← Developer home

Doeh POS — Consumer Mobile API (1.0.0)

Download OpenAPI specification:

Consumer plane. This API serves a shop's own customers (a shop-branded consumer app) — it is not the merchant integration API (sk_ keys, see Loyalty/Delivery above) and not the first-party fulfillment API. Auth is a publishable key (X-Publishable-Key: pk_test_…) plus the customer's bearer token; the shop is derived server-side from the key — a client shop claim is never trusted. Live on the public sandbox (sandbox-api.doehpos.com); the production consumer plane is not yet enabled.

Consumer plane (CONTRACT §15), served by the edge gateway for a shop's OWN customers — the doeh-shop-app audience, not merchant integrations. Every request carries a publishable key (identifies the shop + consumer app; grants nothing alone) AND a customer bearer token; the edge resolves both with Core and signs the (shop, customer) pair. The shop is derived from the key — a client-supplied shop claim is never trusted. Slice 1 is read-only loyalty. Customer identity is issued by the DOEH Identity Platform: OAuth 2.1 authorization-code + PKCE with hosted login and explicit consent at https://auth.doehpos.com (see the Authentication guide at /authentication/ for the full flow and error semantics).

Mobile Loyalty

Read the shop's loyalty program settings

Authorizations:
ConsumerAuth
header Parameters
X-Publishable-Key
required
string

Publishable consumer app key (pk_…). Identifies the shop; grants nothing alone.

Trace-Id
string

Responses

Response samples

Content type
application/json
{
  • "ok": true,
  • "settings": {
    }
}

Read the authenticated customer's points balance

Authorizations:
ConsumerAuth
header Parameters
X-Publishable-Key
required
string

Publishable consumer app key (pk_…). Identifies the shop; grants nothing alone.

Trace-Id
string

Responses

Response samples

Content type
application/json
{
  • "ok": true,
  • "balance": 0
}

Read the authenticated customer's recent loyalty transactions

Authorizations:
ConsumerAuth
header Parameters
X-Publishable-Key
required
string

Publishable consumer app key (pk_…). Identifies the shop; grants nothing alone.

Trace-Id
string

Responses

Response samples

Content type
application/json
{
  • "ok": true,
  • "transactions": [
    ]
}

Redeem the authenticated customer's points for a coupon

NOT idempotent and never retried by the platform — do not blindly re-submit on a transport error; re-check the balance first. An idempotency guarantee may be added later as an additive extension.

Authorizations:
ConsumerAuth
header Parameters
X-Publishable-Key
required
string

Publishable consumer app key (pk_…). Identifies the shop; grants nothing alone.

Trace-Id
string
Request Body schema: application/json
required
points
required
integer >= 1

Whole points to redeem (never a decimal).

Responses

Request samples

Content type
application/json
{
  • "points": 1
}

Response samples

Content type
application/json
{
  • "status": "success",
  • "data": { }
}