# ART CAR — API v1.1
Base: `https://art.codeone.site/api/api.php?action=<ACTION>`  (HTTPS)

Bearer token returned by `POST login`; auth and admin-only permission checks are enforced by PHP.

## Trip creation / update (admin only)
`POST trip_save` accepts:
`{id?:integer,employee_id:integer,title:string,description?:string,scheduled_at?:"YYYY-MM-DD HH:mm:ss" (UTC),start_label?,end_label?,start_lat?,start_lng?,end_lat?,end_lng?,charge_amount?:"150.00",payment_method:"cash"|"visa"|"visa_prepaid"|"none"}`.
- Update allowed only if trip is `assigned`.
- `cash` and `visa` require >0 EGP amount.
- `visa_prepaid` is admin-declared prepaid; requires no driver collection confirmation. No payment-provider integration.
- `none` requires zero amount.

## Trip completion (assigned employee only)
`POST trip_status` with `{id,status:"completed",collected:true|false,collection_note?:string}` for cash/visa.
The server derives amount from the trip; client cannot submit arbitrary collected amount. Zero/no-collection trips can omit the Boolean. Completion and audit insert are atomic under a transaction.

## Finance (admin only)
`GET finance_report&from=2026-10-01&to=2026-10-31&employee_id=&method=all&collection_status=all`
Returns totals (`expected_egp`, `collected_egp`, `uncollected_egp`, `pending_egp`, `visa_prepaid_egp`), per-employee subtotals, and per-trip rows (max 5000; over-limit is rejected).
`POST finance_adjust` `{id,collection_status:"collected"|"uncollected",reason:"سبب واضح للتعديل"}` only completed chargeable trips.
`GET finance_audit&id=<TRIP>` returns immutable history for admins.
All financial data is in EGP.

## Other APIs
`GET` me, dashboard, employees, vehicles, trips, shift, live, location_history, reports, notifications
`POST` login, logout, employee_save, vehicle_save, trip_save, trip_status, trip_location, shift_start, shift_end, shift_heartbeat, location_ping, notification_read, notification_send, device_register
No data is pre-populated; credentials created with install.php.
