●

SalarySafe API

checking…

The confidential pay-matching backend — the server-side counterpart of the browser demo's salarysafe_backend.js.

Endpoints

POST/api/roles— onboarding: upsert role + confidential band
POST/api/links— invite: mint a single-use candidate link
GET/api/links/{token}/config— candidate config (no band)
POST/api/match— salary-only match → within/above only
POST/api/events— behaviour telemetry (append-only)
GET/api/roles/{id}/results— employer: outcomes for a role
GET/api/links/{token}/invite— invite-email merge data
GET/api/links/{token}/result— result-email merge data

Point the browser front-ends here

The candidate flow works against this backend with no code change — set the two globals before its script loads:

<script>
  window.SALARYSAFE_MATCH_URL  = "http://localhost:8090/api/match";
  window.SALARYSAFE_EVENTS_URL = "http://localhost:8090/api/events";
</script>

Invite links carry the backend-generated ?t=token; the candidate's configuration is fetched from /api/links/{token}/config, not embedded via ?d=, so the band never reaches the browser. The employer app's invite/results calls become async fetchs to /api/links and /api/roles/{id}/results.

Money crosses the API in major units; the DB stores minor (band_*_minor). Benefits are keyed by code. Only the direction (within/above = matched/not_matched) is ever returned to either side.