ADR-006: Hostnames and a same-origin API

Status: Accepted Date: 2026-10-10

Context

Schools get {org}.coipe.app. A separate API host would mean CORS for every school origin and a session cookie shared across .coipe.app. Cloudflare's free certificate covers only one subdomain level, and multi-level hosts need Advanced Certificate Manager (about $10/month).

Decision

  • Individuals and families use the apex, coipe.app. Schools use {org}.coipe.app.
  • Every app host serves the API same-origin at /api/*. Session cookies are host-only, so a login on one school's host is never sent to another's.
  • api.coipe.app is reserved for future mobile and partner clients.
  • Every hostname stays one level deep. Staging uses staging.coipe.app and {org}--staging.coipe.app.
  • Reserved slugs: www, api, admin, assets, staging, auth, docs, status, mail, help, and anything containing --.

Alternatives considered

  • app.coipe.app for individuals: an extra level with no benefit.
  • Path-based tenants (coipe.app/s/{org}): no subdomain to allowlist on school networks, and branding and cookie isolation are weaker.

Consequences

  • The edge must route /api/* on every app host to the API.
  • Deeper names wait for Advanced Certificate Manager.