> ## Documentation Index
> Fetch the complete documentation index at: https://docs.vellaro.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Public Draft Preview

> Storefront LIVE-PREVIEW read (F2): return a page's DRAFT block-tree — the
unpublished, in-progress version — gated ONLY by a signed preview token.

No auth header: the token IS the credential. Two INDEPENDENT authorities
guard it, so forgetting one still can't leak another tenant's draft:

  1. the signed token — bad signature / expiry / wrong type → 403; its
     ``tenant_id`` must equal the host-resolved tenant (anti-replay across
     stores) and its ``slug`` must equal the path;
  2. Postgres RLS — the tenant GUC is set from the resolved tenant, so
     ``_load_page`` physically cannot see another tenant's page row.

Serves the OPEN draft when present, else falls back to the PUBLISHED version
(right after a publish the draft is promoted to published, leaving no open
draft — the composer iframe must still show the page); 404 only when neither
exists. Response is marked ``no-store`` so it never lands in a shared/CDN
cache. Publishes nothing, mutates nothing.



## OpenAPI

````yaml https://api.vellaro.io/openapi.json get /api/v1/cms/pages/{slug}/draft-preview
openapi: 3.1.0
info:
  title: Vellaro API
  description: Vellaro 2026 — E-commerce API
  version: 0.1.0
servers:
  - url: https://api.vellaro.io
    description: Produzione
security: []
tags: []
paths:
  /api/v1/cms/pages/{slug}/draft-preview:
    get:
      tags:
        - cms-pages
      summary: Public Draft Preview
      description: >-
        Storefront LIVE-PREVIEW read (F2): return a page's DRAFT block-tree —
        the

        unpublished, in-progress version — gated ONLY by a signed preview token.


        No auth header: the token IS the credential. Two INDEPENDENT authorities

        guard it, so forgetting one still can't leak another tenant's draft:

          1. the signed token — bad signature / expiry / wrong type → 403; its
             ``tenant_id`` must equal the host-resolved tenant (anti-replay across
             stores) and its ``slug`` must equal the path;
          2. Postgres RLS — the tenant GUC is set from the resolved tenant, so
             ``_load_page`` physically cannot see another tenant's page row.

        Serves the OPEN draft when present, else falls back to the PUBLISHED
        version

        (right after a publish the draft is promoted to published, leaving no
        open

        draft — the composer iframe must still show the page); 404 only when
        neither

        exists. Response is marked ``no-store`` so it never lands in a
        shared/CDN

        cache. Publishes nothing, mutates nothing.
      operationId: public_draft_preview_api_v1_cms_pages__slug__draft_preview_get
      parameters:
        - name: slug
          in: path
          required: true
          schema:
            type: string
            title: Slug
        - name: token
          in: query
          required: true
          schema:
            type: string
            title: Token
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiResponse_CmsPageViewerOut_'
        '422':
          description: Validation Error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HTTPValidationError'
components:
  schemas:
    ApiResponse_CmsPageViewerOut_:
      properties:
        data:
          anyOf:
            - $ref: '#/components/schemas/CmsPageViewerOut'
            - type: 'null'
        meta:
          anyOf:
            - $ref: '#/components/schemas/PaginationMeta'
            - type: 'null'
        error:
          anyOf:
            - type: string
            - type: 'null'
          title: Error
        error_code:
          anyOf:
            - type: string
            - type: 'null'
          title: Error Code
      type: object
      title: ApiResponse[CmsPageViewerOut]
    HTTPValidationError:
      properties:
        detail:
          items:
            $ref: '#/components/schemas/ValidationError'
          type: array
          title: Detail
      type: object
      title: HTTPValidationError
    CmsPageViewerOut:
      properties:
        slug:
          type: string
          title: Slug
        page_type:
          type: string
          title: Page Type
        title_i18n:
          anyOf:
            - additionalProperties: true
              type: object
            - type: 'null'
          title: Title I18N
        meta_title_i18n:
          anyOf:
            - additionalProperties: true
              type: object
            - type: 'null'
          title: Meta Title I18N
        meta_description_i18n:
          anyOf:
            - additionalProperties: true
              type: object
            - type: 'null'
          title: Meta Description I18N
        version_no:
          type: integer
          title: Version No
        blocks:
          items:
            additionalProperties: true
            type: object
          type: array
          title: Blocks
      type: object
      required:
        - slug
        - page_type
        - title_i18n
        - meta_title_i18n
        - meta_description_i18n
        - version_no
        - blocks
      title: CmsPageViewerOut
      description: >-
        Public (storefront) view — the published block-tree + SEO metadata.


        Reused verbatim by the draft-preview endpoint (F2): same envelope, but
        the

        ``blocks``/``version_no`` come from the DRAFT version instead of the

        published one, so the composer iframe renders exactly what publishing
        would.
    PaginationMeta:
      properties:
        page:
          type: integer
          title: Page
        page_size:
          type: integer
          title: Page Size
        total:
          type: integer
          title: Total
        total_pages:
          type: integer
          title: Total Pages
      type: object
      required:
        - page
        - page_size
        - total
        - total_pages
      title: PaginationMeta
    ValidationError:
      properties:
        loc:
          items:
            anyOf:
              - type: string
              - type: integer
          type: array
          title: Location
        msg:
          type: string
          title: Message
        type:
          type: string
          title: Error Type
        input:
          title: Input
        ctx:
          type: object
          title: Context
      type: object
      required:
        - loc
        - msg
        - type
      title: ValidationError

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.