# Panoptes API — Full Developer Reference (for LLMs) > Panoptes is a production-based restaurant operating system for Iraq. Its API lets a restaurant owner or their developer reach every action a user can take — POS, KDS, menu and catalog, inventory and production, purchasing, delivery channels, cash and loss control, accounting, HR and payroll, reports — plus webhooks for every audited change and an MCP server for AI agents. This single file is meant to be given to an AI assistant so it can help you integrate with the Panoptes API. It contains the integration basics, every guide, and the full endpoint catalogue. The machine-readable OpenAPI spec is at https://docs.panoptesos.com/panoptes-openapi.json. ## Integration basics - Production base URL: https://api.panoptesos.com - Staging base URL: https://staging-api.panoptesos.com - All routes are versioned under `/api/v1`. - Machine auth: send header `X-Api-Key: pnp__<8hex>.`. Console routes accept it when the key holds the matching `cap:` scope. - Session auth (a dashboard you build): send header `Authorization: Bearer `. - Console routes answer `{ success, data, message, code, errors }`; the public API answers `{ ok, data }` / `{ ok, error: { code, message } }`. `code` is the HTTP status number. - Request and response JSON fields are camelCase. - Amounts are in the branch currency (IQD by default). Writes that move money or stock take an `Idempotency-Key` header. ### Quick start 1. Sign in to the Panoptes dashboard as an owner and create an API key (Developers → API keys). 2. Pick an environment — use staging first, then production. 3. Call an endpoint with your key, for example: ```bash curl -s "https://staging-api.panoptesos.com/api/v1/public/orders" \ -H "X-Api-Key: YOUR_API_KEY" ``` Scopes: every capability has a scope `cap:`, plus presets (`preset:full`, `preset:read_only`, one per module). Effective permission is the owner role AND the key scopes. A call returns 403 if either is missing. --- # Guides ## Getting Started _Create an API key and make your first Panoptes API call._ Panoptes is a production-based restaurant operating system. Its API reaches every action a user can take in the dashboard — POS, kitchen display, menu and catalog, inventory and production, purchasing, delivery channels, cash and loss control, accounting, HR and payroll, and reports — and tells you about every change through signed webhooks. ## 1. Create an API key 1. Sign in to the Panoptes dashboard as an owner (or a user with `manage_api_keys`). 2. Open **Developers → API keys** and choose **New key**. 3. Pick the scopes the integration needs. Prefer a module preset (`preset:pos`, `preset:inventory`, …) over `preset:full`. 4. Copy the key. It looks like `pnp_live_1a2b3c4d.` and is shown **once**. ## 2. Pick an environment | Environment | Base URL | | -------------- | ------------------------------------ | | **Staging** | `https://staging-api.panoptesos.com` | | **Production** | `https://api.panoptesos.com` | Build and test against staging first. Keys are per install — a staging key does not work in production. ## 3. Make a call ```bash curl -s "https://staging-api.panoptesos.com/api/v1/public/items?limit=10" \ -H "X-Api-Key: pnp_test_1a2b3c4d.YOUR_SECRET" ``` ```json { "ok": true, "data": [{ "id": "…", "name": "Chicken shawarma", "price": 4500 }], "total": 42 } ``` ## 4. Go further - **Console routes** (`/api/v1/console/**`) are the full API. A key calls any of them when it holds the matching `cap:` scope — see [Permissions & Scopes](/docs/scopes/). - **Webhooks** push every audited change to your endpoint — see [Webhooks](/docs/webhooks/). - **MCP** lets an AI agent read facts and perform actions — see [MCP / AI Agents](/docs/mcp/). - Use the **Try it** console on any endpoint in the [API Reference](/api-reference/), or import the [Postman collection](/postman/). --- ## Environments & Base URLs _Staging and production hosts, route families and headers._ ## Hosts | Environment | API base URL | | -------------- | ------------------------------------ | | **Staging** | `https://staging-api.panoptesos.com` | | **Production** | `https://api.panoptesos.com` | ## Route families Every route is versioned first and names its audience second: `/api/v1/`. | Family | Route | Credential | Envelope | | -------- | -------------------------- | --------------------------------------------------------- | --------------------------------------------------- | | Console | `/api/v1/console/**` | Console JWT, or an API key with the matching `cap:` scope | `{ success, data, message, code, errors }` | | Public | `/api/v1/public/**` | API key (`X-Api-Key`) | `{ ok, data }` / `{ ok, error: { code, message } }` | | Guest | `/api/v1/guest/**` | None — the QR token in the path is the credential | `{ success, data, … }` | | MCP | `/api/v1/mcp` | API key or OAuth bearer | JSON-RPC over Streamable HTTP | | Realtime | `/api/v1/console/realtime` | Console JWT (`access_token` query) | SignalR | The vendor platform plane (`/api/v1/platform/**`) and the internal offline drain are not part of the integrator API. ## Common headers | Header | When | | -------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | | `X-Api-Key: pnp__<8hex>.` | Machine calls | | `Authorization: Bearer ` | Session calls from a dashboard you build | | `Idempotency-Key: ` | Required on `POST /api/v1/public/orders` and guest self-orders; recommended on every write that moves money or stock | | `Content-Type: application/json` | Any request with a body | JSON fields are camelCase. Amounts are in the branch currency (IQD by default). --- ## API Key Authentication _Mint API keys and authenticate machine-to-machine calls._ ## Key format ``` pnp__<8 hex>. ``` - The **prefix** (`pnp_live_1a2b3c4d`) identifies the key. It is safe to log and is shown in the dashboard list. - The **secret** (32 bytes, base64url) is shown exactly once, in the creation response. Store it in a secret manager. - `live` or `test` is part of the prefix, so a pasted key tells you which install it belongs to. ## Sending the key ```bash curl "https://staging-api.panoptesos.com/api/v1/public/orders" \ -H "X-Api-Key: pnp_test_1a2b3c4d.YOUR_SECRET" ``` ## What a key can do Effective permission is **the owner's role capabilities AND the key's scopes**. A key never exceeds the person who minted it. See [Permissions & Scopes](/docs/scopes/). Three kinds of action stay closed to machines, whatever the scopes: - sign-in and every auth flow, and resetting another user's password; - minting API keys, OAuth clients and connector keys (so a leaked key cannot copy itself); - the vendor platform plane. ## Key controls Each key can carry a per-minute rate limit, a quota, an IP allow-list and an origin allow-list. A refusal answers `429` with a `Retry-After` header. ## Session tokens (JWT) A dashboard you build signs a user in through `/api/v1/console/auth/*` and sends `Authorization: Bearer `. Access tokens are short-lived; refresh tokens are single-use and rotate on every refresh. ## OAuth (AI connectors) AI clients connect through the OAuth 2.0 issuer at `/api/v1/public/oauth/**` with dynamic client registration. The user consents to each scope, one box at a time. An OAuth bearer is accepted on `/api/v1/mcp` only. --- ## Permissions & Scopes _One scope per capability, presets, and the legacy aliases._ ## One scope per capability Every capability `c` in Panoptes has a scope `cap:c` — for example `cap:create_sale`, `cap:manage_inventory_items`, `cap:view_reports`. A key calls a console action when it holds a `cap:` scope for a capability that action's gate accepts. | Module | Example capabilities | | ---------- | -------------------------------------------------------------------------------------------------- | | pos | `create_sale`, `update_order_status`, `cancel_order`, `void_line`, `refund_order`, `manage_tables` | | catalog | `edit_price`, `edit_recipe`, `manage_promotion`, `manage_brands` | | inventory | `manage_inventory_items`, `enter_count`, `approve_variance`, `manage_transfers` | | production | `create_batch`, `close_batch`, `record_waste` | | purchasing | `manage_suppliers`, `create_purchase_order`, `receive_purchase`, `register_supplier_payment` | | delivery | `settle_delivery_account`, `manage_delivery_policy` | | cash | `enter_reconciliation`, `manage_vault` | | accounting | `view_gl`, `manage_accounting`, `manage_periods` | | reports | `view_reports`, `view_profit`, `view_hq` | | audit | `view_audit`, `resolve_fraud` | | hr | `view_hr`, `manage_employees`, `manage_attendance`, `manage_payroll` | | admin | `manage_users`, `manage_settings`, `manage_org` | Each endpoint in the [API Reference](/api-reference/) lists the credentials it accepts. ## Presets Presets make a large grant easy to pick. They are **expanded at mint time and never stored**, so a preset that grows later cannot widen an existing key. - `preset:full` — every capability the owner holds. As powerful as the owner; use sparingly. - `preset:read_only` — the read capabilities. - `preset:` — one per module: `preset:pos`, `preset:inventory`, `preset:hr`, … ## Legacy scopes The original seven scopes stay valid as aliases, each mapping to one capability: `read:reports`, `write:sales`, `write:inventory`, `write:suppliers`, `write:purchases`, `write:catalog`, `manage:webhooks`. ## Refusals | Status | Meaning | | ------ | ------------------------------------------------------------------------------------------------------ | | `401` | Missing, malformed or revoked credential | | `403` | The key's scopes or the owner's role do not permit the action, or the plan does not include the module | --- ## Responses & Errors _The two envelopes, numeric error codes, pagination and idempotency._ ## Envelopes **Console and guest** — `ApiResponse`: ```json { "success": true, "data": {}, "message": null, "code": null, "errors": null } ``` **Public** — the partner envelope: ```json { "ok": true, "data": [], "total": 120 } ``` ```json { "ok": false, "error": { "code": 409, "message": "…" } } ``` ## The code is the HTTP status | Number | Name | | ------ | ---------------------------------- | | 400 | `IDEMPOTENCY_KEY_REQUIRED` | | 401 | `UNAUTHORIZED` · `REAUTH_REQUIRED` | | 403 | `FORBIDDEN` · `TENANT_MISMATCH` | | 404 | `NOT_FOUND` | | 409 | `CONFLICT` · `PERIOD_LOCKED` | | 422 | `VALIDATION` | | 429 | `RATE_LIMITED` | | 500 | `INTERNAL` | Where a number is shared, the specific name is echoed in `errors.code`: ```json { "success": false, "message": "Business day 2026-09-01 is locked.", "code": 409, "errors": { "code": ["PeriodLocked"] } } ``` ## Reading an error 1. `success: true` → read `data`. 2. Take the number: `code` if present, otherwise the HTTP status. 3. **422** → `VALIDATION`; `errors` is the field dictionary (`field → messages`). Do not read `errors.code` as a name here — a form may have a field called `code`. 4. Otherwise, if `errors.code[0]` names a member (e.g. `PeriodLocked`), that name wins. 5. Otherwise use the number's own name from the table above. Unknown numbers are `INTERNAL`. 6. Switch on the name — never on `message`. On `/api/v1/public/**`, read `error.code`. A refused credential, a missing scope, an unbindable body or an unhandled fault there still arrives in the `{ success, … }` shape — apply the steps above to it. ## Pagination - Console lists: `page`, `per_page`, `search`. - Public lists: `limit`, `offset`; the response carries `total`. ## Idempotency Send `Idempotency-Key: ` on writes. It is **mandatory** on `POST /api/v1/public/orders` and guest self-orders (missing → `400 IDEMPOTENCY_KEY_REQUIRED`). A retry with the same key and body returns the original result instead of creating a duplicate. --- ## Webhooks _Subscribe to every audited change, verify signatures, handle retries._ Every state-changing action in Panoptes writes one audit row inside its own transaction. When a branch has an active webhook subscription, an event is staged beside that row — so an event is sent **if and only if** the change committed. ## Event names Events are `.`, for example `pos.void_line`, `inventory.post_transfer`, `hr.run_payroll`. The catalogue is served by the [Webhooks endpoints](/api-reference/webhooks/). A subscription may name exact events, a module wildcard (`pos.*`) or everything (`*`). - Subscribing to `hr.*`, `accounting.*` or `audit.*` requires `view_hr`, `view_gl` or `view_audit` — those payloads carry before-and-after values. `*` requires all three. - Credential and secret lifecycle, evidence views and face registration are **never** broadcast. ## Delivery Panoptes `POST`s to your URL with a JSON body and these headers: | Header | Value | | ------------------------- | ---------------------------------------------------------------------------- | | `x-panoptes-signature` | `sha256=` | | `x-panoptes-event-id` | Unique event id — use it to de-duplicate | | `x-panoptes-event-type` | e.g. `pos.create_sale` | | `x-panoptes-api-version` | The subscription's API version | | `x-panoptes-retry-number` | `0` on the first attempt | Answer any `2xx` quickly. Anything else is retried on a backoff ladder; a delivery that keeps failing is marked exhausted and can be replayed from the dashboard. ## Verifying the signature ```js import crypto from 'node:crypto'; function verify(rawBody, header, secret) { const expected = 'sha256=' + crypto.createHmac('sha256', secret).update(rawBody).digest('hex'); return ( header.length === expected.length && crypto.timingSafeEqual(Buffer.from(header), Buffer.from(expected)) ); } ``` Always verify against the **raw** request bytes, before JSON parsing. ## Testing Use the subscription's **Send test** action to post a test event to your endpoint, and inspect deliveries (status, response body, attempts) from the same screen. --- ## Realtime (SignalR) _Console events over SignalR for dashboards you build._ A dashboard you build can receive live events from the console hub at **`/api/v1/console/realtime`** (SignalR). - Pass the console JWT in the `access_token` query parameter (accepted on this path only). - The hub has one client method, `event`. Its payload carries **ids only** — re-fetch the resource over HTTP to get the data. - You join only the topics your role and plan allow. ```js import * as signalR from '@microsoft/signalr'; const conn = new signalR.HubConnectionBuilder() .withUrl('https://staging-api.panoptesos.com/api/v1/console/realtime', { accessTokenFactory: () => accessToken, }) .withAutomaticReconnect() .build(); conn.on('event', (e) => console.log(e)); await conn.start(); ``` For server-to-server integrations, use [Webhooks](/docs/webhooks/) instead. --- ## MCP Overview _What the Panoptes MCP server is, and how an AI agent uses it._ Panoptes serves a [Model Context Protocol](https://modelcontextprotocol.io) server so an AI agent — Claude, ChatGPT, Cursor or your own — can answer questions about a restaurant from real numbers and, when you allow it, take actions. | | | | ------------- | -------------------------------------------------------------------------------------------------- | | **URL** | `https://api.panoptesos.com/api/v1/mcp` (staging: `https://staging-api.panoptesos.com/api/v1/mcp`) | | **Transport** | Streamable HTTP, stateless JSON-RPC | | **Auth** | `X-Api-Key` header, or an OAuth bearer from the Panoptes OAuth issuer | | **Admission** | `cap:view_reports` (or the legacy `read:reports`) | In the dashboard, **Settings → Developers → MCP / AI** shows the URL for your install, ready-to-paste client configs and the tool list. ## How an agent works with it 1. **`get_business_context` first.** It names the branch the credential is bound to, the currency every amount is in, today's business date and the grounding rules. 2. **Facts** answer the common questions (sales, prime cost, COGS, loss, shrinkage, reorder, payroll…) with numbers computed by the server — the agent never does the arithmetic. 3. **Tables** let it look further: list, read, count and aggregate the readable tables. 4. **Actions** let it change data: `list_actions` finds what the credential may call, `call_action` performs it through the REST pipeline. ## Guarantees - **Same permissions as the REST API.** Effective access is the owner's role AND the credential's scopes. Each fact tool keeps its own capability. - **Reads cannot write.** Fact and table tools run in a `READ ONLY` transaction; `call_action` is the only write path. - **Writes are the real thing.** `call_action` runs in-process through the console pipeline: validation, separation of duties, period locks, idempotency and the audit chain all apply. - **The model is told to ask.** The server instructs the agent to confirm any money or stock movement with the user, and to pass an `idempotencyKey` on every write. Next: [Connect a client](/docs/mcp-connect/) · [Tool reference](/docs/mcp-tools/) · [Actions](/docs/mcp-actions/) --- ## Connect a Client _Claude Code, Claude Desktop, Cursor and OAuth connectors._ ## 1. Get a credential **API key (any client).** In the dashboard open **Settings → Developers → API keys** and mint a key for the agent. - Read-only agent: `preset:read_only` (includes `cap:view_reports`). - Agent that acts: add only the module presets it needs, e.g. `preset:inventory`. Avoid `preset:full` — an agent with it is as powerful as the owner. **OAuth (clients that support it).** Give the client just the URL. It registers itself, opens a Panoptes sign-in window, and you approve each scope one box at a time. An OAuth bearer is accepted on `/api/v1/mcp` only. ## 2. Configure the client ### Claude Code ```bash claude mcp add --transport http panoptes https://api.panoptesos.com/api/v1/mcp \ --header "X-Api-Key: pnp_live_xxxxxxxx.YOUR_SECRET" ``` ### Claude Desktop, Cursor and other JSON configs ```json { "mcpServers": { "panoptes": { "type": "http", "url": "https://api.panoptesos.com/api/v1/mcp", "headers": { "X-Api-Key": "pnp_live_xxxxxxxx.YOUR_SECRET" } } } } ``` ### Claude.ai / ChatGPT connectors Add a custom connector with the URL `https://api.panoptesos.com/api/v1/mcp` and sign in when prompted (OAuth). ## 3. Check it works Ask the agent: _"What is my business context?"_ — it should call `get_business_context` and report your branch, currency and business date. ## Troubleshooting | Response | Cause | | ----------------------------- | ----------------------------------------------------------------------------- | | `401` with `WWW-Authenticate` | Missing, malformed or revoked key; or the tenant is suspended | | `403` | The credential lacks `cap:view_reports`, or the plan does not include the API | | `429` | The key's rate limit or quota — see `Retry-After` | | Tool refused inside a call | That tool's capability is not in the credential's scopes or the owner's role | --- ## Tool Reference _Every MCP tool, what it answers, and its main parameters._ Dates are business days `YYYY-MM-DD` (Asia/Baghdad); an omitted date means today. Amounts are in the branch currency returned by `get_business_context` — never convert them. ## Start here | Tool | Answers | Parameters | | ---------------------- | -------------------------------------------------------------- | ---------- | | `get_business_context` | Bound branch, currency, today's business date, grounding rules | — | ## Facts (read-only) | Tool | Answers | Parameters | | ------------------------- | ---------------------------------------------------- | -------------------------------------------------------------------- | | `get_sales_summary` | Sales over a window | `days` (1–120, default 14) | | `get_prime_cost` | Prime cost: COGS + labour vs net sales | `from`, `to` | | `get_daily_cogs` | Cost of goods sold per day | `from`, `to` | | `get_cost_per_serving` | Cost per serving by product | `channel` (default takeaway), `incompleteOnly`, `page` | | `get_inventory_snapshot` | Stock on hand at one location | location name or kind (`warehouse`, `kitchen`, …) | | `get_item_consumption` | Items used over a range | `from`, `to` | | `get_loss_summary` | Loss over a range | `from`, `to`, `groupBy` (day · shift · material · severity), `shift` | | `get_shrinkage_report` | Warehouse vs kitchen shrinkage | `from`, `to` | | `get_avt_facts` | Actual vs theoretical usage for one day and one book | `businessDate`, `location` (kitchen · warehouse) | | `get_owner_leakage_facts` | The owner's leakage facts for one day | `businessDate` | | `get_price_variance` | Purchase price variance, top movers | `from`, `to`, `topN` | | `get_purchases_summary` | Purchases per day and supplier debt | `days` (1–365, default 30) | | `get_reorder_suggestions` | What to reorder, from consumption velocity | history window in days | | `get_payroll_summary` | Payroll and headcount | — | | `get_sales_integrity` | Per-cashier discount and void outliers | `from`, `to` | | `get_risk_signals` | Current risk signals | `limit` (1–50, default 10) | Loss is the sum of shortages — a surplus never cancels one — and the warehouse and kitchen books are never netted. ## Tables (read-only) | Tool | Does | | ----------------- | --------------------------------------------------------------------- | | `list_tables` | Lists the readable tables and their columns | | `read_table` | Reads rows with filters, sort (`asc` · `desc`) and paging | | `get_record` | One row by id | | `count_table` | Counts rows matching filters | | `aggregate_table` | Sum / average / min / max / count, grouped — computed by the database | Sensitive tables (credentials, secrets, audit internals) are never readable. ## Actions (write) | Tool | Does | | -------------- | --------------------------------------------------------------------------------------- | | `list_actions` | Console actions this credential may call — filter by `module`, `search`, `includeReads` | | `call_action` | Performs one: `method`, `path` (`/api/v1/console/…`), `body`, `idempotencyKey` | See [Actions](/docs/mcp-actions/). --- ## Actions (list_actions / call_action) _Let an agent change data safely through the REST pipeline._ The two action tools give an agent the reach of the [REST API](/api-reference/) without a second set of rules. ## list_actions Returns every console action the credential may call, with its method, route, path parameters and body fields. ```json { "module": "inventory", "search": "transfer", "includeReads": false } ``` All parameters are optional. Actions closed to machines — sign-in and auth flows, minting keys and OAuth clients, the vendor platform — are never listed. ## call_action ```json { "method": "POST", "path": "/api/v1/console/central-kitchen/transfers", "body": { "sourceLocationId": "…", "destLocationId": "…", "lines": [] }, "idempotencyKey": "7f3c2a9e-1b4d-4c1e-9a53-0e2b6d1f8a44" } ``` - `path` is a concrete console path, starting `/api/v1/console/`. - `body` is for POST, PUT and PATCH. - `idempotencyKey` — a fresh value for each write. Reuse it only to retry the identical request. The result is the action's normal response: the `{ success, data, message, code, errors }` envelope (see [Responses & Errors](/docs/errors/)). ## What still applies `call_action` runs **in-process** through the application's own pipeline, as the calling credential, with its real address: - scope AND role capability, and `[SessionOnly]` refusals; - the key's rate limit, quota, IP and origin allow-lists; - validation, separation of duties and period locks; - idempotency and the audit chain — every write is audited, and emits its [webhook](/docs/webhooks/) event like any other change. ## Keeping an agent safe - Give the key only the module presets it needs. - The tool is annotated destructive, and the server tells the model to confirm money and stock movements with the user before calling it. Keep your client's tool-approval prompt on for `call_action`. - Review the agent's changes in the audit log like any other user's. --- # API endpoint catalogue 611 endpoints across 125 resource groups. Format: `METHOD /path — summary [auth]`. Full request/response schemas are in the OpenAPI spec. ## Accounting Exports - `GET /api/v1/console/accounting/accounts/export` [API key] - `GET /api/v1/console/accounting/journal/export` [API key] ## Accounts - `GET /api/v1/console/accounting/accounts` [API key] - `POST /api/v1/console/accounting/accounts` [API key] - `DELETE /api/v1/console/accounting/accounts/{id}` [API key] - `GET /api/v1/console/accounting/accounts/{id}` [API key] - `PUT /api/v1/console/accounting/accounts/{id}` [API key] - `POST /api/v1/console/accounting/accounts/{id}/active` [API key] - `POST /api/v1/console/accounting/accounts/seed` [API key] ## Advances - `GET /api/v1/console/hr/advances` [API key] - `POST /api/v1/console/hr/advances` [API key] - `POST /api/v1/console/hr/advances/{id}/decision` [API key] - `GET /api/v1/console/hr/loans` [API key] - `POST /api/v1/console/hr/loans` [API key] - `POST /api/v1/console/hr/loans/{id}/decision` [API key] ## Aging - `GET /api/v1/console/accounting/aging/payables` [API key] - `GET /api/v1/console/accounting/aging/receivables` [API key] ## Announcements - `GET /api/v1/console/announcements` [API key] ## API Keys - `GET /api/v1/console/developers/api-keys` [JWT] - `POST /api/v1/console/developers/api-keys` [JWT] - `GET /api/v1/console/developers/api-keys/{id}` [JWT] - `PUT /api/v1/console/developers/api-keys/{id}` [JWT] - `POST /api/v1/console/developers/api-keys/{id}/revoke` [JWT] - `POST /api/v1/console/developers/api-keys/{id}/rotate` [JWT] - `GET /api/v1/console/developers/api-keys/scopes` [JWT] ## Approval Requests - `GET /api/v1/console/fraud/approval-requests` [API key] - `POST /api/v1/console/fraud/approval-requests` [API key] - `GET /api/v1/console/fraud/approval-requests/{id}` [API key] - `POST /api/v1/console/fraud/approval-requests/{id}/approve` [API key] - `POST /api/v1/console/fraud/approval-requests/{id}/reject` [API key] ## Attendance - `GET /api/v1/console/hr/attendance` [API key] - `POST /api/v1/console/hr/attendance` [API key] - `POST /api/v1/console/hr/attendance/clock` [API key] ## Audit Chain - `GET /api/v1/console/audit/chain` [API key] - `GET /api/v1/console/audit/chain/proof` [API key] - `GET /api/v1/console/audit/chain/verifications` [API key] - `POST /api/v1/console/audit/chain/verify` [API key] ## Audit Logs - `GET /api/v1/console/audit/logs` [API key] - `GET /api/v1/console/audit/logs/{id}` [API key] - `GET /api/v1/console/audit/logs/entities/{entityType}/{entityId}` [API key] ## Auth - `POST /api/v1/console/auth/activate` [JWT] - `POST /api/v1/console/auth/change-email/cancel` [JWT] - `POST /api/v1/console/auth/change-email/resend` [JWT] - `POST /api/v1/console/auth/change-email/start` [JWT] - `POST /api/v1/console/auth/change-email/verify` [JWT] - `POST /api/v1/console/auth/change-password` [JWT] - `POST /api/v1/console/auth/login` [JWT] - `POST /api/v1/console/auth/logout` [JWT] - `GET /api/v1/console/auth/me` [JWT] - `POST /api/v1/console/auth/password/forgot` [JWT] - `POST /api/v1/console/auth/password/reset` [JWT] - `POST /api/v1/console/auth/refresh` [JWT] - `POST /api/v1/console/auth/register/start` [JWT] - `POST /api/v1/console/auth/register/verify` [JWT] - `POST /api/v1/console/auth/switch-branch` [JWT] - `POST /api/v1/console/auth/verification/resend` [JWT] ## Bank - `GET /api/v1/console/accounting/bank-accounts` [API key] - `POST /api/v1/console/accounting/bank-accounts` [API key] - `GET /api/v1/console/accounting/bank-accounts/{id}` [API key] - `POST /api/v1/console/accounting/bank-accounts/{id}/statement-imports` [API key] - `GET /api/v1/console/accounting/bank-statement-lines` [API key] - `POST /api/v1/console/accounting/bank-statement-lines/{id}/exclude` [API key] - `POST /api/v1/console/accounting/bank-statement-lines/{id}/match` [API key] - `POST /api/v1/console/accounting/bank-statement-lines/{id}/reopen` [API key] - `GET /api/v1/console/accounting/bank-statement-lines/{id}/suggestions` [API key] ## Batch Capacity - `POST /api/v1/console/production/batches/{id}/outputs` [API key] - `DELETE /api/v1/console/production/batches/{id}/outputs/{outputId}` [API key] - `POST /api/v1/console/production/batches/{id}/waste` [API key] ## Batch Templates - `GET /api/v1/console/production/batch-templates` [API key] - `POST /api/v1/console/production/batch-templates` [API key] - `DELETE /api/v1/console/production/batch-templates/{id}` [API key] ## Branch Groups - `GET /api/v1/console/branch-groups` [API key] - `POST /api/v1/console/branch-groups` [API key] - `DELETE /api/v1/console/branch-groups/{id}` [API key] - `PUT /api/v1/console/branch-groups/{id}` [API key] - `POST /api/v1/console/branch-groups/{id}/branches` [API key] - `DELETE /api/v1/console/branch-groups/{id}/branches/{branchId}` [API key] ## Branch Memberships - `GET /api/v1/console/users/{userId}/memberships` [API key] - `POST /api/v1/console/users/{userId}/memberships` [API key] - `DELETE /api/v1/console/users/{userId}/memberships/{branchId}` [API key] - `PATCH /api/v1/console/users/{userId}/org-admin` [API key] ## Branches - `GET /api/v1/console/branches` [API key] - `POST /api/v1/console/branches` [API key] - `DELETE /api/v1/console/branches/{id}` [API key] - `GET /api/v1/console/branches/{id}` [API key] - `PUT /api/v1/console/branches/{id}` [API key] ## Brands - `GET /api/v1/console/brands` [API key] - `POST /api/v1/console/brands` [API key] - `DELETE /api/v1/console/brands/{id}` [API key] - `GET /api/v1/console/brands/{id}` [API key] - `PATCH /api/v1/console/brands/{id}` [API key] - `POST /api/v1/console/brands/{id}/active` [API key] ## Channel Product Map - `GET /api/v1/console/delivery/channels/{channelId}/product-map` [API key] - `POST /api/v1/console/delivery/channels/{channelId}/product-map` [API key] - `DELETE /api/v1/console/delivery/channels/{channelId}/product-map/{mapId}` [API key] ## Channel Receivables - `GET /api/v1/console/delivery/receivables/aging` [API key] ## Channels - `GET /api/v1/console/delivery/channels` [API key] - `GET /api/v1/console/delivery/channels/{channelId}/rules` [API key] - `POST /api/v1/console/delivery/channels/rule-requests` [API key] - `POST /api/v1/console/delivery/channels/rules` [API key] - `PATCH /api/v1/console/delivery/channels/rules/{ruleId}/active` [API key] ## Check In - `GET /api/v1/console/hr/attendance/evidence` [API key] - `POST /api/v1/console/hr/attendance/evidence` [API key] - `POST /api/v1/console/hr/attendance/evidence/{id}/decision` [API key] - `POST /api/v1/console/hr/attendance/evidence/{id}/dispute` [API key] - `POST /api/v1/console/hr/attendance/sessions` [API key] ## Combos - `GET /api/v1/console/combos` [API key] - `POST /api/v1/console/combos` [API key] - `DELETE /api/v1/console/combos/{id}` [API key] - `GET /api/v1/console/combos/{id}` [API key] - `PUT /api/v1/console/combos/{id}` [API key] ## Connectors - `GET /api/v1/console/developers/connectors` [JWT] - `POST /api/v1/console/developers/connectors/{connectorId}/connect` [JWT] ## Consumable BOM - `GET /api/v1/console/products/{productId}/consumables` [API key] - `POST /api/v1/console/products/{productId}/consumables` [API key] - `DELETE /api/v1/console/products/{productId}/consumables/{bomLineId}` [API key] ## Cost Cards - `GET /api/v1/console/costing/cost-per-serving` [API key] - `GET /api/v1/console/costing/orders` [API key] - `GET /api/v1/console/costing/orders/{orderId}` [API key] ## Cost Recalculation - `POST /api/v1/console/costing/recalculate` [API key] - `POST /api/v1/console/costing/recalculate/products/{productId}` [API key] ## Count Corrections - `POST /api/v1/console/inventory/movements/count-corrections` [API key] ## Currencies - `GET /api/v1/console/currencies` [API key] ## Customer Invoices - `GET /api/v1/console/accounting/customer-invoices` [API key] - `POST /api/v1/console/accounting/customer-invoices` [API key] - `DELETE /api/v1/console/accounting/customer-invoices/{id}` [API key] - `GET /api/v1/console/accounting/customer-invoices/{id}` [API key] - `PUT /api/v1/console/accounting/customer-invoices/{id}` [API key] - `POST /api/v1/console/accounting/customer-invoices/{id}/issue` [API key] - `POST /api/v1/console/accounting/customer-invoices/{id}/payments` [API key] - `GET /api/v1/console/accounting/customer-invoices/{id}/pdf` [API key] - `POST /api/v1/console/accounting/customer-invoices/{id}/void` [API key] - `GET /api/v1/console/accounting/customer-invoices/billable-orders` [API key] - `GET /api/v1/console/accounting/customer-invoices/statement` [API key] - `GET /api/v1/console/accounting/customer-invoices/statement/pdf` [API key] ## Dashboards - `GET /api/v1/console/dashboard/export` [API key] - `DELETE /api/v1/console/dashboard/layout` [API key] - `GET /api/v1/console/dashboard/layout` [API key] - `PUT /api/v1/console/dashboard/layout` [API key] - `GET /api/v1/console/dashboard/tiles` [API key] ## Delivery Policies - `GET /api/v1/console/delivery/policies` [API key] - `PUT /api/v1/console/delivery/policies` [API key] - `GET /api/v1/console/delivery/policies/{channelId}` [API key] ## Delivery Reviews - `POST /api/v1/console/delivery/reviews` [API key] - `GET /api/v1/console/delivery/reviews/compliance` [API key] - `POST /api/v1/console/delivery/reviews/missed` [API key] - `GET /api/v1/console/delivery/reviews/returnable-orders` [API key] ## Delivery Settlements - `GET /api/v1/console/delivery/settlements` [API key] - `GET /api/v1/console/delivery/settlements/{id}` [API key] - `POST /api/v1/console/delivery/settlements/{id}/reconcile` [API key] - `POST /api/v1/console/delivery/settlements/import` [API key] - `POST /api/v1/console/delivery/settlements/transfers` [API key] - `GET /api/v1/console/delivery/settlements/variance` [API key] ## Dining Areas - `GET /api/v1/console/pos/dining-areas` [API key] - `POST /api/v1/console/pos/dining-areas` [API key] - `DELETE /api/v1/console/pos/dining-areas/{id}` [API key] - `PUT /api/v1/console/pos/dining-areas/{id}` [API key] ## Dining Tables - `GET /api/v1/console/pos/dining-tables` [API key] - `POST /api/v1/console/pos/dining-tables` [API key] - `DELETE /api/v1/console/pos/dining-tables/{id}` [API key] - `PUT /api/v1/console/pos/dining-tables/{id}` [API key] - `POST /api/v1/console/pos/dining-tables/{id}/active` [API key] - `DELETE /api/v1/console/pos/dining-tables/{id}/qr-token` [API key] - `POST /api/v1/console/pos/dining-tables/{id}/qr-token` [API key] ## Employee Documents - `GET /api/v1/console/hr/employees/{id}/documents` [API key] - `POST /api/v1/console/hr/employees/{id}/documents` [API key] - `DELETE /api/v1/console/hr/employees/documents/{documentId}` [API key] ## Employees - `GET /api/v1/console/hr/departments` [API key] - `GET /api/v1/console/hr/employees` [API key] - `POST /api/v1/console/hr/employees` [API key] - `DELETE /api/v1/console/hr/employees/{id}` [API key] - `GET /api/v1/console/hr/employees/{id}` [API key] - `PUT /api/v1/console/hr/employees/{id}` [API key] - `POST /api/v1/console/hr/employees/{id}/employment-status` [API key] - `GET /api/v1/console/hr/positions` [API key] ## End-of-Day Reports - `GET /api/v1/console/loss/eod-reports` [API key] - `POST /api/v1/console/loss/eod-reports` [API key] - `GET /api/v1/console/loss/eod-reports/{id}` [API key] - `PUT /api/v1/console/loss/eod-reports/{id}` [API key] - `POST /api/v1/console/loss/eod-reports/parse` [API key] ## Exchange Rates - `GET /api/v1/console/exchange-rates` [API key] - `POST /api/v1/console/exchange-rates` [API key] ## Export Jobs - `GET /api/v1/console/export-jobs` [API key] - `POST /api/v1/console/export-jobs` [API key] - `DELETE /api/v1/console/export-jobs/{id}` [API key] - `GET /api/v1/console/export-jobs/{id}` [API key] - `GET /api/v1/console/export-jobs/{id}/download` [API key] ## Export Presets - `GET /api/v1/console/settings/export-presets` [API key] - `POST /api/v1/console/settings/export-presets` [API key] - `DELETE /api/v1/console/settings/export-presets/{id}` [API key] - `GET /api/v1/console/settings/export-presets/domains` [API key] ## Floor - `GET /api/v1/console/pos/floor` [API key] ## Floor Seating - `POST /api/v1/console/pos/orders/{id}/release` [API key] - `POST /api/v1/console/pos/orders/{id}/table` [API key] ## Franchisees - `PATCH /api/v1/console/branches/{branchId}/franchisee` [API key] - `GET /api/v1/console/franchisees` [API key] - `POST /api/v1/console/franchisees` [API key] - `PUT /api/v1/console/franchisees/{id}` [API key] - `GET /api/v1/console/franchisees/{id}/royalty-statement` [API key] ## Fraud Cases - `GET /api/v1/console/fraud/cases` [API key] - `DELETE /api/v1/console/fraud/cases/{id}` [API key] - `GET /api/v1/console/fraud/cases/{id}` [API key] - `PATCH /api/v1/console/fraud/cases/{id}/status` [API key] - `GET /api/v1/console/fraud/cases/summary` [API key] ## Guest · Menu - `GET /api/v1/guest/menu/{identifier}` [public] ## Guest · Self Order - `GET /api/v1/guest/self-order/{qrToken}` [public] - `POST /api/v1/guest/self-order/{qrToken}/orders` [public] - `POST /api/v1/guest/self-order/{qrToken}/quote` [public] ## Guest Payments - `GET /api/v1/console/pos/guest-payments` [API key] - `POST /api/v1/console/pos/guest-payments/{id}/confirm` [API key] - `POST /api/v1/console/pos/guest-payments/{id}/reject` [API key] ## HQ - `GET /api/v1/console/hq/branches` [API key] - `GET /api/v1/console/hq/consolidated-pnl` [API key] - `GET /api/v1/console/hq/today` [API key] ## HR Dashboard - `GET /api/v1/console/hr/employees/{id}/profile` [API key] - `GET /api/v1/console/hr/summary` [API key] ## HR Notifications - `GET /api/v1/console/hr/notifications` [API key] - `POST /api/v1/console/hr/notifications/{id}/read` [API key] - `POST /api/v1/console/hr/notifications/read-all` [API key] - `POST /api/v1/console/hr/notifications/rebuild` [API key] ## Idempotency Keys - `GET /api/v1/console/platform/idempotency-keys` [API key] - `POST /api/v1/console/platform/idempotency-keys/{id}/release` [API key] - `POST /api/v1/console/platform/idempotency-keys/sweep` [API key] ## Integrity Alerts - `GET /api/v1/console/audit/alerts` [API key] - `POST /api/v1/console/audit/alerts/{id}/acknowledge` [API key] ## Inventory Counts - `GET /api/v1/console/inventory/counts` [API key] - `POST /api/v1/console/inventory/counts` [API key] - `POST /api/v1/console/inventory/counts/{countId}/lines/{lineId}/approve` [API key] - `POST /api/v1/console/inventory/counts/{countId}/lines/{lineId}/evidence` [API key] - `GET /api/v1/console/inventory/counts/{id}` [API key] - `POST /api/v1/console/inventory/counts/{id}/approve` [API key] - `GET /api/v1/console/inventory/counts/evidence/{evidenceId}` [API key] - `GET /api/v1/console/inventory/counts/sheet` [API key] ## Inventory Items - `GET /api/v1/console/inventory/items` [API key] - `POST /api/v1/console/inventory/items` [API key] - `DELETE /api/v1/console/inventory/items/{id}` [API key] - `GET /api/v1/console/inventory/items/{id}` [API key] - `PUT /api/v1/console/inventory/items/{id}` [API key] - `GET /api/v1/console/inventory/items/lookup` [API key] ## Journal - `POST /api/v1/console/accounting/journal/daily-sales` [API key] - `GET /api/v1/console/accounting/journal/entries` [API key] - `GET /api/v1/console/accounting/journal/entries/{id}` [API key] ## KDS Board - `GET /api/v1/console/kds/board` [API key] - `POST /api/v1/console/kds/tickets/{ticketId}/transition` [API key] ## KDS Stations - `GET /api/v1/console/kds/stations` [API key] - `POST /api/v1/console/kds/stations` [API key] - `DELETE /api/v1/console/kds/stations/{id}` [API key] - `PUT /api/v1/console/kds/stations/{id}` [API key] ## Kitchen Transfers - `GET /api/v1/console/central-kitchen/kitchen-transfers` [API key] - `POST /api/v1/console/central-kitchen/kitchen-transfers` [API key] - `POST /api/v1/console/central-kitchen/kitchen-transfers/{id}/approve` [API key] - `POST /api/v1/console/central-kitchen/kitchen-transfers/{id}/reject` [API key] ## Leave - `GET /api/v1/console/hr/leave` [API key] - `POST /api/v1/console/hr/leave` [API key] - `POST /api/v1/console/hr/leave/{id}/decision` [API key] ## Ledger Lock - `POST /api/v1/console/loss/days/lock` [API key] - `POST /api/v1/console/loss/periods/close` [API key] - `POST /api/v1/console/loss/periods/lock` [API key] - `POST /api/v1/console/loss/periods/reopen` [API key] ## Legal Entities - `GET /api/v1/console/accounting/legal-entities` [API key] - `POST /api/v1/console/accounting/legal-entities` [API key] - `DELETE /api/v1/console/accounting/legal-entities/{id}` [API key] - `GET /api/v1/console/accounting/legal-entities/{id}` [API key] - `PUT /api/v1/console/accounting/legal-entities/{id}` [API key] ## Loss Capture - `GET /api/v1/console/production/portion-checks` [API key] - `POST /api/v1/console/production/portion-checks` [API key] - `GET /api/v1/console/production/staff-meals` [API key] - `POST /api/v1/console/production/staff-meals` [API key] ## Loss Summary - `GET /api/v1/console/loss/breakdown` [API key] - `GET /api/v1/console/loss/completeness` [API key] - `GET /api/v1/console/loss/slice` [API key] - `GET /api/v1/console/loss/summary` [API key] ## Media Images - `POST /api/v1/media/images` [API key] - `DELETE /api/v1/media/images/{assetId}` [API key] - `GET /api/v1/media/images/{assetId}` [API key] - `POST /api/v1/media/images/refresh-urls` [API key] - `GET /api/v1/media/owners/{ownerType}/{ownerId}/images` [API key] - `DELETE /api/v1/media/owners/{ownerType}/{ownerId}/images/{slot}` [API key] - `PUT /api/v1/media/owners/{ownerType}/{ownerId}/images/{slot}` [API key] - `PUT /api/v1/media/owners/{ownerType}/{ownerId}/images/gallery/order` [API key] - `POST /api/v1/media/owners/images/batch` [API key] ## Modifiers - `GET /api/v1/console/modifiers/groups` [API key] - `POST /api/v1/console/modifiers/groups` [API key] - `DELETE /api/v1/console/modifiers/groups/{id}` [API key] - `GET /api/v1/console/modifiers/groups/{id}` [API key] - `POST /api/v1/console/modifiers/options` [API key] - `DELETE /api/v1/console/modifiers/options/{id}` [API key] - `POST /api/v1/console/modifiers/validate-selection` [API key] ## Module Vocabularies - `GET /api/v1/console/delivery/channel-types` [API key] - `POST /api/v1/console/delivery/channel-types` [API key] - `DELETE /api/v1/console/delivery/channel-types/{id}` [API key] - `PATCH /api/v1/console/delivery/channel-types/{id}` [API key] - `PUT /api/v1/console/delivery/channel-types/{id}` [API key] - `POST /api/v1/console/delivery/channel-types/{id}/active` [API key] - `GET /api/v1/console/hr/document-types` [API key] - `POST /api/v1/console/hr/document-types` [API key] - `DELETE /api/v1/console/hr/document-types/{id}` [API key] - `PATCH /api/v1/console/hr/document-types/{id}` [API key] - `PUT /api/v1/console/hr/document-types/{id}` [API key] - `POST /api/v1/console/hr/document-types/{id}/active` [API key] - `GET /api/v1/console/hr/leave-types` [API key] - `POST /api/v1/console/hr/leave-types` [API key] - `DELETE /api/v1/console/hr/leave-types/{id}` [API key] - `PATCH /api/v1/console/hr/leave-types/{id}` [API key] - `PUT /api/v1/console/hr/leave-types/{id}` [API key] - `POST /api/v1/console/hr/leave-types/{id}/active` [API key] - `GET /api/v1/console/hr/violation-types` [API key] - `POST /api/v1/console/hr/violation-types` [API key] - `DELETE /api/v1/console/hr/violation-types/{id}` [API key] - `PATCH /api/v1/console/hr/violation-types/{id}` [API key] - `PUT /api/v1/console/hr/violation-types/{id}` [API key] - `POST /api/v1/console/hr/violation-types/{id}/active` [API key] - `GET /api/v1/console/inventory/units` [API key] - `POST /api/v1/console/inventory/units` [API key] - `DELETE /api/v1/console/inventory/units/{id}` [API key] - `PATCH /api/v1/console/inventory/units/{id}` [API key] - `PUT /api/v1/console/inventory/units/{id}` [API key] - `POST /api/v1/console/inventory/units/{id}/active` [API key] - `GET /api/v1/console/inventory/variance-reasons` [API key] - `POST /api/v1/console/inventory/variance-reasons` [API key] - `DELETE /api/v1/console/inventory/variance-reasons/{id}` [API key] - `PATCH /api/v1/console/inventory/variance-reasons/{id}` [API key] - `PUT /api/v1/console/inventory/variance-reasons/{id}` [API key] - `POST /api/v1/console/inventory/variance-reasons/{id}/active` [API key] - `GET /api/v1/console/production/capacity-types` [API key] - `POST /api/v1/console/production/capacity-types` [API key] - `DELETE /api/v1/console/production/capacity-types/{id}` [API key] - `PATCH /api/v1/console/production/capacity-types/{id}` [API key] - `PUT /api/v1/console/production/capacity-types/{id}` [API key] - `POST /api/v1/console/production/capacity-types/{id}/active` [API key] - `GET /api/v1/console/settings/payment-methods` [API key] - `POST /api/v1/console/settings/payment-methods` [API key] - `DELETE /api/v1/console/settings/payment-methods/{id}` [API key] - `PATCH /api/v1/console/settings/payment-methods/{id}` [API key] - `PUT /api/v1/console/settings/payment-methods/{id}` [API key] - `POST /api/v1/console/settings/payment-methods/{id}/active` [API key] - `GET /api/v1/console/settings/revoke-reasons` [API key] - `POST /api/v1/console/settings/revoke-reasons` [API key] - `DELETE /api/v1/console/settings/revoke-reasons/{id}` [API key] - `PATCH /api/v1/console/settings/revoke-reasons/{id}` [API key] - `PUT /api/v1/console/settings/revoke-reasons/{id}` [API key] - `POST /api/v1/console/settings/revoke-reasons/{id}/active` [API key] ## OAuth 2.0 - `GET /api/v1/public/oauth/authorize` [public] - `POST /api/v1/public/oauth/register` [public] - `POST /api/v1/public/oauth/token` [public] ## OAuth Clients - `GET /api/v1/console/developers/oauth-clients` [JWT] - `POST /api/v1/console/developers/oauth-clients` [JWT] - `POST /api/v1/console/developers/oauth-clients/{id}/revoke` [JWT] - `POST /api/v1/console/oauth/consent` [JWT] ## Online Menu - `GET /api/v1/console/online-menu` [API key] - `DELETE /api/v1/console/online-menu/domain` [API key] - `PUT /api/v1/console/online-menu/domain` [API key] - `POST /api/v1/console/online-menu/domain/verify` [API key] - `PUT /api/v1/console/online-menu/enabled` [API key] - `PUT /api/v1/console/online-menu/slug` [API key] - `GET /api/v1/console/online-menu/slug/availability` [API key] ## Order Courses - `POST /api/v1/console/pos/orders/{id}/courses/{courseNumber}/fire` [API key] ## Org Units - `POST /api/v1/console/hr/departments` [API key] - `DELETE /api/v1/console/hr/departments/{id}` [API key] - `PUT /api/v1/console/hr/departments/{id}` [API key] - `POST /api/v1/console/hr/positions` [API key] - `DELETE /api/v1/console/hr/positions/{id}` [API key] - `PUT /api/v1/console/hr/positions/{id}` [API key] ## Organizations - `GET /api/v1/console/organizations` [API key] - `POST /api/v1/console/organizations` [API key] - `DELETE /api/v1/console/organizations/{id}` [API key] - `GET /api/v1/console/organizations/{id}` [API key] - `PUT /api/v1/console/organizations/{id}` [API key] - `POST /api/v1/console/organizations/{id}/branches` [API key] ## Outbox - `GET /api/v1/console/platform/outbox` [API key] - `GET /api/v1/console/platform/outbox/{id}` [API key] - `POST /api/v1/console/platform/outbox/{id}/replay` [API key] ## Payroll - `GET /api/v1/console/hr/payroll` [API key] - `POST /api/v1/console/hr/payroll` [API key] - `GET /api/v1/console/hr/payroll/{id}` [API key] - `POST /api/v1/console/hr/payroll/{id}/approve` [API key] - `POST /api/v1/console/hr/payroll/{id}/pay` [API key] - `PUT /api/v1/console/hr/payroll/payslips/{payslipId}` [API key] ## Performance Reviews - `GET /api/v1/console/hr/performance-reviews` [API key] - `POST /api/v1/console/hr/performance-reviews` [API key] ## Periods - `GET /api/v1/console/accounting/periods` [API key] - `DELETE /api/v1/console/accounting/periods/{id}` [API key] - `GET /api/v1/console/accounting/periods/{id}` [API key] - `POST /api/v1/console/accounting/periods/close` [API key] - `POST /api/v1/console/accounting/periods/lock` [API key] - `POST /api/v1/console/accounting/periods/reopen` [API key] ## Pilots - `GET /api/v1/console/loss/pilots` [API key] - `POST /api/v1/console/loss/pilots` [API key] - `DELETE /api/v1/console/loss/pilots/{id}` [API key] - `GET /api/v1/console/loss/pilots/{id}` [API key] - `PUT /api/v1/console/loss/pilots/{id}` [API key] - `POST /api/v1/console/loss/pilots/{id}/status` [API key] ## POS Orders - `GET /api/v1/console/pos/orders` [API key] - `POST /api/v1/console/pos/orders` [API key] - `GET /api/v1/console/pos/orders/{id}` [API key] - `POST /api/v1/console/pos/orders/{id}/cancel` [API key] - `POST /api/v1/console/pos/orders/{id}/refund` [API key] - `PATCH /api/v1/console/pos/orders/{id}/status` [API key] - `POST /api/v1/console/pos/orders/{orderId}/lines/{lineId}/comp` [API key] - `POST /api/v1/console/pos/orders/{orderId}/lines/{lineId}/void` [API key] ## Pos Reference - `GET /api/v1/console/pos/reference` [API key] ## Price Preview - `GET /api/v1/console/pricing/live-promotions` [API key] - `POST /api/v1/console/pricing/preview` [API key] ## Price Variance - `GET /api/v1/console/purchase-invoices/loss-slices` [API key] - `GET /api/v1/console/purchase-invoices/price-history` [API key] - `GET /api/v1/console/purchase-invoices/price-variance` [API key] - `GET /api/v1/console/reports/price-variance` [API key] ## Product Categories - `GET /api/v1/console/product-categories` [API key] - `POST /api/v1/console/product-categories` [API key] - `DELETE /api/v1/console/product-categories/{id}` [API key] - `GET /api/v1/console/product-categories/{id}` [API key] - `PATCH /api/v1/console/product-categories/{id}` [API key] ## Product Import - `GET /api/v1/console/catalog/imports/{batchId}` [API key] - `POST /api/v1/console/catalog/imports/{batchId}/commit` [API key] - `POST /api/v1/console/catalog/imports/products` [API key] ## Production Batches - `GET /api/v1/console/production/batches` [API key] - `POST /api/v1/console/production/batches` [API key] - `DELETE /api/v1/console/production/batches/{id}` [API key] - `GET /api/v1/console/production/batches/{id}` [API key] - `PUT /api/v1/console/production/batches/{id}` [API key] - `POST /api/v1/console/production/batches/{id}/close` [API key] - `PUT /api/v1/console/production/batches/{id}/overflow` [API key] - `PUT /api/v1/console/production/batches/{id}/status` [API key] ## Products - `GET /api/v1/console/products` [API key] - `POST /api/v1/console/products` [API key] - `DELETE /api/v1/console/products/{id}` [API key] - `GET /api/v1/console/products/{id}` [API key] - `PATCH /api/v1/console/products/{id}/availability` [API key] - `PATCH /api/v1/console/products/{id}/price` [API key] - `GET /api/v1/console/products/{id}/recipe` [API key] - `POST /api/v1/console/products/{id}/recipe/ingredients` [API key] - `DELETE /api/v1/console/products/{id}/recipe/ingredients/{bomLineId}` [API key] ## Promotions - `GET /api/v1/console/promotions` [API key] - `POST /api/v1/console/promotions` [API key] - `DELETE /api/v1/console/promotions/{id}` [API key] - `GET /api/v1/console/promotions/{id}` [API key] - `PATCH /api/v1/console/promotions/{id}/active` [API key] - `POST /api/v1/console/promotions/change-requests` [API key] ## Public · Catalog - `GET /api/v1/public/categories` [API key] - `GET /api/v1/public/items` [API key] - `GET /api/v1/public/modifiers` [API key] ## Public · Inventory - `GET /api/v1/public/inventory` [API key] - `GET /api/v1/public/suppliers` [API key] ## Public · Menu Images - `GET /api/v1/public/menu/{identifier}/images` [API key] ## Public · Orders - `GET /api/v1/public/orders` [API key] - `POST /api/v1/public/orders` [API key] - `GET /api/v1/public/orders/{id}` [API key] ## Purchase Approvals - `POST /api/v1/console/purchase-invoices/approvals/{approvalRequestId}/apply` [API key] - `POST /api/v1/console/purchase-orders/{id}/apply-approval` [API key] - `POST /api/v1/console/purchase-orders/{id}/revert-approval` [API key] ## Purchase Invoices - `GET /api/v1/console/purchase-invoices` [API key] - `POST /api/v1/console/purchase-invoices` [API key] - `GET /api/v1/console/purchase-invoices/{id}` [API key] - `GET /api/v1/console/supplier-returns` [API key] - `POST /api/v1/console/supplier-returns` [API key] - `GET /api/v1/console/supplier-returns/{id}` [API key] ## Purchase Orders - `GET /api/v1/console/purchase-orders` [API key] - `POST /api/v1/console/purchase-orders` [API key] - `DELETE /api/v1/console/purchase-orders/{id}` [API key] - `GET /api/v1/console/purchase-orders/{id}` [API key] - `PUT /api/v1/console/purchase-orders/{id}` [API key] - `POST /api/v1/console/purchase-orders/{id}/cancel` [API key] - `POST /api/v1/console/purchase-orders/{id}/close` [API key] - `POST /api/v1/console/purchase-orders/{id}/submit` [API key] ## Receipts - `GET /api/v1/console/pos/orders/{id}/kitchen-chits` [API key] - `GET /api/v1/console/pos/orders/{id}/receipt` [API key] - `GET /api/v1/console/pos/orders/{id}/receipt/escpos` [API key] ## Receiving Discrepancies - `GET /api/v1/console/receiving-discrepancies` [API key] - `POST /api/v1/console/receiving-discrepancies` [API key] ## Reconciliation - `GET /api/v1/console/cash/reconciliations` [API key] - `POST /api/v1/console/cash/reconciliations` [API key] - `DELETE /api/v1/console/cash/reconciliations/{id}` [API key] - `GET /api/v1/console/cash/reconciliations/{id}` [API key] - `GET /api/v1/console/cash/reconciliations/expected` [API key] ## Recruitment - `GET /api/v1/console/hr/candidates` [API key] - `POST /api/v1/console/hr/candidates` [API key] - `POST /api/v1/console/hr/candidates/{id}/hire` [API key] - `POST /api/v1/console/hr/candidates/{id}/stage` [API key] - `GET /api/v1/console/hr/job-openings` [API key] - `POST /api/v1/console/hr/job-openings` [API key] - `POST /api/v1/console/hr/job-openings/{id}/status` [API key] ## Regions - `GET /api/v1/console/regions` [API key] - `POST /api/v1/console/regions` [API key] - `DELETE /api/v1/console/regions/{id}` [API key] - `PUT /api/v1/console/regions/{id}` [API key] ## Reorder - `POST /api/v1/console/purchase-orders/from-suggestions` [API key] - `GET /api/v1/console/purchase-orders/reorder-suggestions` [API key] ## Report Builder - `GET /api/v1/console/report-builder/datasets` [API key] - `POST /api/v1/console/report-builder/preview` [API key] - `GET /api/v1/console/report-builder/reports` [API key] - `POST /api/v1/console/report-builder/reports` [API key] - `DELETE /api/v1/console/report-builder/reports/{id}` [API key] - `GET /api/v1/console/report-builder/reports/{id}` [API key] - `PUT /api/v1/console/report-builder/reports/{id}` [API key] - `GET /api/v1/console/report-builder/reports/{id}/run` [API key] ## Report Subscriptions - `GET /api/v1/console/report-subscriptions` [API key] - `POST /api/v1/console/report-subscriptions` [API key] - `DELETE /api/v1/console/report-subscriptions/{id}` [API key] - `POST /api/v1/console/report-subscriptions/{id}/activate` [API key] - `POST /api/v1/console/report-subscriptions/{id}/deactivate` [API key] ## Reports - `GET /api/v1/console/reports/{key}` [API key] - `GET /api/v1/console/reports/{key}/export` [API key] - `GET /api/v1/console/reports/catalogue` [API key] ## Sale Invoices - `DELETE /api/v1/console/pos/sale-invoices/{id}` [API key] - `GET /api/v1/console/pos/sale-invoices/{id}` [API key] - `PATCH /api/v1/console/pos/sale-invoices/{id}` [API key] - `POST /api/v1/console/pos/sale-invoices/{id}/restore` [API key] ## Sales Channels - `GET /api/v1/console/pos/channels` [API key] ## Sales Integrity - `GET /api/v1/console/fraud/adjustments` [API key] - `GET /api/v1/console/fraud/comp-void-by-server` [API key] - `GET /api/v1/console/fraud/sales-integrity` [API key] ## Setup - `POST /api/v1/console/setup` [API key] - `GET /api/v1/console/setup/status` [API key] ## Shelf Life - `GET /api/v1/console/inventory/shelf-life` [API key] - `POST /api/v1/console/inventory/shelf-life/propose-waste` [API key] ## Shifts - `GET /api/v1/console/hr/roster` [API key] - `POST /api/v1/console/hr/roster` [API key] - `GET /api/v1/console/hr/shifts` [API key] - `POST /api/v1/console/hr/shifts` [API key] ## Statements - `GET /api/v1/console/accounting/statements/balance-sheet` [API key] - `GET /api/v1/console/accounting/statements/export` [API key] - `GET /api/v1/console/accounting/statements/gl-detail` [API key] - `GET /api/v1/console/accounting/statements/pnl` [API key] - `GET /api/v1/console/accounting/statements/reconciliation` [API key] - `GET /api/v1/console/accounting/statements/trial-balance` [API key] ## Stock Locations - `GET /api/v1/console/inventory/stock-locations` [API key] - `POST /api/v1/console/inventory/stock-locations` [API key] - `DELETE /api/v1/console/inventory/stock-locations/{id}` [API key] - `GET /api/v1/console/inventory/stock-locations/{id}` [API key] - `PUT /api/v1/console/inventory/stock-locations/{id}` [API key] - `GET /api/v1/console/inventory/stock-locations/{id}/stock` [API key] ## Stock Movements - `GET /api/v1/console/inventory/movements` [API key] - `GET /api/v1/console/inventory/movements/{id}` [API key] - `POST /api/v1/console/inventory/movements/adjustments` [API key] ## Subscription - `GET /api/v1/console/subscription` [API key] - `GET /api/v1/console/subscription/notice` [API key] - `GET /api/v1/console/subscription/plans` [API key] ## Supplier Payments - `GET /api/v1/console/suppliers/{id}/payable` [API key] - `GET /api/v1/console/suppliers/{id}/payments` [API key] - `POST /api/v1/console/suppliers/{id}/payments` [API key] - `GET /api/v1/console/suppliers/{id}/statement` [API key] ## Suppliers - `GET /api/v1/console/suppliers` [API key] - `POST /api/v1/console/suppliers` [API key] - `DELETE /api/v1/console/suppliers/{id}` [API key] - `GET /api/v1/console/suppliers/{id}` [API key] - `GET /api/v1/console/suppliers/{id}/items` [API key] - `PUT /api/v1/console/suppliers/{id}/items` [API key] - `PUT /api/v1/console/suppliers/{id}/payment-terms` [API key] ## Tax Codes - `GET /api/v1/console/accounting/tax-codes` [API key] - `POST /api/v1/console/accounting/tax-codes` [API key] - `DELETE /api/v1/console/accounting/tax-codes/{id}` [API key] - `GET /api/v1/console/accounting/tax-codes/{id}` [API key] - `PUT /api/v1/console/accounting/tax-codes/{id}` [API key] - `POST /api/v1/console/accounting/tax-codes/{id}/active` [API key] ## Three Way Match - `POST /api/v1/console/purchase-invoices/{id}/clear-match-exception` [API key] - `GET /api/v1/console/purchase-invoices/{id}/match-lines` [API key] ## Transfer Orders - `GET /api/v1/console/central-kitchen/transfers` [API key] - `POST /api/v1/console/central-kitchen/transfers` [API key] - `DELETE /api/v1/console/central-kitchen/transfers/{id}` [API key] - `GET /api/v1/console/central-kitchen/transfers/{id}` [API key] - `POST /api/v1/console/central-kitchen/transfers/{id}/approve` [API key] - `POST /api/v1/console/central-kitchen/transfers/{id}/cancel` [API key] - `POST /api/v1/console/central-kitchen/transfers/{id}/pick` [API key] - `POST /api/v1/console/central-kitchen/transfers/{id}/post` [API key] - `POST /api/v1/console/central-kitchen/transfers/{id}/receive` [API key] - `POST /api/v1/console/central-kitchen/transfers/{id}/reject` [API key] - `POST /api/v1/console/central-kitchen/transfers/{id}/review` [API key] - `POST /api/v1/console/central-kitchen/transfers/{id}/ship` [API key] - `POST /api/v1/console/central-kitchen/transfers/{id}/submit` [API key] ## Usage Variance - `GET /api/v1/console/inventory/usage-variance` [API key] - `GET /api/v1/console/inventory/usage-variance/export` [API key] ## Users - `GET /api/v1/console/users` [API key] - `POST /api/v1/console/users` [API key] - `DELETE /api/v1/console/users/{id}` [API key] - `GET /api/v1/console/users/{id}` [API key] - `PATCH /api/v1/console/users/{id}` [API key] - `POST /api/v1/console/users/{id}/resend-invite` [API key] - `POST /api/v1/console/users/{id}/reset-password` [API key] - `GET /api/v1/console/users/roles` [API key] ## Vault - `GET /api/v1/console/cash/vault` [API key] - `POST /api/v1/console/cash/vault/adjustments` [API key] - `POST /api/v1/console/cash/vault/deposits` [API key] - `GET /api/v1/console/cash/vault/entries` [API key] - `POST /api/v1/console/cash/vault/withdrawals` [API key] ## Violations - `GET /api/v1/console/hr/violations` [API key] - `POST /api/v1/console/hr/violations` [API key] ## Vocabularies - `GET /api/v1/console/settings/vocabularies` [API key] - `GET /api/v1/console/settings/vocabularies/{vocabulary}` [API key] - `POST /api/v1/console/settings/vocabularies/{vocabulary}` [API key] - `DELETE /api/v1/console/settings/vocabularies/{vocabulary}/{id}` [API key] - `GET /api/v1/console/settings/vocabularies/{vocabulary}/{id}` [API key] - `PATCH /api/v1/console/settings/vocabularies/{vocabulary}/{id}` [API key] - `PUT /api/v1/console/settings/vocabularies/{vocabulary}/{id}` [API key] - `POST /api/v1/console/settings/vocabularies/{vocabulary}/{id}/active` [API key] - `POST /api/v1/console/settings/vocabularies/{vocabulary}/reorder` [API key] ## Webhooks - `GET /api/v1/console/developers/webhook-deliveries` [JWT] - `GET /api/v1/console/developers/webhook-deliveries/{id}` [JWT] - `POST /api/v1/console/developers/webhook-deliveries/{id}/retry` [JWT] - `POST /api/v1/console/developers/webhook-deliveries/retry-failed` [JWT] - `GET /api/v1/console/developers/webhooks` [JWT] - `POST /api/v1/console/developers/webhooks` [JWT] - `DELETE /api/v1/console/developers/webhooks/{id}` [JWT] - `GET /api/v1/console/developers/webhooks/{id}` [JWT] - `PUT /api/v1/console/developers/webhooks/{id}` [JWT] - `POST /api/v1/console/developers/webhooks/{id}/activate` [JWT] - `POST /api/v1/console/developers/webhooks/{id}/deactivate` [JWT] - `GET /api/v1/console/developers/webhooks/{id}/deliveries` [JWT] - `POST /api/v1/console/developers/webhooks/{id}/rotate-secret` [JWT] - `POST /api/v1/console/developers/webhooks/{id}/test` [JWT] - `GET /api/v1/console/developers/webhooks/event-catalog` [JWT] - `GET /api/v1/console/developers/webhooks/event-types` [JWT]