Developers
Build on the NexDine platform
Scoped API keys, a versioned REST surface, and HMAC-signed webhooks. Keys are created by venue admins under Settings → Developers.
Authentication
Every request is authenticated with a tenant-scoped API key sent as a bearer token. Keys are hashed at rest, individually rate-limited, and can be revoked at any time. Responses use a consistent envelope with cursor pagination.
curl https://nexdine.app/api/v1/orders?limit=5 \
-H "Authorization: Bearer nxd_live_..."{
"success": true,
"data": [ { "id": "...", "status": "COMPLETED", "total_cents": 8450, "items": [ ... ] } ],
"meta": { "next_cursor": "eyJ0IjoiMjAyNi0uLi4ifQ" }
}Endpoints
- GET
/api/v1/ordersScope
read:ordersList orders, newest first, with line items.
Query parameters
limit- Page size, 1-100 (default 25).
cursor- Opaque cursor from meta.next_cursor.
status- Filter by order status (e.g. COMPLETED).
created_after- ISO 8601 timestamp lower bound.
- GET
/api/v1/bookingsScope
read:bookingsList bookings, newest first.
Query parameters
limit- Page size, 1-100 (default 25).
cursor- Opaque cursor from meta.next_cursor.
status- Filter by booking status (e.g. CONFIRMED).
reservation_from- ISO 8601 reservation-time lower bound.
reservation_to- ISO 8601 reservation-time upper bound.
- POST
/api/v1/bookingsScope
write:bookingsCreate a booking. Availability rules, booking horizon, and table allocation run exactly as for the venue's own booking widget.
Body fields
guest_namerequired- Guest full name (2-150 chars).
guest_phonerequired- Phone number in E.164 format.
guest_countrequired- Party size, 1-50.
reservation_timerequired- ISO 8601 datetime.
notes- Free-text notes (max 500 chars).
- GET
/api/v1/bookings/{id}Scope
read:bookingsFetch a single booking by id.
- PATCH
/api/v1/bookings/{id}Scope
write:bookingsUpdate booking details (guest count, reservation time, notes) and/or status. Table capacity and overlap rules apply exactly as in the dashboard.
Body fields
guest_count- Party size, 1-50.
reservation_time- ISO 8601 datetime.
notes- Free-text notes, null to clear.
status- PENDING | CONFIRMED | ARRIVED | SEATED | COMPLETED | CANCELLED | NO_SHOW.
- DELETE
/api/v1/bookings/{id}Scope
write:bookingsCancel a booking (status CANCELLED) with staff semantics. Deposit refunds are not automatic. Issue them via the dashboard.
- GET
/api/v1/orders/{id}Scope
read:ordersFetch a single order with its items.
- PATCH
/api/v1/orders/{id}Scope
write:ordersAdvance or change an order's lifecycle status. Runs the same history, courier, stock and realtime side effects as the staff flow.
Body fields
statusrequired- RECEIVED | CONFIRMED | PREPARING | READY | SERVED_COLLECTED_DELIVERED | COMPLETED | CANCELLED | VOIDED.
- GET
/api/v1/customersScope
read:customersList customer profiles, newest first.
Query parameters
limit- Page size, 1-100 (default 25).
cursor- Opaque cursor from meta.next_cursor.
search- Match on name, email, or phone.
- GET
/api/v1/inventoryScope
read:inventoryList inventory items with stock levels and par thresholds.
Query parameters
limit- Page size, 1-100 (default 25).
cursor- Opaque cursor from meta.next_cursor.
low_stock- Set to true to return only items below par.
Webhooks
Register HTTPS endpoints per event under Settings → Developers. Deliveries are JSON POSTs signed with your endpoint's secret and retried with exponential backoff for up to eight attempts. Verify the signature by computing HMAC-SHA256 over `${t}.${body}` and comparing it to the v1 value.
X-NexDine-Event: order.created
X-NexDine-Delivery: <delivery uuid>
X-NexDine-Signature: t=1789000000,v1=<hex hmac-sha256 of "t.body" with your signing secret>Events
order.createdA new order was recorded on any channel.booking.createdA new booking was created (any source).booking.updatedBooking details or status changed.payment.capturedAn order was fully paid (card or cash).inventory.low_stockAn inventory item dropped to or below its par threshold.