Danvas
Danvas
DashboardSupportWelcome

👤 USER DOCS

User Guides

Getting Started

Getting StartedDashboard & OnboardingApp Settings

Tutorials

Tutorial: Setting Up Shift Tasks & ClosersTutorial: Managing Incidents in the InboxTutorial: Tracking Compliance & Sync StatusTutorial: Operational Workflows with the AI AssistantTutorial: Building & Deploying Custom Checklists

Daily Operations (Staff)

Shift Workspace & TasksService Day SetupDaily Line-UpStaff Service Day ReportsForms

Communication & Chat

Messages & AnnouncementsUnified Operations InboxAI Assistant

Manager & Admin Guides

Daily Line-Up SetupStaff SchedulingManaging LocationsNPS and Guest FeedbackCouponsContacts and Guest HistoryManager CloseoutsDaily Line-Up & ComplianceAnalyticsIncident ReportingWhistleblower Concerns & FeedbackAdmin Tools

⚙️ DEVELOPER DOCS

Getting Started

Getting StartedDevelopmentDeployment Guide

Architecture

Architecture OverviewExplanation: AI Integration & Tenant SecurityExplanation: Dynamic Forms Engine DesignExplanation: Compliance Ledger DesignExplanation: Live Sync & Data FreshnessData FlowArchitecture Decision Records

Core Domain

Core DomainDatabase ReferenceLocations DomainAuth & RBACScheduling DomainReports DomainIncidents DomainUnified Operations InboxLive Sync Data FreshnessToast Sync PipelineNotifications DomainCoupons and Guest NPSAudit Log & Compliance ArchitectureDesign Audit FindingsAI Chat IntegrationAnalytics & Tips Integration

Frontend

Frontend ArchitectureFormsLoading SkeletonsComponentsPWA & Offline ShellScreenshots

API Reference

API Reference

Endpoints

POS Sales APIOptimization Data APISchedule Shifts APIEmployee Export APIReports APIIncidents APIAI Chat APIPush Notifications APIWebhooks APICron API

Contributing

ContributingCode Examples

Security

Security & Compliance

Release Notes

What's New

Cron API

Internal endpoints for scheduled operational tasks

The Cron API consists of headless endpoints triggered by Vercel Cron on a scheduled basis. These endpoints handle background tasks such as compliance monitoring, report reminders, announcement publication, data synchronization, contact retention, and coupon expiration.

GET
/cron/keep-alive

Response Body

OK

response?stringtext/plain
curl -X GET "https://example.com/cron/keep-alive"
"OK"
GET
/cron/report-reminder

Authorization

cronSecret
headerAuthorizationBearer <token>

CRON_SECRET environment variable

Response Body

Cron job completed

response?stringtext/plain
curl -X GET "https://example.com/cron/report-reminder"
"OK — 3 reminders sent"
GET
/cron/check-compliance

Authorization

cronSecret
headerAuthorizationBearer <token>

CRON_SECRET environment variable

Response Body

Cron job completed

response?stringtext/plain
curl -X GET "https://example.com/cron/check-compliance"
"OK — nudged 5 staff, 2 managers"
GET
/cron/aggregate-heroes

Authorization

cronSecret
headerAuthorizationBearer <token>

CRON_SECRET environment variable

Response Body

Cron job completed

response?stringtext/plain
curl -X GET "https://example.com/cron/aggregate-heroes"
"OK — MVP messages created for: John Doe"
GET
/cron/publish-scheduled-announcements

Authorization

cronSecret
headerAuthorizationBearer <token>

CRON_SECRET environment variable

Response Body

Cron job completed

curl -X GET "https://example.com/cron/publish-scheduled-announcements"
Empty
GET
/cron/prune-soft-deleted-contacts

Authorization

cronSecret
headerAuthorizationBearer <token>

CRON_SECRET environment variable

Response Body

Cron job completed

curl -X GET "https://example.com/cron/prune-soft-deleted-contacts"
Empty
GET
/cron/sync-schedule-from-7shifts

Authorization

cronSecret
headerAuthorizationBearer <token>

CRON_SECRET environment variable

Response Body

Cron job completed

curl -X GET "https://example.com/cron/sync-schedule-from-7shifts"
Empty
GET
/cron/sync-7shifts-roles

Authorization

cronSecret
headerAuthorizationBearer <token>

CRON_SECRET environment variable

Response Body

Cron job completed

curl -X GET "https://example.com/cron/sync-7shifts-roles"
Empty
GET
/cron/expire-coupons

Authorization

cronSecret
headerAuthorizationBearer <token>

CRON_SECRET environment variable

Response Body

Cron job completed

curl -X GET "https://example.com/cron/expire-coupons"
Empty

Security

Endpoints are protected by a shared secret passed in the Authorization: Bearer <CRON_SECRET> header. The keep-alive endpoint is public but performs no sensitive operations.

Configured Vercel schedules

Schedules are defined in apps/api/vercel.json. All configured jobs except /cron/keep-alive require cron authentication.

RouteSchedule (UTC)Purpose
/cron/keep-alive0 1 * * *Keep the database connection warm
/cron/report-reminder0 20 * * *Remind about unfiled reports
/cron/check-compliance0 14 * * 1Check weekly filing compliance
/cron/aggregate-heroes0 14 * * 1Aggregate Hero of the Shift mentions
/cron/publish-scheduled-announcements*/5 * * * *Publish due announcements
/cron/prune-soft-deleted-contacts30 8 * * *Prune expired soft-deleted contacts
/cron/sync-schedule-from-7shifts0 */6 * * *Refresh the 7shifts schedule read model
/cron/sync-7shifts-roles0 */4 * * *Refresh 7shifts role mappings
/cron/expire-coupons* * * * *Release due coupon reservations and check expiry health

For tip mart backfill across a date range, use the CLI documented in Analytics & Tips Integration.

Coupon expiry health

GET /cron/expire-coupons uses the shared authenticated cron handler. Its schedule is owned by apps/api/vercel.json. The database owns expiry and reserved capacity; Vercel Cron only schedules work. The sweep claims bounded batches (currently 100) and atomically transitions due active reservations, releases their held capacity, and accepts stable expiry events. Repeated delivery cannot release the same capacity twice. Lazy expiry on supported guest resume/transition paths remains part of the lifecycle.

The sweep stays disabled until complete retry readiness is admitted. Its disabled HTTP 200 response explicitly says status: "disabled"; this is not evidence that expiry ran or that admission flags may be enabled.

Completed runs record privacy-safe correlation, duration, expired/ignored counts, accepted/duplicate event counts, reconciliation delta, and oldest expiry lag. A nonzero reconciliation delta or lag above the current 120-second health bound records diagnostics before raising the failed health gate. Investigate the safe run/correlation evidence rather than editing campaign counters. Existing cron run history and logs provide execution evidence. Immutable scheduled-run events remain disabled by the shared admission gate pending ADR-0102 privacy approval; their schema alone does not prove that a run was recorded.

Expiry notifications use the durable guest-event and notification queue contracts; provider failures do not reverse committed reservation transitions. No raw Contact values, private links, cookies, or staff proof belong in these diagnostics.

See Coupons and Guest NPS and the Coupon/NPS rollout runbook for schema, admission, no-op, and rollout evidence. The completed 2026-10-07 reliability release does not automatically enable expiry/retry for every team.

Related

Analytics & Tips Integration

Architecture Overview

Compliance Domain

API Overview

Webhooks API

Lifecycle event handlers for Clerk and Svix

Contributing

Guidelines for contributing to the Danvas platform

On this page

SecurityConfigured Vercel schedulesCoupon expiry healthRelated