openapi: 3.2.0 info: title: Huma Platform Order Management API version: 1.0.0 description: Huma Platform servers: - url: https://workspace-gcp-uk.api.huma.com/api/integration/v1 description: Base URL declared by the provider in apis.yml (roadmap#122). tags: - name: Order Management paths: /api/plugins/v1/order-management/products: get: operationId: api_plugins_v1_order_management_products_retrieve_[list_products] description: 'List Products Returns all available products.' summary: List Products tags: - Order Management security: - JWT Auth: [] - Hawk Auth: [] - jwtAuth: [] responses: '200': content: application/json: schema: $ref: '#/components/schemas/ProductsResponseDRF' description: '' /api/plugins/v1/order-management/user/{user_id}/order: post: operationId: api_plugins_v1_order_management_user_order_create_[create_order] description: 'Create OrderDTO Creates a new order for the user.' summary: Create Order parameters: - in: path name: user_id schema: type: string pattern: ^[a-f0-9]{24}$ required: true tags: - Order Management requestBody: content: application/json: schema: $ref: '#/components/schemas/CreateOrderRequestObjectDRF' application/x-www-form-urlencoded: schema: $ref: '#/components/schemas/CreateOrderRequestObjectDRF' multipart/form-data: schema: $ref: '#/components/schemas/CreateOrderRequestObjectDRF' required: true security: - JWT Auth: [] - Hawk Auth: [] - jwtAuth: [] responses: '201': content: application/json: schema: $ref: '#/components/schemas/ResultIdResponseObjectDRF' description: '' /api/plugins/v1/order-management/user/{user_id}/order/{order_id}: put: operationId: api_plugins_v1_order_management_user_order_update_[update_order] description: 'Update OrderDTO Updates an order''s status or cart.' summary: Update Order parameters: - in: path name: order_id schema: type: string pattern: ^[a-f0-9]{24}$ required: true - in: path name: user_id schema: type: string pattern: ^[a-f0-9]{24}$ required: true tags: - Order Management requestBody: content: application/json: schema: $ref: '#/components/schemas/UpdateOrderRequestObjectDRF' application/x-www-form-urlencoded: schema: $ref: '#/components/schemas/UpdateOrderRequestObjectDRF' multipart/form-data: schema: $ref: '#/components/schemas/UpdateOrderRequestObjectDRF' security: - JWT Auth: [] - Hawk Auth: [] - jwtAuth: [] responses: '200': content: application/json: schema: $ref: '#/components/schemas/ResultIdResponseObjectDRF' description: '' /api/plugins/v1/order-management/user/{user_id}/orders: get: operationId: api_plugins_v1_order_management_user_orders_retrieve_[list_orders] description: 'List Orders Returns all orders for the user.' summary: List Orders parameters: - in: query name: userId schema: type: string required: true - in: path name: user_id schema: type: string pattern: ^[a-f0-9]{24}$ required: true tags: - Order Management security: - JWT Auth: [] - Hawk Auth: [] - jwtAuth: [] responses: '200': content: application/json: schema: $ref: '#/components/schemas/ListOrdersResponseObjectDRF' description: '' components: schemas: ResultIdResponseObjectDRF: type: object properties: id: type: string UpdateOrderRequestObjectDRF: type: object properties: userId: type: string orderId: type: string status: type: string cart: type: array items: $ref: '#/components/schemas/OrderItemDRF' ProductsResponseDRF: type: object properties: products: type: array items: $ref: '#/components/schemas/ProductDTODRF' OrderDTODRF: type: object properties: id: type: string userId: type: string cart: type: array items: $ref: '#/components/schemas/OrderItemDRF' status: type: string createDateTime: type: string format: date-time updateDateTime: type: string format: date-time required: - cart - createDateTime - status - updateDateTime - userId ListOrdersResponseObjectDRF: type: object properties: orders: type: array items: $ref: '#/components/schemas/OrderDTODRF' CreateOrderRequestObjectDRF: type: object properties: userId: type: string cart: type: array items: $ref: '#/components/schemas/OrderItemDRF' required: - cart - userId OrderItemDRF: type: object properties: productId: type: string quantity: type: integer sku: type: string title: type: string image: type: string required: - productId - quantity - sku ProductDTODRF: type: object properties: id: type: string title: type: string image: type: string sku: type: string required: - image - sku - title securitySchemes: Hawk_Auth: type: apiKey in: header name: Authorization description: 'Hawk MAC authentication. Paste a full Authorization header value. Example: Authorization: Hawk id="userId:clientId", ts="", nonce="", mac=""[, hash=""][, ext=""] Note: Swagger UI cannot generate Hawk headers. Use your client to compute the MAC (e.g., with mohawk), then paste the full value here.' JWT_Auth: type: http scheme: bearer in: header bearerFormat: JWT description: 'Use HTTP Bearer auth with a JWT. Send the token in the Authorization header: Authorization: Bearer The token should contain standard claims plus projectId and clientId in user claims.' jwtAuth: type: http scheme: bearer bearerFormat: JWT