openapi: 3.0.1 info: title: UrbanPiper POS Integration Aggregator Webhooks API description: 'UrbanPiper''s POS-integration REST API connects a restaurant POS/ERP to online ordering aggregators (Swiggy, Zomato, UberEats, DoorDash, Deliveroo, Talabat, Amazon, Careem and others). It covers store/location management, catalogue and menu push, store and item/option availability toggles, order status updates and webhook registration. Authentication is a static API key passed as `Authorization: apikey :`; multi-brand requests also pass the `X-UPR-Biz-Id` header.' termsOfService: https://www.urbanpiper.com/terms-of-service contact: name: UrbanPiper POS Support email: pos.support@urbanpiper.com url: https://api-docs.urbanpiper.com/downstream/ version: v1 servers: - url: https://pos-int.urbanpiper.com description: Staging / sandbox environment. Production base URL is shared during certification. security: - apiKeyAuth: [] tags: - name: Webhooks description: Register and manage outbound webhook endpoints. paths: /external/api/v1/webhooks/: get: operationId: listWebhooks tags: - Webhooks summary: List webhooks description: List the configured webhook endpoints for the business. responses: '200': description: A list of webhooks. content: application/json: schema: type: array items: $ref: '#/components/schemas/Webhook' '401': $ref: '#/components/responses/Unauthorized' post: operationId: createWebhook tags: - Webhooks summary: Create a webhook description: Register a webhook endpoint that UrbanPiper calls to deliver callbacks. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/Webhook' responses: '201': description: Webhook created. content: application/json: schema: $ref: '#/components/schemas/Webhook' '401': $ref: '#/components/responses/Unauthorized' /external/api/v1/webhooks/{webhook_id}/: get: operationId: getWebhook tags: - Webhooks summary: Get a webhook parameters: - name: webhook_id in: path required: true schema: type: string responses: '200': description: The webhook. content: application/json: schema: $ref: '#/components/schemas/Webhook' '401': $ref: '#/components/responses/Unauthorized' put: operationId: updateWebhook tags: - Webhooks summary: Update a webhook parameters: - name: webhook_id in: path required: true schema: type: string requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/Webhook' responses: '200': description: Webhook updated. content: application/json: schema: $ref: '#/components/schemas/Webhook' '401': $ref: '#/components/responses/Unauthorized' /external/api/v1/webhooks/retry/: post: operationId: retryWebhookOrder tags: - Webhooks summary: Retry webhook order delivery description: Request a retry of an order webhook that was not successfully delivered. requestBody: required: true content: application/json: schema: type: object responses: '200': description: Retry enqueued. content: application/json: schema: $ref: '#/components/schemas/StatusResponse' '401': $ref: '#/components/responses/Unauthorized' components: schemas: StatusResponse: type: object properties: status: type: string message: type: string Webhook: type: object properties: id: type: integer url: type: string event: type: string active: type: boolean responses: Unauthorized: description: Missing or invalid Authorization header. content: application/json: schema: $ref: '#/components/schemas/StatusResponse' securitySchemes: apiKeyAuth: type: apiKey in: header name: Authorization description: 'Static API key authentication. Pass the header as `Authorization: apikey :`. Multi-brand requests must also include the `X-UPR-Biz-Id` header identifying the business/brand.'