Information
- OpenAPI version:
3.1.0
Orders, routing and invoicing for the bottled gas trade. This spec is the contract for the web app, the driver app and the WhatsApp agent.
Register and sign in under /auth, which sets a session cookie. Every endpoint described here needs that session.
A person can belong to several tenants with a different role in each. Tenant-scoped endpoints read X-Tenant-Id, and the header only works for a tenant the caller is a member of. GET /me lists them.
Every tenant-scoped endpoint names the scope it needs, as resource:action. A session carries the scopes its role allows. An API key carries the scopes it was granted, which is never more than the person who created it could grant. A caller without the scope is refused with missing_scope, whichever way it arrived.
Set by signing in under /auth. Used by our own web and driver apps.
Security scheme type: apiKey
Cookie parameter name: bottle.session_token
A key created by an owner or admin of the business, sent as Authorization: Bearer <key>. Carries only the scopes it was granted.
Security scheme type: http
The console: Bottle’s own staff, signed in as themselves with two-step sign-in on. The scope named is the least console role the route needs. Never a key.
Security scheme type: apiKey
Cookie parameter name: bottle.session_token
Which of your tenants the request is for. Rejected unless you are a member of it.
Security scheme type: apiKey
Header parameter name: X-Tenant-Id