overlay: 1.0.0 info: title: API Evangelist enhancements for Florist One Affiliate API version: 1.0.0 x-generated: '2026-09-10' x-method: generated x-source: >- Derived from Florist One's own published sample code at https://github.com/fhwsolutions/FloristOne_API, the public documentation at https://www.floristone.com/api/how-it-works/ and https://www.floristone.com/api/flowers-api-faq/, the API Agreement at https://www.floristone.com/api/print_api_legal/, and one live probe of https://www.floristone.com/api/rest on 2026-09-10. Applies our findings without mutating the harvested description. extends: openapi/florist-one-affiliate-api-openapi.yml actions: - target: $.info update: x-apievangelist-profile: https://apis.io/provider/florist-one/ x-contract-provenance: >- Florist One publishes no OpenAPI. This description was written by API Evangelist from the provider's public PHP and ColdFusion sample code and its public documentation. It is a third-party description, not a provider artifact. x-docs-gated: >- The endpoint-level documentation at https://www.floristone.com/api/technical-information/ is behind an API Key and password login, so parameter semantics beyond the names below are unverified. - target: $.servers update: x-base-url-note: >- The callable base is https://www.floristone.com/api/rest. The /api/ path is the marketing and documentation site and is not an API host. - target: $.components.securitySchemes.basicAuth update: x-wire-format: 'Authorization: ' x-rfc7617-conformant: false x-wire-format-note: >- Every published Florist One sample omits the "Basic " scheme prefix required by RFC 7617. See authentication/florist-one-authentication.yml. x-no-www-authenticate: >- An unauthenticated request returns 403 with no WWW-Authenticate challenge and a text/html IIS error page. - target: $.paths update: x-error-envelope: >- No error responses are declared by the provider and none are documented. The one observed failure (403, unauthenticated) returns text/html, not JSON and not application/problem+json. See errors/florist-one-problem-types.yml. x-response-field-casing: >- Response keys are UPPERCASE (PRODUCTS, CODE, PRICE, ORDERNO, SUBTOTAL, ITEMS, RECIPIENT). A case-sensitive client written against lowercase keys will fail. x-rate-limit-signal: >- None. No RateLimit-*, X-RateLimit-* or Retry-After header is emitted. See rate-limits/florist-one-rate-limits.yml. x-idempotency: >- Not supported anywhere on this API. See conventions/florist-one-conventions.yml. - target: $.paths['/affiliate/legalagreement'].post update: x-purpose: >- Returns the affiliate legal agreement text for display in the integrator's own signup flow, on a content field. The human-readable equivalents are published at https://www.floristone.com/api/print_affiliate_legal/ and https://www.floristone.com/api/print_api_legal/. x-read-only-in-effect: >- Declared as POST but retrieves content and mutates nothing.