# thechat.online — Feature implementation report

## Included in this source package

The base project already includes account/session management, AI provider/model registry, server-side plan and quota gates, subscription plans, PayPal and crypto-provider payment routes, admin APIs, security events/audit logs, support tickets, notifications, usage analytics, and client-side Markdown/JSON conversation export.

This update adds:

- Developer API key management in Dashboard → Developer API (create/list/revoke, maximum five active keys, one-time secret display).
- Hashed API key storage; the plaintext secret is never stored in MySQL.
- `POST /api/v1/chat`, a non-streaming OpenAI-compatible chat completion endpoint that uses the same plan/model/rate/spend checks as the web chat and records successful usage.
- Authenticated server-side conversation export at `GET /api/conversations/{id}/export?format=md|txt`.
- cPanel checks for MySQL/MariaDB `DATABASE_URL`, production secret length, Node.js version, standalone build, and the developer-key schema.
- Deployment documentation for the new endpoints and schema update.

## Required external setup

AI providers, PayPal, crypto-payment provider, SMTP/email, and OAuth features require the corresponding real credentials and provider-side webhook configuration. These integrations must be tested in sandbox mode before accepting real payments.

## Deployment notes

1. Back up the production database.
2. Upload/extract this package outside `public_html` where possible.
3. Configure Node.js 22 and environment variables in cPanel.
4. Run `npm install`, `npx prisma generate`, `npx prisma db push`, `npm run db:seed`, and `npm run build`.
5. Run `npm run cpanel:check` and verify `/api/health`.
6. Test registration/login, model access, quota limits, key creation/revocation, API completion, conversation export, admin authorization, and payment webhooks.

A full production build could not be run in the preparation environment because project dependencies are not installed there. Do not consider the deployment verified until the steps above pass on the target host.
