# Live platform status — mcp.loyaly.ai Probed 2026-09-09. `LOYALY_API_BASE=https://mcp.loyaly.ai` The host is confirmed as the Behavision platform: it answers the documented flat `{"error": "...", "message": "..."}` contract with the documented codes (`bad_credentials`, `unauthorized`, `not_found`, `bad_request`). **8 of the 16 endpoints the spec documents are not deployed yet.** A `401 unauthorized` proves the route exists and is gated. A `404 {"error":"not_found","message":"No such endpoint."}` means it is absent. ## Live | Endpoint | Probe | Console feature | |---|---|---| | `POST /api/auth/login` | 401 `bad_credentials` | Sign in — **wired** | | `POST /api/auth/refresh` | 400 `refresh_token is required` | Token rotation — **wired** | | `POST /api/auth/logout` | 401 `unauthorized` | Sign out — **wired** | | `GET /api/auth/me` | 401 `unauthorized` | Session confirmation — **wired** | | `GET /api/sites` | 401 `unauthorized` | Site switcher + Store page — **wired** | | `GET /api/visitors` | 401 `unauthorized` | Customer directory — service written, UI not built | | `GET /api/reports/footfall` | 401 `unauthorized` | Visitors KPI + Footfall chart — **wired** | | `GET /api/reports/conversion` | 401 `unauthorized` | Purchases/Revenue/Conversion + Sales — **wired** | ## Not deployed | Endpoint | Probe | Blocks | |---|---|---| | `GET /api/visits` | 404 | **Recent arrivals feed, Activity page** | | `POST /api/purchases` | 404 | **Mobile → dashboard purchase flow** | | `GET /api/team` | 404 | Leaderboard team table | | `GET /api/team/invitations` | 404 | Invite flow | | `GET /api/auth/invitation` | 404 | Join preview | | `POST /api/auth/register` | 404 | Redeeming an invitation | | `GET /api/auth/sessions` | 404 | Device management | | `GET /api/cameras` | 404 | Camera list / live view | ## Consequence for the "most important requirement" The brief's §7 flow — ``` Mobile → POST /api/visits → DB → Dashboard GET /api/visits → new visit appears Mobile → POST /api/purchases → DB → reports update ``` — cannot run today. **Neither `/api/visits` nor `/api/purchases` is deployed.** The console side is built and pointed at both; they return 404 until the platform ships them. What *does* work end to end once there is an account: sign in, site switching, and every KPI and chart on the Dashboard and Sales pages, since those read the two report endpoints that are live. ## Still needed A valid account on `mcp.loyaly.ai`. There is no open registration by design, and `POST /api/auth/register` is not deployed either — so an account has to be created directly on the platform side.