REST, keys, scopes

Your orders, on your own systems

A key, a header and a URL. Orders, products, categories, appointments and services — the same data the dashboard reads.

Included on the Business plan and up

GET /api/v1/orders
# request
curl "https://waveorder.app/api/v1/orders?status=PENDING" \
  -H "Authorization: Bearer wo_live_YOUR_API_KEY"

# 200 OK
{
  "orders": [{
    "id": "507f1f77bcf86cd799439011",
    "orderNumber": "WO-1042",
    "status": "PENDING",
    "type": "DELIVERY",
    "total": 72,
    "customerName": "Ana Silva"
  }],
  "pagination": { "page": 1, "limit": 50, "total": 1, "pages": 1 }
}

RESTful design

Clean, predictable URLs and standard HTTP methods. Easy to understand and integrate.

Secure

API key authentication with granular scopes. All requests over HTTPS.

Rate limited

60 requests per minute per key. Fair usage ensures reliability for all.

Quick start

Get started in minutes with our simple REST API.

1

Generate an API key

Go to your admin dashboard → API Access → Create Key

2

Make your first request

# For Restaurants/Retail:
curl -X GET "https://waveorder.app/api/v1/products" \\
  -H "Authorization: Bearer wo_live_YOUR_API_KEY"

# For Salons:
curl -X GET "https://waveorder.app/api/v1/services" \\
  -H "Authorization: Bearer wo_live_YOUR_API_KEY"
3

Get JSON response

# Restaurants/Retail Response:
{
  "products": [
    {
      "id": "507f1f77bcf86cd799439011",
      "name": "Margherita Pizza",
      "price": 12.99,
      "stock": 50,
      "isActive": true
    }
  ],
  "pagination": {
    "page": 1,
    "limit": 50,
    "total": 125,
    "pages": 3
  }
}

# Salons Response:
{
  "services": [
    {
      "id": "507f1f77bcf86cd799439011",
      "name": "Classic Haircut",
      "price": 20.00,
      "serviceDuration": 30,
      "requiresAppointment": true,
      "isActive": true
    }
  ],
  "pagination": {
    "page": 1,
    "limit": 50,
    "total": 25,
    "pages": 1
  }
}

Authentication

Every request carries an API key. Send it one of two ways.

A key belongs to one business and carries its plan and its scopes. It is checked on every call, so the same key cannot reach another tenant's data.

Authorization header

Authorization: Bearer wo_live_YOUR_API_KEY

or

X-API-Key header

X-API-Key: wo_live_YOUR_API_KEY

What the key can reach

Scoped to one business

Checked on every request.

A key belongs to a business, carries its plan and its scopes, and is checked at runtime on every call. There is no account-wide key and nothing crosses a tenant boundary — which is why the reference is public and the keys are not.

API endpoints

Base URL: https://waveorder.app/api/v1

Restaurant and retail stores use Products and Orders; salon and services stores use Services and Appointments. Every endpoint, parameter, request body, and response — with a live “try it” console — is in the interactive reference, generated straight from the API so it never goes stale.

Rate limiting

API requests are limited to 60 requests per minute per API key.

HeaderDescription
X-RateLimit-LimitMaximum requests per window (60)
X-RateLimit-RemainingRemaining requests in current window
X-RateLimit-ResetSeconds until rate limit resets
Retry-AfterSeconds to wait (only on 429 response)

Error handling

The API returns standard HTTP status codes and JSON error responses.

CodeMeaning
200Success
201Created (for POST requests)
400Bad Request — Invalid parameters
401Unauthorized — Missing or invalid API key
403Forbidden — Missing scope, wrong business type, or plan without API access
404Not Found — Resource doesn't exist
429Too Many Requests — Rate limit exceeded
500Internal Server Error

Example error response:

{
  "error": "Missing required scope: products:write"
}

Ready to build?

API access is included on the Business plan and up. Talk to our team to get set up and start integrating.

API Documentation | WaveOrder