives in your ship tier, your standing
at each port (folded into the trader/tavern reads above), and your officers.
v0.1 ships read-only. A v0.2 write surface is planned for after auth hardening:
POST /actions (commit a voyage plan or a Shipwright batch), POST /market/list|buy,
and the trader/tavern/shipyard writes — the same actions the web client performs, just callable
directly.
Rate limits
Free accounts get 60 requests/minute (current design value). Higher tiers are a planned membership perk later — the same Screeps-style monetization lane where automation capacity itself is the thing worth paying for, never an in-game power advantage.
Botting is legal, one account is the rule
Playing IdlePiracy by bot, with your own API key, is legal and documented. We'd rather you did it well than quietly. The only rule is one account per player. Automation players are treated as the subscriber core. See Fairness for how the one-account rule is enforced in practice.
Publishing the spec
An OpenAPI spec will be published alongside the API itself. Community tools built against it are free marketing — the more captains build their own dashboards, alert bots, and market trackers, the better for everyone.