openapi: 3.2.0 info: title: Piknik.Spot Place API description: Piknik.Spot API with OAuth2 authentication, Model Context Protocol (MCP) support, and Agent-to-Agent (A2A) capabilities for AI-powered local food system interactions. version: 1.0.0 contact: name: Piknik.Spot API Support url: https://piknik.spot email: info@piknik.spot license: name: Proprietary url: https://piknik.spot/terms servers: - url: https://piknik.spot/api description: Production Server - url: http://localhost:3000/api description: Development Server tags: - name: Place paths: /place/{id}/og-image: get: summary: GET /place/{id}/og-image description: Endpoint for /place/{id}/og-image tags: - Place responses: '200': description: Success content: application/json: schema: type: object '400': description: Bad Request content: application/json: schema: $ref: '#/components/schemas/Error' '401': description: Unauthorized content: application/json: schema: $ref: '#/components/schemas/Error' security: [] parameters: - name: id in: path required: true schema: type: string description: id identifier operationId: getPlaceByIdOgImage x-operation-id-source: derived /place/{id}/users/{userId}: put: summary: PUT /place/{id}/users/{userId} description: Endpoint for /place/{id}/users/{userId} tags: - Place responses: '200': description: Success content: application/json: schema: type: object '400': description: Bad Request content: application/json: schema: $ref: '#/components/schemas/Error' '401': description: Unauthorized content: application/json: schema: $ref: '#/components/schemas/Error' security: - bearerAuth: [] - cookieAuth: [] parameters: - name: id in: path required: true schema: type: string description: id identifier - name: userId in: path required: true schema: type: string description: userId identifier requestBody: required: true content: application/json: schema: type: object operationId: putPlaceByIdUsersByUserId x-operation-id-source: derived delete: summary: DELETE /place/{id}/users/{userId} description: Endpoint for /place/{id}/users/{userId} tags: - Place responses: '200': description: Success content: application/json: schema: type: object '400': description: Bad Request content: application/json: schema: $ref: '#/components/schemas/Error' '401': description: Unauthorized content: application/json: schema: $ref: '#/components/schemas/Error' security: - bearerAuth: [] - cookieAuth: [] parameters: - name: id in: path required: true schema: type: string description: id identifier - name: userId in: path required: true schema: type: string description: userId identifier operationId: deletePlaceByIdUsersByUserId x-operation-id-source: derived /place/{id}/users: get: summary: GET /place/{id}/users description: Endpoint for /place/{id}/users tags: - Place responses: '200': description: Success content: application/json: schema: type: object '400': description: Bad Request content: application/json: schema: $ref: '#/components/schemas/Error' '401': description: Unauthorized content: application/json: schema: $ref: '#/components/schemas/Error' security: - bearerAuth: [] - cookieAuth: [] parameters: - name: id in: path required: true schema: type: string description: id identifier operationId: getPlaceByIdUsers x-operation-id-source: derived post: summary: POST /place/{id}/users description: Endpoint for /place/{id}/users tags: - Place responses: '201': description: Created successfully content: application/json: schema: type: object '400': description: Bad Request content: application/json: schema: $ref: '#/components/schemas/Error' '401': description: Unauthorized content: application/json: schema: $ref: '#/components/schemas/Error' security: - bearerAuth: [] - cookieAuth: [] parameters: - name: id in: path required: true schema: type: string description: id identifier requestBody: required: true content: application/json: schema: type: object operationId: postPlaceByIdUsers x-operation-id-source: derived /place/challenge-interest: post: summary: POST /place/challenge-interest description: Endpoint for /place/challenge-interest tags: - Place responses: '201': description: Created successfully content: application/json: schema: type: object '400': description: Bad Request content: application/json: schema: $ref: '#/components/schemas/Error' '401': description: Unauthorized content: application/json: schema: $ref: '#/components/schemas/Error' security: - bearerAuth: [] - cookieAuth: [] parameters: - name: businessId in: query schema: type: string description: businessId parameter requestBody: required: true content: application/json: schema: type: object operationId: postPlaceChallengeInterest x-operation-id-source: derived get: summary: GET /place/challenge-interest description: Endpoint for /place/challenge-interest tags: - Place responses: '200': description: Success content: application/json: schema: type: object '400': description: Bad Request content: application/json: schema: $ref: '#/components/schemas/Error' '401': description: Unauthorized content: application/json: schema: $ref: '#/components/schemas/Error' security: - bearerAuth: [] - cookieAuth: [] parameters: - name: businessId in: query schema: type: string description: businessId parameter operationId: getPlaceChallengeInterest x-operation-id-source: derived /place/challenge-opportunities: get: summary: GET /place/challenge-opportunities description: Endpoint for /place/challenge-opportunities tags: - Place responses: '200': description: Success content: application/json: schema: type: object '400': description: Bad Request content: application/json: schema: $ref: '#/components/schemas/Error' '401': description: Unauthorized content: application/json: schema: $ref: '#/components/schemas/Error' security: - bearerAuth: [] - cookieAuth: [] parameters: - name: businessId in: query schema: type: string description: businessId parameter operationId: getPlaceChallengeOpportunities x-operation-id-source: derived /place/games/{gameId}/participation: patch: summary: PATCH /place/games/{gameId}/participation description: Endpoint for /place/games/{gameId}/participation tags: - Place responses: '200': description: Success content: application/json: schema: type: object '400': description: Bad Request content: application/json: schema: $ref: '#/components/schemas/Error' '401': description: Unauthorized content: application/json: schema: $ref: '#/components/schemas/Error' security: - bearerAuth: [] - cookieAuth: [] parameters: - name: gameId in: path required: true schema: type: string description: gameId identifier requestBody: required: true content: application/json: schema: type: object operationId: patchPlaceGamesByGameIdParticipation x-operation-id-source: derived /place/games/{gameId}/qr-code/pdf: get: summary: GET /place/games/{gameId}/qr-code/pdf description: Endpoint for /place/games/{gameId}/qr-code/pdf tags: - Place responses: '200': description: Success content: application/json: schema: type: object '400': description: Bad Request content: application/json: schema: $ref: '#/components/schemas/Error' '401': description: Unauthorized content: application/json: schema: $ref: '#/components/schemas/Error' security: - bearerAuth: [] - cookieAuth: [] parameters: - name: gameId in: path required: true schema: type: string description: gameId identifier - name: business in: query schema: type: string description: business parameter - name: type in: query schema: type: string description: type parameter operationId: getPlaceGamesByGameIdQrCodePdf x-operation-id-source: derived /place/games/{gameId}/qr-code: get: summary: GET /place/games/{gameId}/qr-code description: Endpoint for /place/games/{gameId}/qr-code tags: - Place responses: '200': description: Success content: application/json: schema: type: object '400': description: Bad Request content: application/json: schema: $ref: '#/components/schemas/Error' '401': description: Unauthorized content: application/json: schema: $ref: '#/components/schemas/Error' security: - bearerAuth: [] - cookieAuth: [] parameters: - name: gameId in: path required: true schema: type: string description: gameId identifier - name: business in: query schema: type: string description: business parameter - name: type in: query schema: type: string description: type parameter operationId: getPlaceGamesByGameIdQrCode x-operation-id-source: derived /place/games: get: summary: GET /place/games description: Endpoint for /place/games tags: - Place responses: '200': description: Success content: application/json: schema: type: object '400': description: Bad Request content: application/json: schema: $ref: '#/components/schemas/Error' '401': description: Unauthorized content: application/json: schema: $ref: '#/components/schemas/Error' security: - bearerAuth: [] - cookieAuth: [] parameters: - name: businessType in: query schema: type: string description: Type of business - name: businessId in: query schema: type: string description: businessId parameter operationId: getPlaceGames x-operation-id-source: derived /place/store-qr/{participantId}/qr-code/pdf: get: summary: GET /place/store-qr/{participantId}/qr-code/pdf description: Endpoint for /place/store-qr/{participantId}/qr-code/pdf tags: - Place responses: '200': description: Success content: application/json: schema: type: object '400': description: Bad Request content: application/json: schema: $ref: '#/components/schemas/Error' '401': description: Unauthorized content: application/json: schema: $ref: '#/components/schemas/Error' security: - bearerAuth: [] - cookieAuth: [] parameters: - name: participantId in: path required: true schema: type: string description: participantId identifier - name: size in: query schema: type: string description: size parameter operationId: getPlaceStoreQrByParticipantIdQrCodePdf x-operation-id-source: derived /place/store-qr/{participantId}/qr-code: get: summary: GET /place/store-qr/{participantId}/qr-code description: Endpoint for /place/store-qr/{participantId}/qr-code tags: - Place responses: '200': description: Success content: application/json: schema: type: object '400': description: Bad Request content: application/json: schema: $ref: '#/components/schemas/Error' '401': description: Unauthorized content: application/json: schema: $ref: '#/components/schemas/Error' security: - bearerAuth: [] - cookieAuth: [] parameters: - name: participantId in: path required: true schema: type: string description: participantId identifier operationId: getPlaceStoreQrByParticipantIdQrCode x-operation-id-source: derived components: schemas: Error: type: object properties: error: type: string description: Error message error_description: type: string description: Detailed error description securitySchemes: cookieAuth: type: apiKey in: cookie name: next-auth.session-token description: Session-based authentication for web browsers oauth2: type: oauth2 description: OAuth 2.0 authentication for external applications and AI agents flows: authorizationCode: authorizationUrl: https://piknik.spot/api/oauth/authorize tokenUrl: https://piknik.spot/api/oauth/token refreshUrl: https://piknik.spot/api/oauth/token scopes: marketplace:write: Create and manage marketplace listings events:write: Create and manage community events read:profile: Read user profile information write:profile: Update user profile information bearerAuth: type: http scheme: bearer bearerFormat: JWT description: 'OAuth2 access token (JWT). Include in Authorization header as: Bearer {token}'