openapi: 3.2.0 info: title: Mobile Passcodes API version: '1.0' contact: name: Punchh Dev Support url: https://developers.punchh.com description: 'Punchh provides a robust platform for offering loyalty programs to customers. When a business integrates its back-end with the Punchh server, the Punchh APIs become instrumental in executing loyalty programs for enrolled customers, primarily via business-branded mobile apps and websites tailored by Punchh. To establish integration with the Punchh APIs, you need to understand how they are invoked and what responses are returned by the Punchh server. You can call APIs using any suitable API test client, such as Postman. Thus, the response to every API call made in Postman under a chosen environment (in app and/or platform) is reflected in the app and/or platform.' servers: - url: https://SERVER_NAME_GOES_HERE.punchh.com tags: - name: Passcodes paths: /api2/mobile/passcodes/forgot_passcode: post: responses: '200': description: '' content: text/plain: examples: default: value: "[\n \"An email has been sent to your registered email address to reset your Passcode.\"\n]" summary: Forgot Passcode description: Sends an email to a user with a reset passcode link when the user taps the reset passcode button in the app of a business operationId: mobile_forgot_passcode tags: - Passcodes parameters: - $ref: '#/components/parameters/signature' - $ref: '#/components/parameters/Authorization' - $ref: '#/components/parameters/Accept' - $ref: '#/components/parameters/Accept-Language' - $ref: '#/components/parameters/Content-Type' - $ref: '#/components/parameters/User-Agent' x-stoplight: id: 7232d383da18c requestBody: content: application/json: schema: type: object properties: client: type: string description: OAuth client ID provided by the business required: - client examples: default: value: client: CLIENT_GOES_HERE /api2/mobile/passcodes: post: responses: '200': description: '' content: text/plain: examples: default: value: "[\n \"Passcode has been successfully created.\"\n]" summary: Create Passcode description: Creates a passcode for a user operationId: mobile_create_passcode tags: - Passcodes parameters: - $ref: '#/components/parameters/Authorization' - $ref: '#/components/parameters/signature' - $ref: '#/components/parameters/Accept' - $ref: '#/components/parameters/Content-Type' - $ref: '#/components/parameters/User-Agent' x-stoplight: id: 082fbac988b5c requestBody: content: application/json: schema: type: object properties: client: type: string x-stoplight: id: wrtzmt49f077a description: OAuth client ID provided by the business passcode: type: string x-stoplight: id: pama3knz7sbb0 description: Passcode to be set for the user default: 1234 required: - client - passcode examples: default: value: client: CLIENT_GOES_HERE passcode: '1234' components: parameters: signature: schema: type: string default: '{{$$.env.signature}}' name: x-pch-digest in: header description: The [signature](/docs/dev-portal-mobile/additional-topics/signature-sha256) for the API call required: true Accept-Language: schema: type: string default: en name: Accept-Language in: header description: Preferred language User-Agent: schema: type: string default: AppName/AppVersion/BuildNumber (OS; Model; MANUFACTURER; MODEL; OS Version) in: header name: User-Agent description: Used to identify the software, device, and application initiating the request, providing information about the client to the server. For details, see [User Agent](/docs/dev-portal-mobile/additional-topics/user-agent). required: true Content-Type: schema: type: string default: application/json name: Content-Type in: header description: Set this header to application/json. required: true Accept: schema: type: string default: application/json name: Accept in: header description: Advertises which content types the client is able to understand required: true Authorization: schema: type: string default: Bearer ACCESS_TOKEN_GOES_HERE name: Authorization in: header description: Used to authorize the request with access_token. It should be supplied as `Bearer ACCESS_TOKEN_GOES_HERE`. required: true x-stoplight: id: bf6eddb435209 x-ext-urls: {}