Skip to content

Overview

Orders, routing and invoicing for the bottled gas trade. This spec is the contract for the web app, the driver app and the WhatsApp agent.

Authentication

Register and sign in under /auth, which sets a session cookie. Every endpoint described here needs that session.

Tenants

A person can belong to several tenants with a different role in each. Tenant-scoped endpoints read X-Tenant-Id, and the header only works for a tenant the caller is a member of. GET /me lists them.

Permissions

Every tenant-scoped endpoint names the scope it needs, as resource:action. A session carries the scopes its role allows. An API key carries the scopes it was granted, which is never more than the person who created it could grant. A caller without the scope is refused with missing_scope, whichever way it arrived.

Information

  • OpenAPI version: 3.1.0

Set by signing in under /auth. Used by our own web and driver apps.

Security scheme type: apiKey

Cookie parameter name: bottle.session_token

A key created by an owner or admin of the business, sent as Authorization: Bearer <key>. Carries only the scopes it was granted.

Security scheme type: http

The console: Bottle’s own staff, signed in as themselves with two-step sign-in on. The scope named is the least console role the route needs. Never a key.

Security scheme type: apiKey

Cookie parameter name: bottle.session_token

Which of your tenants the request is for. Rejected unless you are a member of it.

Security scheme type: apiKey

Header parameter name: X-Tenant-Id