openapi: 3.1.0 info: title: Open Loyalty REST Authorization API version: '1.0' description: API-first, headless loyalty and gamification platform. This document models a representative, grounded subset of the Open Loyalty REST API across members (customers), transactions, points transfers, reward campaigns, levels (tiers), and earning rules. Endpoints are scoped per store using a storeCode path segment. Open Loyalty is delivered as managed cloud SaaS on a per-tenant instance, so the server host below is a template - substitute your own Open Loyalty instance host. Requests and responses are JSON over HTTPS, authenticated with a JWT bearer token or a permanent API token. contact: name: Open Loyalty url: https://www.openloyalty.io license: name: Open Loyalty (Open Source Edition Apache-2.0 / Enterprise SaaS) url: https://github.com/OpenLoyalty servers: - url: https://{instance}.openloyalty.io/api description: Per-tenant Open Loyalty instance (substitute your own host). variables: instance: default: your-instance description: Your Open Loyalty tenant subdomain. security: - bearerAuth: [] - permanentToken: [] tags: - name: Authorization description: Authentication and token issuance. paths: /admin/login_check: post: operationId: adminLogin tags: - Authorization summary: Obtain a JWT for an admin user security: [] requestBody: required: true content: application/json: schema: type: object properties: username: type: string password: type: string required: - username - password responses: '200': description: A signed JWT bearer token. content: application/json: schema: type: object properties: token: type: string /{storeCode}/customer/login_check: post: operationId: customerLogin tags: - Authorization summary: Obtain a JWT for a member (customer) security: [] parameters: - $ref: '#/components/parameters/StoreCode' requestBody: required: true content: application/json: schema: type: object properties: username: type: string password: type: string responses: '200': description: A signed JWT bearer token for the member. components: parameters: StoreCode: name: storeCode in: path required: true description: The store the request is scoped to. schema: type: string default: DEFAULT securitySchemes: bearerAuth: type: http scheme: bearer bearerFormat: JWT description: 'JWT obtained from POST /admin/login_check (admin) or POST /{storeCode}/customer/login_check (member), sent as Authorization: Bearer .' permanentToken: type: apiKey in: header name: X-AUTH-TOKEN description: Permanent API token issued to an admin account. externalDocs: description: Open Loyalty REST API reference url: https://docs.openloyalty.io/en/latest/api/