OrderPin Open API

Open API · v1

Read your OrderPin data
straight from your own systems.

Five REST endpoints for bills, payments, employees, wages and time entries. One credential pair, one request shape, JSON in and JSON out — built for incremental synchronization into your accounting, payroll or BI stack.

  • POST JSON over HTTPS
  • 200 records per page
  • 31 days max range per query
  • Per-client rate limits

APIs

Everything works the same way

Authenticate

Every request carries two headers issued by OrderPin. Requests are scoped automatically to the store behind your credentials — you never pass a store or tenant id. To get them, email api@orderpin.us with your Store ID.

X-Client-IDYour client ID
AuthorizationBearer <your-api-key>
Content-Typeapplication/json

Call

Use the path form — the API name is part of the URL and the version segment pins the contract:

POST https://{base-url}/orderpin/oapi/order/bill/v1

A JSON body is always required, at least one filter must be present, and unknown parameters are rejected rather than ignored.

Try it

curl -X POST 'https://{base-url}/orderpin/oapi/order/bill/v1' \
  -H 'X-Client-ID: US00000001' \
  -H 'Authorization: Bearer sk_live_xxxxxxxxxxxxxxxxxxxx' \
  -H 'Content-Type: application/json' \
  -d '{
    "filter": { "modifiedStartAt": 1767225600000, "modifiedEndAt": 1769817600000 },
    "limit": 200,
    "sort": [{ "field": "modifiedAt", "type": "desc" }],
    "with_record_count": true
  }'

Replace {base-url} with the host OrderPin issued to you.

Built for sync jobs

Incremental by design

Filter on modifiedStartAt / modifiedEndAt to pull only what changed since your last run. Ranges must stay under 31 days.

Stable pagination

Pair skip and limit with an explicit sort so pages never overlap or skip records. Ask for with_record_count once, on the first page.

Honest rate limits

Read X-RateLimit-Limit and X-RateLimit-Remaining from every response; on 429 wait the whole Retry-After. Failed authentication never costs quota.

Precise errors

Every failure returns a numeric code and a msg that names the offending parameter. Check the body code even on HTTP 200 — an unknown API name returns 1020.

Errors at a glance

HTTPCodeMeaning
4012004Missing X-Client-ID header
4012003Missing or malformed Authorization header
4012001Unknown client ID
4012005Invalid API key
4032006Open API not enabled for the account
4001004Invalid request parameter
2001020Unknown API name or version
4292012Rate limit exceeded — honor Retry-After
5001003 / 1012Transient server failure — retry with backoff

Each reference page lists the full 1004 validation messages for that API.

Need credentials?

Client IDs and API keys are issued per store. Email api@orderpin.us with your Store ID — that is all we need to enable the Open API for you. Running several stores? Request a separate set for each Store ID.

Talk to us