Getting Started
Environments & Base URLs
Staging and production hosts, route families and headers.
Hosts
| Environment | API base URL |
|---|---|
| Staging | https://staging-api.panoptesos.com |
| Production | https://api.panoptesos.com |
Route families
Every route is versioned first and names its audience second: /api/v1/<area>.
| Family | Route | Credential | Envelope |
|---|---|---|---|
| Console | /api/v1/console/** | Console JWT, or an API key with the matching cap: scope | { success, data, message, code, errors } |
| Public | /api/v1/public/** | API key (X-Api-Key) | { ok, data } / { ok, error: { code, message } } |
| Guest | /api/v1/guest/** | None — the QR token in the path is the credential | { success, data, … } |
| MCP | /api/v1/mcp | API key or OAuth bearer | JSON-RPC over Streamable HTTP |
| Realtime | /api/v1/console/realtime | Console JWT (access_token query) | SignalR |
The vendor platform plane (/api/v1/platform/**) and the internal offline drain are not part
of the integrator API.
Common headers
| Header | When |
|---|---|
X-Api-Key: pnp_<env>_<8hex>.<secret> | Machine calls |
Authorization: Bearer <jwt> | Session calls from a dashboard you build |
Idempotency-Key: <uuid> | Required on POST /api/v1/public/orders and guest self-orders; recommended on every write that moves money or stock |
Content-Type: application/json | Any request with a body |
JSON fields are camelCase. Amounts are in the branch currency (IQD by default).