openapi: 3.0.0 info: version: 1.1.1 title: On Demand Rider Authentication Proofs API x-logo: url: data:image/svg+xml,%3Csvg width='173' height='28' xmlns='http://www.w3.org/2000/svg'%3E%3Cg transform='translate(-64 -15)' fill='none' fill-rule='evenodd'%3E%3Cpath d='M0 0h1350v60H0z'%3E%3C/path%3E%3Cpath d='M0 0h1350v60H0z'%3E%3C/path%3E%3Cg transform='translate(64 15)' fill='%23D61F26'%3E%3Cpath d='M32.18 13.383l-.021.012-3.754 1.531-.115.053-.915 4.18c-.061.143-.244.177-.367.058l-2.735-3.234-.013-.01-15.423 6.618a.103.103 0 01-.104-.176l13.333-9.98-1.687-3.852c-.084-.175.071-.362.277-.31h.002l4.086 1.006 3.172-2.823c.137-.107.323-.03.358.14l.31 4.241 3.658 2.141c.157.1.134.332-.062.405zM30.316 1.258C25.582-.6 20.376.795 17.164 4.365L4.63 17.793c-.169.181-.09.408.115.438l3.34.205c.267.017.3.247.166.404L.086 27.646c-.142.152.03.392.224.332l11.656-3.683c.246-.085.436.135.332.328l-1.56 2.756c-.08.157.071.372.267.358l16.804-3.743c4.015-.636 7.6-3.316 9.193-7.374 2.4-6.09-.598-12.967-6.686-15.362z'%3E%3C/path%3E%3Cpath d='M75.362 21.69h-3.829L74.53 7.658l4.176-1.535-3.343 15.565'%3E%3C/path%3E%3Cpath d='M67.138 13.653c-.917 0-1.444.759-1.658 1.638 1.813 0 2.362-.566 2.362-1.036 0-.33-.295-.602-.704-.602m-2.087 4.096c-.02.096-.04.274-.04.37 0 .625.428.84 1.562.84 1.013 0 2.456-.255 3.297-.546v2.868c-1.073.39-2.753.603-4.1.603-3.16 0-4.682-.859-4.682-3.725 0-2.814 1.307-7.201 6.344-7.201 3.198 0 4.153 1.445 4.153 2.968 0 1.97-1.696 3.647-6.534 3.823'%3E%3C/path%3E%3Cpath d='M82.316 10.455c-1.305 0-2.145-.839-2.145-1.99 0-1.503 1.054-2.341 2.359-2.341 1.328 0 2.148.838 2.148 1.97 0 1.522-1.034 2.361-2.362 2.361'%3E%3C/path%3E%3Cpath d='M79.63 11.31h3.94l-1.992 10.224h-3.98L79 14.354'%3E%3C/path%3E%3Cpath d='M94.925 11.31c-1.367 3.435-2.87 6.79-4.78 10.224h-4.88c-.623-3.24-.898-6.654-.818-10.224h3.981a47.373 47.373 0 00.036 4.994c.021.43.061.838.099 1.251h.022c.174-.413.368-.82.545-1.251.682-1.68 1.306-3.51 1.777-4.994h4.018'%3E%3C/path%3E%3Cpath d='M100.252 13.653c-.915 0-1.445.759-1.661 1.638 1.817 0 2.363-.566 2.363-1.036 0-.33-.29-.602-.702-.602m-2.086 4.096a2.33 2.33 0 00-.042.37c0 .625.431.84 1.561.84 1.016 0 2.46-.255 3.299-.546v2.868c-1.074.39-2.752.603-4.097.603-3.163 0-4.684-.859-4.684-3.725 0-2.814 1.306-7.201 6.341-7.201 3.2 0 4.155 1.445 4.155 2.968 0 1.97-1.694 3.647-6.533 3.823'%3E%3C/path%3E%3Cpath d='M112.351 14.92a4.396 4.396 0 00-.957-.12c-.879 0-1.581.88-1.895 2.5l-.816 4.235H104.7l1.993-10.224h2.987l.096 1.363c.916-1.13 1.64-1.716 2.752-1.716.506 0 .78.039.915.078l-1.091 3.883'%3E%3C/path%3E%3Cpath d='M124.799 11.31c-1.758 4.567-3.318 7.902-4.88 10.207-2.262 3.376-4.254 4.157-6.304 4.157-.605 0-1.247-.16-1.561-.314l.626-2.947h1.366c.683 0 .974-.275 1.424-.879-.761-2.75-1.133-6.594-1.094-10.224h4.002a44.95 44.95 0 00.039 4.936c.02.448.056.878.095 1.309h.02c.177-.413.37-.82.547-1.27a50.015 50.015 0 001.736-4.975h3.984'%3E%3C/path%3E%3Cpath d='M140.1 21.534h-4.2l.997-5.153h-3.553l-.997 5.153h-4.192l2.652-13.62h4.197l-.955 4.86h3.551l.957-4.86h4.193l-2.651 13.62'%3E%3C/path%3E%3Cpath d='M148.37 13.653c-.918 0-1.442.759-1.658 1.638 1.815 0 2.364-.566 2.364-1.036 0-.33-.296-.602-.706-.602m-2.088 4.096a2.32 2.32 0 00-.037.37c0 .625.43.84 1.559.84 1.016 0 2.46-.255 3.299-.546v2.868c-1.073.39-2.752.603-4.1.603-3.16 0-4.682-.859-4.682-3.725 0-2.814 1.307-7.201 6.342-7.201 3.2 0 4.158 1.445 4.158 2.968 0 1.97-1.7 3.647-6.539 3.823'%3E%3C/path%3E%3Cpath d='M160.467 14.92a4.333 4.333 0 00-.954-.12c-.877 0-1.581.88-1.893 2.5l-.82 4.235h-3.979l1.988-10.224h2.985l.1 1.363c.916-1.13 1.637-1.716 2.748-1.716.51 0 .782.039.92.078l-1.095 3.883'%3E%3C/path%3E%3Cpath d='M167.006 14.1c-1.6 0-2.03 2.44-2.03 3.533 0 .877.37 1.13 1.095 1.13 1.577 0 1.988-2.44 1.988-3.55 0-.858-.35-1.113-1.053-1.113m-1.485 7.784c-3.102 0-4.622-1.327-4.622-3.98 0-2.947 1.462-6.946 6.615-6.946 3.084 0 4.624 1.366 4.624 3.982 0 3.005-1.464 6.944-6.617 6.944'%3E%3C/path%3E%3Cpath d='M52.543 18.294h-.781l1.404-7.182h1.095c1.657 0 2.262.98 2.262 2.323 0 2.715-1.504 4.86-3.98 4.86m3.719-6.928l2.652-2.545c-1.035-.623-2.455-.908-4.227-.908h-5.073l-2.651 13.621h5.289c6.144 0 8.601-4.293 8.601-8.76 0-1.161-.25-2.09-.732-2.81l-3.86 1.402'%3E%3C/path%3E%3C/g%3E%3C/g%3E%3C/svg%3E altText: Delivery Hero backgroundColor: '#FFFFFF' description: "# About\nThe On Demand Rider (ODR) API provides system-to-system integration to facilitate on-demand courier delivery service requests.\nEach integration is scoped as a specific Brand using a ClientID.\nEach delivery request will be called an Order.\nThe ODR API is supporting the following products:\n\n
\n \"Glovo\n \"Gostation\"\n \"Talabat\n \"Foody\"\n \"efood\"\n \"pandago\"\n \"foodora\n
\n\n\n## On Demand Concepts\n\n### Client\nA Client represents a **single integration for a specific Brand** and acts as the **\"parent vendor\"**. It contains high-level information such as:\n* Customer's known name of the Brand/Branch\n* General Address of the Brand/Branch that includes Latitude and Longitude.\n\n### Outlets\nOutlets are **the individual branches or vendor locations tied to the Client**. Each outlet represents the specific pickup location for deliveries. In ODR, if a client has **multiple locations**, they **can all be configured under the same parent vendor**.\nOutlet details include:\n* Branch vendor name\n* Address of outlet with latitude and longitude.\n \n\n**Note**: In ODR, **all orders should be sent from an Outlet**. Even if the client has only one location, the order should still originate from the Outlet and not the parent vendor.\n\n## Ordering Steps\n1. The Sender address must be specified when submitting an Order.\n2. The Sender latitude and longitude will be used to find the matching Branch/Outlet.\n\n### Supported Payment Methods\n| Payment Method | Description |\n| - | - |\n| PAID | Order has been fully paid already and courier will not collect any amount from the end customer |\n| CASH_ON_DELIVERY | Courier will collect payment (order amount) from the end customer upon delivery |\n| CARD_ON_DELIVERY | Payment by credit card upon receipt of the order |\n\n## API Endpoints and URLs\n\nBelow are the API endpoints for each brand and country:\n\n- Production URLs use DH-friendly domains when available.\n- Staging URLs always use raw infra domains.\n\n### Talabat\n| Country | Prod API | Stage API |\n| - | - | - |\n| United Arab Emirates | https://talabat-api-euw2.deliveryhero.io/ae | https://api-infra-eu-west-2.stg.ondemandrider.net/ae |\n| Bahrain | https://talabat-api-euw2.deliveryhero.io/bh | https://api-infra-eu-west-2.stg.ondemandrider.net/bh |\n| Egypt | https://talabat-api-euw2.deliveryhero.io/eg | https://api-infra-eu-west-2.stg.ondemandrider.net/eg |\n| Jordan | https://talabat-api-euw2.deliveryhero.io/jo | https://api-infra-eu-west-2.stg.ondemandrider.net/jo |\n| Kuwait | https://talabat-api-euw2.deliveryhero.io/kw | https://api-infra-eu-west-2.stg.ondemandrider.net/kw |\n| Oman | https://talabat-api-euw2.deliveryhero.io/om | https://api-infra-eu-west-2.stg.ondemandrider.net/om |\n| Qatar | https://talabat-api-euw2.deliveryhero.io/qa | https://api-infra-eu-west-2.stg.ondemandrider.net/qa |\n\n---\n\n### Hungerstation\n| Country | Prod API | Stage API |\n| - | - | - |\n| Saudi Arabia | https://talabat-api-euw2.deliveryhero.io/sa | https://api-infra-eu-west-2.stg.ondemandrider.net/sa |\n\n---\n\n### Pandago\n| Country | Prod API | Stage API |\n| - | - | - |\n| Bangladesh | https://pandago-api-apse.deliveryhero.io/bd | https://api-infra-ap-southeast-1.stg.ondemandrider.net/bd |\n| Hong Kong | https://pandago-api-apse.deliveryhero.io/hk | https://api-infra-ap-southeast-1.stg.ondemandrider.net/hk |\n| Cambodia | https://pandago-api-apse.deliveryhero.io/kh | https://api-infra-ap-southeast-1.stg.ondemandrider.net/kh |\n| Laos | https://pandago-api-apse.deliveryhero.io/la | https://api-infra-ap-southeast-1.stg.ondemandrider.net/la |\n| Myanmar | https://pandago-api-apse.deliveryhero.io/mm | https://api-infra-ap-southeast-1.stg.ondemandrider.net/mm |\n| Malaysia | https://pandago-api-apse.deliveryhero.io/my | https://api-infra-ap-southeast-1.stg.ondemandrider.net/my |\n| Philippines | https://pandago-api-apse.deliveryhero.io/ph | https://api-infra-ap-southeast-1.stg.ondemandrider.net/ph |\n| Pakistan (APSO) | https://pandago-api-apso.deliveryhero.io/pk | https://api-infra-ap-south-1.stg.ondemandrider.net/pk |\n| Singapore | https://pandago-api-apse.deliveryhero.io/sg | https://api-infra-ap-southeast-1.stg.ondemandrider.net/sg |\n| Thailand | https://pandago-api-apse.deliveryhero.io/th | https://api-infra-ap-southeast-1.stg.ondemandrider.net/th |\n| Taiwan | https://pandago-api-apse.deliveryhero.io/tw | https://api-infra-ap-southeast-1.stg.ondemandrider.net/tw |\n\n---\n\n### Foodora Go\n| Country | Prod API | Stage API |\n| - | - | - |\n| Czech Republic | https://talabat-api-euw2.deliveryhero.io/cz | https://api-infra-eu-west-2.stg.ondemandrider.net/cz |\n| Finland | https://foodorago-api-eun1.deliveryhero.io/fi | https://api-infra-eu-north-1.stg.ondemandrider.net/fi |\n| Hungary | https://talabat-api-euw2.deliveryhero.io/hu | https://api-infra-eu-west-2.stg.ondemandrider.net/hu |\n| Norway | https://foodorago-api-eun1.deliveryhero.io/no | https://api-infra-eu-north-1.stg.ondemandrider.net/no |\n| Sweden | https://foodorago-api-eun1.deliveryhero.io/se | https://api-infra-eu-north-1.stg.ondemandrider.net/se |\n| Austria | https://api-infra-eu-west-2.ondemandrider.net/at | https://api-infra-eu-west-2.stg.ondemandrider.net/at |\n\n---\n\n### Efood\n| Country | Prod API | Stage API |\n| - | - | - |\n| Greece | https://api-infra-eu-west-2.ondemandrider.net/gr | https://api-infra-eu-west-2.stg.ondemandrider.net/gr |\n\n---\n\n### Foody\n| Country | Prod API | Stage API |\n| - | - | - |\n| Cyprus | https://api-infra-eu-west-2.ondemandrider.net/cy | https://api-infra-eu-west-2.stg.ondemandrider.net/cy |\n\n---\n\n### Glovo\n| Country | Prod API | Stage API |\n| - | - | - |\n| Armenia | https://ondemand-api-glovoapp.deliveryhero.io/am | https://api-infra-eu-central-1.stg.ondemandrider.net/am |\n| Bosnia & Herzegovina | https://ondemand-api-glovoapp.deliveryhero.io/ba | https://api-infra-eu-central-1.stg.ondemandrider.net/ba |\n| Bulgaria | https://ondemand-api-glovoapp.deliveryhero.io/bg | https://api-infra-eu-central-1.stg.ondemandrider.net/bg |\n| Ivory Coast | https://ondemand-api-glovoapp.deliveryhero.io/ci | https://api-infra-eu-central-1.stg.ondemandrider.net/ci |\n| Spain | https://ondemand-api-glovoapp.deliveryhero.io/es | https://api-infra-eu-central-1.stg.ondemandrider.net/es |\n| Georgia | https://ondemand-api-glovoapp.deliveryhero.io/ge | https://api-infra-eu-central-1.stg.ondemandrider.net/ge |\n| Croatia | https://ondemand-api-glovoapp.deliveryhero.io/hr | https://api-infra-eu-central-1.stg.ondemandrider.net/hr |\n| Italy | https://ondemand-api-glovoapp.deliveryhero.io/it | https://api-infra-eu-central-1.stg.ondemandrider.net/it |\n| Kenya | https://ondemand-api-glovoapp.deliveryhero.io/ke | https://api-infra-eu-central-1.stg.ondemandrider.net/ke |\n| Kyrgyzstan | https://ondemand-api-glovoapp.deliveryhero.io/kg | https://api-infra-eu-central-1.stg.ondemandrider.net/kg |\n| Kazakhstan | https://ondemand-api-glovoapp.deliveryhero.io/kz | https://api-infra-eu-central-1.stg.ondemandrider.net/kz |\n| Morocco | https://ondemand-api-glovoapp.deliveryhero.io/ma | https://api-infra-eu-central-1.stg.ondemandrider.net/ma |\n| Moldova | https://ondemand-api-glovoapp.deliveryhero.io/md | https://api-infra-eu-central-1.stg.ondemandrider.net/md |\n| Montenegro | https://ondemand-api-glovoapp.deliveryhero.io/me | https://api-infra-eu-central-1.stg.ondemandrider.net/me |\n| Nigeria | https://ondemand-api-glovoapp.deliveryhero.io/ng | https://api-infra-eu-central-1.stg.ondemandrider.net/ng |\n| Poland | https://ondemand-api-glovoapp.deliveryhero.io/pl | https://api-infra-eu-central-1.stg.ondemandrider.net/pl |\n| Portugal | https://ondemand-api-glovoapp.deliveryhero.io/pt | https://api-infra-eu-central-1.stg.ondemandrider.net/pt |\n| Romania | https://ondemand-api-glovoapp.deliveryhero.io/ro | https://api-infra-eu-central-1.stg.ondemandrider.net/ro |\n| Serbia | https://ondemand-api-glovoapp.deliveryhero.io/rs | https://api-infra-eu-central-1.stg.ondemandrider.net/rs |\n| Tunisia | https://ondemand-api-glovoapp.deliveryhero.io/tn | https://api-infra-eu-central-1.stg.ondemandrider.net/tn |\n| Ukraine | https://ondemand-api-glovoapp.deliveryhero.io/ua | https://api-infra-eu-central-1.stg.ondemandrider.net/ua |\n| Uganda | https://ondemand-api-glovoapp.deliveryhero.io/ug | https://api-infra-eu-central-1.stg.ondemandrider.net/ug |\n\n---\n\n# Getting Started\n\n## 1. Provide a public key\nThese are the steps to start using the ODR API:\n1. Generate Key Pair (Private Key and Public Key) to support secure communication with the ODR API.\n\n Follow these commands on a terminal:\n ```bash\n # Generate private key\n # output: client.pem file\n openssl genrsa -out client.pem 2048\n\n # Generate public key from the generated private one\n # input: client.pem file\n # output: client.pub file\n openssl rsa -in client.pem -pubout > client.pub\n ```\n Or, follow these steps:\n 1. Open a browser and access [this Online RSA Generator](https://emn178.github.io/online-tools/rsa/key-generator/)\n 2. Select key length to 2048 bit, and click the Generate Key Pair button.\n 3. Copy and save the Private Key to a file with .pem extension (e.g. client.pem).\n 4. Copy and save the Public Key to a file with .pub extension (e.g. client.pub).\n2. The ODR representative will provide you with `ClientID`, `KeyID` and `Scope` that your service will need to generate an Access Token for the ODR API.\n | Attribute | Description | Example |\n | - | - | - |\n | ClientID | Your service identifier| pandago:sg:00000000-0000-0000-0000-000000000000 |\n | KeyID | Your public key identifier| 00000000-0000-0000-0000-000000000001 |\n | Scope | Access scope of your service| `pandago.api.{country code}.*` (ex: `pandago.api.pt.*`) |\n\n\n## 2. Generate signed JWT\nGenerate assertion as a signed token in Javascript Web Token (JWT) format.\n\nThis is the payload structure of the token:\n```\n{\n \"alg\":\"RS256\",\n \"typ\":\"JWT\",\n \"kid\": \"{{KeyID}}\"\n}\n.\n{\n \"iss\":\"{{ClientID}}\",\n \"sub\":\"{{ClientID}}\",\n \"jti\":\"{{random uuid (e.g. caa56777-4e88-4c59-be70-3ae513fd2e00)}}\",\n \"exp\":{{unix timestamp in the future (e.g. 1894712882)}},\n \"aud\":\"https://sts.deliveryhero.io\"\n}\n```\nAnd use your Private Key to sign the token.\n\n\uD83D\uDCA1 **Tips** \uD83D\uDCA1\n* Always use `https://sts.deliveryhero.io` for `aud` key, in both testing and prod environments\n* For the `exp` key, just get a future timestamp (ex in 1 year) with [unixtimestamp.com](https://www.unixtimestamp.com/index.php)\n\n## 3. Get a JWT access token\n\nFollow the instructions to call [the auth endpont](#tag/Authentication)\n" servers: - url: https://pandago-api-sandbox.deliveryhero.io/sg/api/v1 description: Sandbox environment - url: https://api-infra-eu-central-1.stg.ondemandrider.net/{country code}/api/v1 description: "Stage Glovo generic \uD83D\uDCA1 Find your country URL [here](#section/About/API-Endpoints-and-URLs) \uD83D\uDCA1" - url: https://ondemand-api-glovoapp.deliveryhero.io/{country code}/api/v1 description: "Production Glovo generic \uD83D\uDCA1 Find your country URL [here](#section/About/API-Endpoints-and-URLs) \uD83D\uDCA1" - url: https://ondemand-api-glovoapp.deliveryhero.io/pt/api/v1 description: Example in production for Glovo Portugal security: - Bearer_Token: [] tags: - name: Proofs paths: /orders/proof_of_pickup/{order_id}: get: summary: Get Proof of Pickup for Order description: 'Use this endpoint to get proof of pickup for existing and picked up orders. __NOTE:__ Proof of pickup will be deleted after 1 week because of security and privacy concerns __NOTE:__ API returns encoded base64 file, so if you want to show that response in your html page, you should follow this element using `'' />` *NOTE: Not yet rolled out.* ' tags: - Proofs parameters: - name: Authorization in: header required: true schema: type: string default: Bearer {access-token} - name: order_id in: path required: true description: ID of the order to get its proof of pickup schema: type: string responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/GetProofOfPickupResponse' examples: response: value: base64EncodedFileResponse as file '404': description: Not found content: application/json: schema: $ref: '#/components/schemas/ErrorResponseForProofOfPickup' examples: response: value: message: Proof of pickup for this order was not found '500': description: Server error content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' examples: response: value: message: Unable to proceed, something went wrong /orders/proof_of_delivery/{order_id}: get: summary: Get Proof of Delivery for Order description: 'Use this endpoint to get proof of delivery for existing and delivered orders. __NOTE:__ Proof of delivery will be deleted after 1 week because of security and privacy concerns __NOTE:__ API returns encoded base64 file, so if you want to show that response in your html page, you should follow this element using `'' />` ' tags: - Proofs parameters: - name: Authorization in: header required: true schema: type: string default: Bearer {access-token} - name: order_id in: path required: true description: ID of the order to get its proof of delivery schema: type: string responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/GetProofOfDeliveryResponse' examples: response: value: base64EncodedFileResponse as file '404': description: Not found content: application/json: schema: $ref: '#/components/schemas/ErrorResponseForProofOfDelivery' examples: response: value: message: Proof of delivery for this order was not found '500': description: Server error content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' examples: response: value: message: Unable to proceed, something went wrong /orders/proof_of_return/{order_id}: get: summary: Get Proof of Return for Order description: 'Use this endpoint to get proof of return for existing and returned orders. __NOTE:__ Proof of return will be deleted after 1 week because of security and privacy concerns __NOTE:__ API returns encoded base64 file, so if you want to show that response in your html page, you should follow this element using `'' />` ' tags: - Proofs parameters: - name: Authorization in: header required: true schema: type: string default: Bearer {access-token} - name: order_id in: path required: true description: ID of the order to get its proof of return schema: type: string responses: '200': description: Success content: application/json: schema: $ref: '#/components/schemas/GetProofOfReturnResponse' examples: response: value: base64EncodedFileResponse as file '404': description: Not found content: application/json: schema: $ref: '#/components/schemas/ErrorResponseForProofOfReturn' examples: response: value: message: Proof of return for this order was not found '500': description: Server error content: application/json: schema: $ref: '#/components/schemas/ErrorResponse' examples: response: value: message: Unable to proceed, something went wrong components: schemas: ProofOfReturn: title: ProofOfReturn type: string format: binary ProofOfDelivery: title: ProofOfDelivery type: string format: binary ErrorResponseForProofOfPickup: title: Error Response type: object properties: message: type: string required: - message ErrorResponseForProofOfReturn: title: Error Response type: object properties: message: type: string required: - message ErrorResponse: title: Error Response type: object properties: message: type: string required: - message GetProofOfDeliveryResponse: $ref: '#/components/schemas/ProofOfDelivery' GetProofOfReturnResponse: $ref: '#/components/schemas/ProofOfReturn' ProofOfPickup: title: ProofOfPickup type: string format: binary ErrorResponseForProofOfDelivery: title: Error Response type: object properties: message: type: string required: - message GetProofOfPickupResponse: $ref: '#/components/schemas/ProofOfPickup' securitySchemes: Bearer_Token: type: apiKey name: Authorization in: header description: 'Provide the access token in the format: `Bearer {access-token}`. You can obtain the access token from the [Authentication endpoint](#tag/Authentication). ' x-tagGroups: - name: Authentication tags: - Authentication - name: Orders tags: - OrdersManagement - OrdersEstimation - RiderPosition - Proofs - name: Outlets tags: - Outlets - name: Callback tags: - Callback