ADR-006: Hostnames and a same-origin API
Status: Accepted Date: 2026-10-10
Context
Schools get {org}.coipe.app. A separate API host would mean CORS for every school origin and a session cookie shared across .coipe.app. Cloudflare's free certificate covers only one subdomain level, and multi-level hosts need Advanced Certificate Manager (about $10/month).
Decision
- Individuals and families use the apex,
coipe.app. Schools use{org}.coipe.app. - Every app host serves the API same-origin at
/api/*. Session cookies are host-only, so a login on one school's host is never sent to another's. api.coipe.appis reserved for future mobile and partner clients.- Every hostname stays one level deep. Staging uses
staging.coipe.appand{org}--staging.coipe.app. - Reserved slugs:
www,api,admin,assets,staging,auth,docs,status,mail,help, and anything containing--.
Alternatives considered
app.coipe.appfor individuals: an extra level with no benefit.- Path-based tenants (
coipe.app/s/{org}): no subdomain to allowlist on school networks, and branding and cookie isolation are weaker.
Consequences
- The edge must route
/api/*on every app host to the API. - Deeper names wait for Advanced Certificate Manager.