Open API · v1
Read your OrderPin data
straight from your own systems.
Five REST endpoints for bills, payments, employees, wages and time entries. One credential pair, one request shape, JSON in and JSON out — built for incremental synchronization into your accounting, payroll or BI stack.
- POST JSON over HTTPS
- 200 records per page
- 31 days max range per query
- Per-client rate limits
APIs
Bill API
order.bill
Retrieve bills (checks/orders) with their aggregated amounts, including the payment and product-line records belonging to each bill.
Read the reference → OrdersTransaction API
order.bill.transaction
Retrieve payment transactions (tenders) across bills — card, cash, gift-card and balance payments, with card and device details.
Read the reference → LaborEmployee API
labor.employee
Retrieve employee master data (profile and status), including the role and wage records belonging to each employee. Temporary users are never returned by this API.
Read the reference → LaborEmployee Wage API
labor.employee.wage
Retrieve employee wage records — the hourly rate of each employee, per role.
Read the reference → LaborTime Entry API
labor.timeEntry
Retrieve employee time-clock entries (punch records), including the break records belonging to each entry.
Read the reference →Everything works the same way
Authenticate
Every request carries two headers issued by OrderPin. Requests are scoped automatically to the store behind your credentials — you never pass a store or tenant id. To get them, email api@orderpin.us with your Store ID.
X-Client-ID | Your client ID |
Authorization | Bearer <your-api-key> |
Content-Type | application/json |
Call
Use the path form — the API name is part of the URL and the version segment pins the contract:
POST https://{base-url}/orderpin/oapi/order/bill/v1
A JSON body is always required, at least one filter must be present, and unknown parameters are rejected rather than ignored.
Try it
curl -X POST 'https://{base-url}/orderpin/oapi/order/bill/v1' \
-H 'X-Client-ID: US00000001' \
-H 'Authorization: Bearer sk_live_xxxxxxxxxxxxxxxxxxxx' \
-H 'Content-Type: application/json' \
-d '{
"filter": { "modifiedStartAt": 1767225600000, "modifiedEndAt": 1769817600000 },
"limit": 200,
"sort": [{ "field": "modifiedAt", "type": "desc" }],
"with_record_count": true
}'
Replace {base-url} with the host OrderPin issued to you.
Built for sync jobs
Incremental by design
Filter on
modifiedStartAt / modifiedEndAt to pull only what changed since your
last run. Ranges must stay under 31 days.
Stable pagination
Pair skip and limit
with an explicit sort so pages never overlap or skip records. Ask for
with_record_count once, on the first page.
Honest rate limits
Read X-RateLimit-Limit and
X-RateLimit-Remaining from every response; on 429 wait the whole
Retry-After. Failed authentication never costs quota.
Precise errors
Every failure returns a numeric code
and a msg that names the offending parameter. Check the body code even on
HTTP 200 — an unknown API name returns 1020.
Errors at a glance
| HTTP | Code | Meaning |
|---|---|---|
401 | 2004 | Missing X-Client-ID header |
401 | 2003 | Missing or malformed Authorization header |
401 | 2001 | Unknown client ID |
401 | 2005 | Invalid API key |
403 | 2006 | Open API not enabled for the account |
400 | 1004 | Invalid request parameter |
200 | 1020 | Unknown API name or version |
429 | 2012 | Rate limit exceeded — honor Retry-After |
500 | 1003 / 1012 | Transient server failure — retry with backoff |
Each reference page lists the full 1004 validation messages for that API.
Need credentials?
Client IDs and API keys are issued per store. Email api@orderpin.us with your Store ID — that is all we need to enable the Open API for you. Running several stores? Request a separate set for each Store ID.
Talk to us