Download OpenAPI specification:
Consumer plane. This API serves a shop's own customers (a shop-branded consumer app) — it is not the merchant integration API (
sk_keys, see Loyalty/Delivery above) and not the first-party fulfillment API. Auth is a publishable key (X-Publishable-Key: pk_test_…) plus the customer's bearer token; the shop is derived server-side from the key — a client shop claim is never trusted. Live on the public sandbox (sandbox-api.doehpos.com); the production consumer plane is not yet enabled.
Consumer plane (CONTRACT §15), served by the edge gateway for a shop's OWN customers — the doeh-shop-app audience, not merchant integrations. Every request carries a publishable key (identifies the shop + consumer app; grants nothing alone) AND a customer bearer token; the edge resolves both with Core and signs the (shop, customer) pair. The shop is derived from the key — a client-supplied shop claim is never trusted. Slice 1 is read-only loyalty. Customer identity is issued by the DOEH Identity Platform: OAuth 2.1 authorization-code + PKCE with hosted login and explicit consent at https://auth.doehpos.com (see the Authentication guide at /authentication/ for the full flow and error semantics).
| X-Publishable-Key required | string Publishable consumer app key (pk_…). Identifies the shop; grants nothing alone. |
| Trace-Id | string |
{- "ok": true,
- "settings": {
- "shop_id": 0,
- "program_active": true,
- "earn_rate": "string",
- "currency": "string"
}
}| X-Publishable-Key required | string Publishable consumer app key (pk_…). Identifies the shop; grants nothing alone. |
| Trace-Id | string |
{- "ok": true,
- "balance": 0
}| X-Publishable-Key required | string Publishable consumer app key (pk_…). Identifies the shop; grants nothing alone. |
| Trace-Id | string |
{- "ok": true,
- "transactions": [
- {
- "id": "string",
- "type": "earn",
- "points": 0,
- "reason": "string",
- "at": "2019-08-24T14:15:22Z"
}
]
}NOT idempotent and never retried by the platform — do not blindly re-submit on a transport error; re-check the balance first. An idempotency guarantee may be added later as an additive extension.
| X-Publishable-Key required | string Publishable consumer app key (pk_…). Identifies the shop; grants nothing alone. |
| Trace-Id | string |
| points required | integer >= 1 Whole points to redeem (never a decimal). |
{- "points": 1
}{- "status": "success",
- "data": { }
}