openapi: 3.0.3 info: title: PetExec Authentication API description: The PetExec API is a REST API for existing PetExec customers and their developers to extend the PetExec pet-care business management platform (daycare, boarding, grooming, training, and scheduled services). Every endpoint, path, and scope in this document is transcribed directly from PetExec's own public GitHub examples repository (https://github.com/PetExec/API-Examples), which is the only complete source of PetExec API technical detail publicly available - PetExec's interactive apidoc reference at https://secure.petexec.net/api/apidoc/index.html is a JavaScript-rendered single-page app and does not expose a machine-readable spec. Access requires an active PetExec account. Client credentials (client_id / client_secret) are self-issued from Company Preferences > Misc. Settings > Maintain API Applications inside the PetExec console, then exchanged for a scoped Bearer token via an OAuth2 Resource Owner Password Credentials (password) grant against POST /token. PetExec was acquired by Togetherwork in November 2024 and is being migrated toward Gingr; PetExec is no longer accepting new customers, but this API surface is documented as live for existing accounts as of the review date. Some of PetExec's own published examples are internally inconsistent (mixed "user-card" / "userCard" casing, a menu example that appears to call the wrong path) - those inconsistencies are called out inline below rather than silently corrected. version: '1.0' contact: name: PetExec url: https://www.petexec.net/features/api-for-developers servers: - url: https://secure.petexec.net/api description: PetExec production API (used by nearly all official PHP and most JavaScript examples) - url: https://beta.petexec.net/api description: PetExec beta/staging API (referenced by some official JavaScript examples for the same paths; not separately documented) security: - bearerAuth: [] tags: - name: Authentication description: OAuth2 password-grant token issuance. paths: /token: post: operationId: getAccessToken tags: - Authentication summary: Obtain an access token (password grant) description: Exchanges a PetExec username/password plus a client_id/client_secret (sent as an HTTP Basic Authorization header) for a scoped Bearer access token. `scope` is a space-separated list, e.g. "owner_read owner_update". Public clients (e.g. browser JavaScript) should not expose client_secret. security: [] parameters: - name: Authorization in: header required: true description: Basic base64(client_id:client_secret) schema: type: string requestBody: required: true content: application/x-www-form-urlencoded: schema: type: object required: - grant_type - username - password properties: grant_type: type: string enum: - password username: type: string password: type: string scope: type: string description: Space-separated list of requested scopes (e.g. owner_read, owner_update, usercard_read, menu_read, report_read). responses: '200': description: Access token issued. content: application/json: schema: $ref: '#/components/schemas/TokenResponse' '401': $ref: '#/components/responses/Unauthorized' components: schemas: TokenResponse: type: object properties: access_token: type: string token_type: type: string expires_in: type: integer scope: type: string Error: type: object additionalProperties: true responses: Unauthorized: description: Missing, invalid, or expired Bearer token, or insufficient scope. content: application/json: schema: $ref: '#/components/schemas/Error' securitySchemes: bearerAuth: type: http scheme: bearer description: 'OAuth2 password-grant access token obtained from POST /token. Passed as `Authorization: Bearer YOUR_ACCESS_TOKEN`.'