openapi: 3.2.0 info: title: Bolt Stores API version: '1.0' description: 'Partner API for grocery and retail stores integrating warehouses and product information management (PIM) systems with Bolt Food / Bolt Market delivery - import and edit product catalogs, prices, and discount price lists, manage category trees, section layouts, options, fees, timetables, menu drafts and publishing, update stock quantities, and fulfill orders picked by item. Bolt also calls partner-hosted webhooks for order and courier lifecycle events. Access is partner-gated: an integrator ID and HMAC secret are issued by Bolt when a test account is created. This document is an API Evangelist summary of the official Redocly-published spec at developer.bolt.eu - the endpoint paths, methods, server, webhooks, and authentication are taken verbatim from the upstream spec, while request and response schemas are summarized rather than reproduced in full.' contact: url: https://developer.bolt.eu/ license: name: Bolt Terms and Conditions url: https://bolt.eu/en/legal/ x-endpoints-modeled: false x-schemas-summarized: true x-source: 'https://developer.bolt.eu/stores/main/ (upstream spec: https://developer.bolt.eu/versions/98.0.0/docs/stores/main.yaml)' servers: - url: https://node.bolt.eu/delivery-provider-pos description: Production security: - boltHmacSignature: [] tags: - name: Bolt Stores API paths: {} webhooks: sendNewOrder: post: operationId: webhook-sendNewOrder summary: Bolt sends a new order to the partner-hosted endpoint for acceptance. description: Outbound webhook - Bolt POSTs to a partner-hosted endpoint. Documented upstream at https://developer.bolt.eu/stores/main/. requestBody: content: application/json: schema: $ref: '#/components/schemas/SummarizedRequest' responses: '200': description: Partner acknowledges the event. tags: - Bolt Stores API sendCancelOrder: post: operationId: webhook-sendCancelOrder summary: Bolt notifies the partner-hosted endpoint that an order was cancelled. description: Outbound webhook - Bolt POSTs to a partner-hosted endpoint. Documented upstream at https://developer.bolt.eu/stores/main/. requestBody: content: application/json: schema: $ref: '#/components/schemas/SummarizedRequest' responses: '200': description: Partner acknowledges the event. tags: - Bolt Stores API sendOrderUpdate: post: operationId: webhook-sendOrderUpdate summary: Bolt sends order state updates to the partner-hosted endpoint. description: Outbound webhook - Bolt POSTs to a partner-hosted endpoint. Documented upstream at https://developer.bolt.eu/stores/main/. requestBody: content: application/json: schema: $ref: '#/components/schemas/SummarizedRequest' responses: '200': description: Partner acknowledges the event. tags: - Bolt Stores API sendProviderStatus: post: operationId: webhook-sendProviderStatus summary: Bolt notifies the partner-hosted endpoint of provider (store) status changes. description: Outbound webhook - Bolt POSTs to a partner-hosted endpoint. Documented upstream at https://developer.bolt.eu/stores/main/. requestBody: content: application/json: schema: $ref: '#/components/schemas/SummarizedRequest' responses: '200': description: Partner acknowledges the event. tags: - Bolt Stores API sendCourierDetails: post: operationId: webhook-sendCourierDetails summary: Bolt sends courier details for an order to the partner-hosted endpoint. description: Outbound webhook - Bolt POSTs to a partner-hosted endpoint. Documented upstream at https://developer.bolt.eu/stores/main/. requestBody: content: application/json: schema: $ref: '#/components/schemas/SummarizedRequest' responses: '200': description: Partner acknowledges the event. tags: - Bolt Stores API courierPickedUpOrder: post: operationId: webhook-courierPickedUpOrder summary: Bolt notifies the partner-hosted endpoint that the courier picked up the order. description: Outbound webhook - Bolt POSTs to a partner-hosted endpoint. Documented upstream at https://developer.bolt.eu/stores/main/. requestBody: content: application/json: schema: $ref: '#/components/schemas/SummarizedRequest' responses: '200': description: Partner acknowledges the event. tags: - Bolt Stores API components: schemas: SummarizedRequest: type: object description: Request body summarized - see the official Bolt developer portal for the full documented schema of each operation. additionalProperties: true securitySchemes: boltHmacSignature: type: apiKey in: header name: x-external-integrator-id description: Partner-gated HMAC request signing. Every request carries the integrator ID in `x-external-integrator-id` plus a `x-server-authorization-hmac-sha256` header containing the base64-encoded HMAC-SHA256 signature of the raw payload, computed with a secret key issued by Bolt. Webhook calls from Bolt to the partner authenticate with Basic auth or a partner-hosted identity server issuing bearer tokens. externalDocs: description: Bolt Stores API reference on the Bolt developer portal url: https://developer.bolt.eu/stores/main/