Developer API: the full reference
Every merchant endpoint is open: integrate one scenario (e.g. sync orders into your ERP) or build your own front end entirely. All endpoints below, searchable; responses are authoritative over docs.
Conventions
All endpoints are HTTPS POST with an application/json body (some also accept x-www-form-urlencoded).
Uniform envelope: {"code": 200, "msg": "ok", "data": {...}}. code 200 means success; any other code is a business error while HTTP status stays 200.
Money is always a two-decimal string (e.g. "88.00"). Timestamps use YYYY-MM-DD HH:mm:ss; a sale is dated by its completion time.
| code | Meaning |
|---|---|
| 200 | Success |
| 100 | Missing or invalid parameter |
| 101 | Not logged in / token expired |
| 102 | No permission |
| 429 | Rate limited, retry later |
| 500 | Server error (please include out_trade_no / time when reporting) |
Authentication
Successful logins issue a JWT as Cookie: token, valid 30 days with sliding renewal; send it back on every request (browsers do this automatically; server-side integrations should persist and replay it).
Customers log in via WeChat or SMS; the back office and POS use staff accounts. The two token types are not interchangeable. Public read endpoints under /api/login, /api/payment, /api/banner, /api/menu, /api/store, /api/cart work anonymously; everything else returns code 101 without a token.
Sandbox: https://orderstaging.teamotto.net (demo store Pizza King Mong Kok, store_id=13; request demo credentials from us).
Order Status Quick Reference
| status | Meaning |
|---|---|
| 0 | Awaiting payment |
| 1 / 10 / 11 / 21 | Confirmed, preparing (11 dine-in, 21 takeaway) |
| 22 | Ready for pickup (includes number_pick_up) |
| 12 / 23 / 24 / 25 | Completed (table cleared / pickup verified) |
| 41 / 42 | Cancelled / voided |
Payment channels: 1 WeChat Pay, 2 QFPay, 91 cash, 92 Octopus, 93 FPS, 94 card. After checkout, poll Order/getInfoByOutTradeNo with out_trade_no (4s interval recommended).
Authentication登入認證
/api/Login/postLoginForWeChatCustomer WeChat login (miniprogram code to openid).codeRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Login/postLoginForPhoneCustomer login via phone SMS code.phone_codephone_numberRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Login/postLogoutLog out and clear the token.(none explicit; session and body apply)
Request: HTTPS POST; uniform {code, msg, data} envelope.
/api/Login/postLoginForTestTest-environment login (staging only).user_idRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Login/postLoginForStaffStaff / merchant back-office login. Issues a JWT cookie (token), valid 30 days with sliding renewal.usernamepasswordbrandRequest: HTTPS POST; uniform {code, msg, data} envelope.
Stores & Tables門店與枱位
/api/Store/getBrandByHostForClientResolve brand info by host (customer entry).(none explicit; session and body apply)
Request: HTTPS POST; uniform {code, msg, data} envelope.
/api/Store/getInfoForStaffRead the current staff's store profile.(none explicit; session and body apply)
Request: HTTPS POST; uniform {code, msg, data} envelope.
/api/Store/postEditForStaffUpdate store profile (open status, notice, takeaway settings).(none explicit; session and body apply)
Request: HTTPS POST; uniform {code, msg, data} envelope.
/api/Store/getInfoByIdRead a store's public profile.store_idRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Store/getListForPagePaginated store list (geo sort, keyword), for chain overview and customer store picker.pagerowskeywordbrand_idlatitudelongitudesort_typeRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Store/getLocationRead store geolocation.(none explicit; session and body apply)
Request: HTTPS POST; uniform {code, msg, data} envelope.
/api/Store/getSeatListForPageForStaffPaginated table (seat) list.pagerowskeywordRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Store/getSeatListAllForStaffAll seats, unfiltered.(none explicit; session and body apply)
Request: HTTPS POST; uniform {code, msg, data} envelope.
/api/Store/postSeatAddMultipleForStaffAdd seats in batch.array_listRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Store/postSeatDeleteForStaffDelete a seat.store_seat_idRequest: HTTPS POST; uniform {code, msg, data} envelope.
Banners橫額廣告
/api/Banner/getListAllByStoreIdRead store banners by position.store_idpositionRequest: HTTPS POST; uniform {code, msg, data} envelope.
Cart購物車
/api/Cart/getListAllRead cart by store and seat.store_idnumber_seatRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Cart/postEditAdd or update a cart line.cart_idRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Cart/postDeleteDelete a cart line.cart_idRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Cart/postDeleteAllClear the cart.(none explicit; session and body apply)
Request: HTTPS POST; uniform {code, msg, data} envelope.
Orders訂單
/api/Order/getInfoByOutTradeNoGet order by out_trade_no (customer status polling).out_trade_noRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Order/getInfoForStatisticForStaffSales statistics overview by day.(none explicit; session and body apply)
Request: HTTPS POST; uniform {code, msg, data} envelope.
/api/Order/getInfoForStatisticTwoForStaffStatistics by meal period / channel.(none explicit; session and body apply)
Request: HTTPS POST; uniform {code, msg, data} envelope.
/api/Order/getInfoForStatisticThreeForStaffStatistics by top-selling items.dateRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Order/getInfoForStatisticChartForStaffChart data for a date range and channel.rangechanneldateRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Order/getInfoByOutTradeNoForStaffStaff-side order detail by out_trade_no.out_trade_noRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Order/getListForPagePaginated orders (customer order history).pagerowskeywordstore_idtypestatusis_pendingRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Order/getListForPageForStaffStore order list with status / period / time filters.pagerowskeywordtypestatusis_pendingstart_timeend_timeRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Order/postAddForUserCustomer checkout (dine-in or takeaway; returns out_trade_no for the cashier).array_itemRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Order/postAddForStaffStaff-side order creation (POS / tablet).array_itemRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Order/postSyncOfflineForStaffDescription in progress.client_uuidplaced_atpayment_methodpaid_amountarray_itemRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Order/postModifyForPaidForStaffMark order paid for offline methods (cash, Octopus, FPS).out_trade_nopayment_methodpaid_amountRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Order/getTodayLiveForStaffToday's live operations feed for big-screen / dashboard.(none explicit; session and body apply)
Request: HTTPS POST; uniform {code, msg, data} envelope.
/api/Order/getAiInsightForStaffAI business insight summary.(none explicit; session and body apply)
Request: HTTPS POST; uniform {code, msg, data} envelope.
/api/Order/postModifyForCancelForStaffCancel or void an order with reason.out_trade_nocancel_reasonRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Order/postModifyForCompletePackForStaffMark takeaway packed: enters ready-for-pickup with pickup number.out_trade_nonumber_pick_upRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Order/postScanResolveForStaffScan resolver (item-fire / pickup codes, tolerant of dropped chars).scan_textRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Order/postPrintForStaffManually reprint receipt / kitchen ticket.out_trade_noRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Order/postModifyForItemRefundForStaffRefund a single item.order_item_idquantityrefund_reasonRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Order/postModifyForSeatClearedForStaffMark table cleared (order becomes completed).out_trade_noRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Order/postItemModifyForProcessedForStaffMark one item processed (KDS item-level firing).order_item_idorder_item_combo_idRequest: HTTPS POST; uniform {code, msg, data} envelope.
Payment Callbacks支付回調
/api/Payment/notifyWeChatPayGlobalWeChat Pay server callback (invoked by the payment gateway only).(none explicit; session and body apply)
Request: HTTPS POST; uniform {code, msg, data} envelope.
/api/Payment/notifyQFPayGlobalQFPay server callback.(none explicit; session and body apply)
Request: HTTPS POST; uniform {code, msg, data} envelope.
Payment Settings支付設置
/api/PaymentConfig/getForStaffRead store payment config (secrets masked).(none explicit; session and body apply)
Request: HTTPS POST; uniform {code, msg, data} envelope.
/api/PaymentConfig/postForStaffSave store payment config (QFPay merchant params).qfpay_mchidqfpay_codeqfpay_keyqfpay_currencyqfpay_statusRequest: HTTPS POST; uniform {code, msg, data} envelope.
Printers打印機
/api/Printer/getInfoByIdForStaffPrinter detail.printer_idRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Printer/getListForPageForStaffPaginated printers (type 1 front receipt, 2 kitchen ticket).pagerowskeywordtypestatusRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Printer/postEditForStaffCreate or update a printer (cloud params, item binding).printer_idRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Printer/postDeleteForStaffDelete a printer.printer_idRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Printer/getCloudDefaultsForStaffCloud printer defaults and templates.(none explicit; session and body apply)
Request: HTTPS POST; uniform {code, msg, data} envelope.
/api/Printer/getCloudDevicesForStaffQuery online devices on the cloud printer platform.(none explicit; session and body apply)
Request: HTTPS POST; uniform {code, msg, data} envelope.
/api/Printer/postTestPrintForStaffSend a test print job.printer_idRequest: HTTPS POST; uniform {code, msg, data} envelope.
Staff員工
/api/Staff/getInfoForStaffCurrent staff profile.(none explicit; session and body apply)
Request: HTTPS POST; uniform {code, msg, data} envelope.
/api/Staff/getInfoByIdForStaffRead staff by id.staff_idRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Staff/getListForPageForStaffPaginated staff list.pagerowskeywordstatusRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Staff/postEditForStaffCreate or update staff (role, store assignment).staff_idRequest: HTTPS POST; uniform {code, msg, data} envelope.
/api/Staff/postModifyPasswordForStaffDescription in progress.old_passwordnew_passwordRequest: HTTPS POST; uniform {code, msg, data} envelope.
Customers顧客
/api/User/getInfoCurrent customer profile (points, tags).(none explicit; session and body apply)
Request: HTTPS POST; uniform {code, msg, data} envelope.
/api/User/getStoreListForPageForOrderStores the customer can order from.pagerowsRequest: HTTPS POST; uniform {code, msg, data} envelope.
Upload文件上傳
/api/Upload/uploadImageForStaffUpload an image (menu/store photos; auto-compressed with thumbnail).(none explicit; session and body apply)
Request: HTTPS POST; uniform {code, msg, data} envelope.
Your integration plan, in 30 minutes
Tell us your current system and the data you want in sync; we will give you the plan (and a quote if custom work is involved).
Book a technical call