App serves at http://localhost:3000. `VITE_USE_MOCKS=true` is the default data path until AP-15 wires live API calls.
### API + data plane (AP-14)
```bash
docker compose up -d
cp .env.example .env
npm run db:migrate
npm run db:seed
npm run dev:api
```
API listens on http://127.0.0.1:8787. Vite proxies `/api` to that port.
Smoke:
```bash
curl -s http://127.0.0.1:8787/health
curl -s http://127.0.0.1:8787/api/me
```
`DEV_AUTH_BYPASS=true` is local-only and only allowed when `NODE_ENV` is `development` or `test` (rejected for production, staging, preview, and any other value).
API roles (source of truth): `admin`, `ap_processor`, `approver`, `viewer`. Frontend mocks still use `ap_operator` until AP-15 remaps them.
### OpenAPI / Redocly
Linting uses the same `redocly.yaml` ruleset as `procurement-ingest`.
```bash
npm run lint:api
npm run docs:preview # builds HTML via redocly build-docs and opens it