{"items":[{"type":"link","label":"Redocly Cafe","link":"/openapi/cafe","routeSlug":"/openapi/cafe","content":{"contentType":"overview","meta":{"name":"Redocly Cafe"},"children":[{"nodeType":"container","panels":[{"title":"Download OpenAPI description","titleTranslationKey":"download.description.title","children":[{"kind":"download","label":"cafe.json","url":"/_bundle/openapi/cafe.json?download"},{"kind":"download","label":"cafe.yaml","url":"/_bundle/openapi/cafe.yaml?download"}]},{"title":"Overview","titleTranslationKey":"info.title","children":[{"kind":"externallink","title":"URL","titleTranslationKey":"info.contact.url","label":"https://redocly.com/contact-us/","url":"https://redocly.com/contact-us/"},{"kind":"email","title":"E-mail","titleTranslationKey":"info.contact.name","email":"team@redocly.com","label":"team@redocly.com","withCopyButton":true,"copyContent":"team@redocly.com"},{"kind":"externallink","title":"License","titleTranslationKey":"info.license","label":"MIT","url":"https://opensource.org/licenses/MIT"},{"kind":"externallink","label":"Terms of Service","labelTranslationKey":"info.termsOfService","url":"https://redocly.com/subscription-agreement"}]},{"title":"Languages","titleTranslationKey":"languages.title","children":[{"kind":"languages","options":[{"key":"curl","title":"curl","lang":"curl"},{"key":"javascript","title":"JavaScript","lang":"JavaScript"},{"key":"node","title":"Node.js","lang":"Node.js"},{"key":"python","title":"Python","lang":"Python"},{"key":"java","title":"Java","lang":"Java"},{"key":"csharp","title":"C#","lang":"C#"},{"key":"php","title":"PHP","lang":"PHP"},{"key":"go","title":"Go","lang":"Go"},{"key":"ruby","title":"Ruby","lang":"Ruby"},{"key":"r","title":"R","lang":"R"},{"key":"payload","title":"Payload","lang":"Payload"}]}]},{"title":"Servers","titleTranslationKey":"servers.title","children":[{"kind":"servers","servers":[{"url":"/_mock/openapi/cafe","description":"Mock server","isMockServer":true},{"url":"https://api.cafe.redocly.com","description":"Live server."}],"mode":"default"}]}],"children":[{"nodeType":"overview-section-wrapper","children":[{"nodeType":"header","level":1,"label":"Redocly Cafe (1.0.0)","showPageActions":true},{"nodeType":"overview-section-wrapper","children":[{"nodeType":"markdoc","content":"Demo API for cafe operators (not customers) to manage menus, orders, and revenue.\nCreate API credentials and try it yourself in a realistic OpenAPI workflow."}],"sectionId":"/openapi/cafe"}],"sectionId":"/openapi/cafe"}]}]}},{"type":"group","label":"Authorization","link":"/openapi/cafe/authorization","routeSlug":"/openapi/cafe/authorization","items":[{"label":"Create OAuth2 client","deprecated":false,"httpVerb":"post","isAdditionalOperation":false,"isWebhook":false,"type":"link","link":"/openapi/cafe/authorization/registeroauth2client","routeSlug":"/openapi/cafe/authorization/registeroauth2client","metadata":{"seo":{"title":"Create OAuth2 client","description":"Register a new OAuth2 client for dynamic client registration.This endpoint implements the Dynamic Client Registration Protocol (RFC 7591), using camelCase field names instead of the RFC's snake_case convention (e.g., redirectUris instead of redirect_uris, grantTypes instead of grant_types).The name field is required. Other fields are optional. If not provided:"}},"content":{"contentType":"item","itemVariant":"httpItem","meta":{"sourceId":"registerOAuth2Client","name":"Create OAuth2 client","isWebhook":false,"pointer":"/paths/~1oauth2~1register/post","hasSamples":true},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"Create OAuth2 client","isWebhook":false,"showPageActions":true}],"panels":[]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Request","labelTranslationKey":"request","deepLinkSuffix":"request"},{"nodeType":"markdoc","content":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Register a new OAuth2 client for dynamic client registration."},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"This endpoint implements the Dynamic Client Registration Protocol (RFC 7591), using camelCase field names instead of the RFC's snake_case convention (e.g., "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"redirectUris"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" instead of "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"redirect_uris"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grantTypes"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" instead of "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grant_types"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":")."},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"The "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"name"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" field is required. Other fields are optional. If not provided:"},"children":[]}]}]},{"$$mdtype":"Node","type":"list","attributes":{"ordered":false,"marker":"-"},"children":[{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"redirectUris"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" defaults to an empty array. Note: When using the "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" grant type, "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"redirectUris"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" must be provided (per RFC 7591 Section 2)."},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"scopes"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" defaults to all available scopes (menu:read, menu:write, orders:read, orders:write, revenue:read)"},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grantTypes"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" defaults to "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"client_credentials"},"children":[]}]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"These defaults interact: a request that supplies only "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"name"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" pairs "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" with an empty "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"redirectUris"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", which is not a usable combination."},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Supply "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"redirectUris"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" explicitly to register the "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" grant, or set "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grantTypes"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" to "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"client_credentials"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" alone for a client that needs no redirect URI."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Refresh tokens require no registration and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" is not a value you can register in "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grantTypes"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"The token endpoint returns a refresh token alongside every access token it issues for the "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" grant, and accepts "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grant_type=refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" from any client presenting a refresh token issued to it."},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"The "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"client_credentials"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" grant returns no refresh token (RFC 6749 Section 4.4.3); those clients request a new access token with their own credentials instead."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Returns the registered client information per RFC 7591, including:"},"children":[]}]}]},{"$$mdtype":"Node","type":"list","attributes":{"ordered":false,"marker":"-"},"children":[{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"clientId"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"clientSecret"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" (must be stored securely)"},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"clientIdIssuedAt"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"clientSecretExpiresAt"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" timestamps"},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"All registered client metadata (name, redirectUris, scopes, grantTypes)"},"children":[]}]}]}]}]},{"nodeType":"item-content","variant":"body","label":"Request Body","labelTranslationKey":"body","required":true,"mediaTypes":["application/json"],"mediaTypeSchemas":{"application/json":{"schemaId":"components/schemas/RegisterClientObject","exampleIds":["paths/~1oauth2~1register/post/requestBody/content/application~1json/examples/RegisterClientObject","paths/~1oauth2~1register/post/requestBody/content/application~1json/examples/RegisterClientForAuthorizationCode"]}},"schemaId":"components/schemas/RegisterClientObject","exampleIds":["paths/~1oauth2~1register/post/requestBody/content/application~1json/examples/RegisterClientObject","paths/~1oauth2~1register/post/requestBody/content/application~1json/examples/RegisterClientForAuthorizationCode"],"pointer":"/paths/~1oauth2~1register/post/requestBody"}],"panels":[{"children":[{"kind":"code-sample","source":{"kind":"code-sample","operationType":"http","method":"POST","path":"/oauth2/register","servers":[{"url":"/_mock/openapi/cafe","description":"Mock server","isMockServer":true},{"url":"https://api.cafe.redocly.com","description":"Live server."}],"parameters":{"path":[],"query":[],"querystring":[],"header":[],"cookie":[]},"security":[],"requestBody":{"application/json":{"schemaId":"components/schemas/RegisterClientObject","exampleIds":["paths/~1oauth2~1register/post/requestBody/content/application~1json/examples/RegisterClientObject","paths/~1oauth2~1register/post/requestBody/content/application~1json/examples/RegisterClientForAuthorizationCode"]}},"responseCodes":["201","400","500"],"pointer":"/oauth2/register","href":"authorization/registeroauth2client","openApiOperationId":"registerOAuth2Client","summary":"Create OAuth2 client"},"isWebhook":false,"hideReplay":false,"servers":[{"url":"/_mock/openapi/cafe","description":"Mock server","isMockServer":true},{"url":"https://api.cafe.redocly.com","description":"Live server."}],"schemaId":"components/schemas/RegisterClientObject","exampleIds":["paths/~1oauth2~1register/post/requestBody/content/application~1json/examples/RegisterClientObject","paths/~1oauth2~1register/post/requestBody/content/application~1json/examples/RegisterClientForAuthorizationCode"],"mediaTypes":["application/json"],"mediaTypeSchemas":{"application/json":{"schemaId":"components/schemas/RegisterClientObject","exampleIds":["paths/~1oauth2~1register/post/requestBody/content/application~1json/examples/RegisterClientObject","paths/~1oauth2~1register/post/requestBody/content/application~1json/examples/RegisterClientForAuthorizationCode"]}},"examples":[{},{}]}]}]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Responses","labelTranslationKey":"responses","deepLinkSuffix":"responses"},{"nodeType":"item-content","variant":"responses","responses":[{"code":"201","description":"OAuth2 client registered successfully.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/OAuth2Client"}},"schemaId":"components/schemas/OAuth2Client"},{"code":"400","description":"Bad request - invalid input parameters.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"500","description":"Internal server error.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"}],"pointer":"/paths/~1oauth2~1register/post/responses"}],"panels":[{"children":[{"kind":"response","headerTitle":"Response","responseCodes":[{"code":"201","schemaId":"components/schemas/OAuth2Client","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/OAuth2Client"}}},{"code":"400","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"500","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"feedback","pageSlug":"/authorization/registeroauth2client"}],"panels":[]}]},"httpPath":"/oauth2/register"}],"content":{"contentType":"group","meta":{"name":"Authorization"},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"Authorization","showPageActions":true},{"nodeType":"markdoc","content":"Create a client to demo the API."}],"panels":[{"children":[{"kind":"group-items","title":"Operations","titleTranslationKey":"operations","items":[{"title":"/oauth2/register","summary":"Create OAuth2 client","prefix":{"name":"post","color":"post"},"badges":[],"link":"/authorization/registeroauth2client","deprecated":false}]}]}]}]}},{"type":"group","label":"Products","link":"/openapi/cafe/products","routeSlug":"/openapi/cafe/products","items":[{"label":"List all menu items","deprecated":false,"httpVerb":"get","isAdditionalOperation":false,"isWebhook":false,"type":"link","link":"/openapi/cafe/products/listmenuitems","routeSlug":"/openapi/cafe/products/listmenuitems","metadata":{"seo":{"title":"List all menu items","description":"Retrieve a collection of menu items with optional filtering and pagination."}},"content":{"contentType":"item","itemVariant":"httpItem","meta":{"sourceId":"listMenuItems","name":"List all menu items","isWebhook":false,"pointer":"/paths/~1menu/get","hasSamples":false},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"List all menu items","isWebhook":false,"showPageActions":true}],"panels":[]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Request","labelTranslationKey":"request","deepLinkSuffix":"request"},{"nodeType":"markdoc","content":"Retrieve a collection of menu items with optional filtering and pagination."},{"nodeType":"item-content","variant":"query","label":"Query","labelTranslationKey":"query","parameters":[{"name":"after","in":"query","schemaId":"schema_10","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Use the "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"endCursor"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" as a value for the "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"after"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" parameter to get the next page."},"children":[]}]}]}]},{"name":"before","in":"query","schemaId":"schema_10","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Use the "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"startCursor"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" as a value for the "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"before"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" parameter to get the previous page."},"children":[]}]}]}]},{"name":"sort","in":"query","schemaId":"schema_10","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Sorts the collection by a single field. Prefix with "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"-"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" for descending order"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"(for example, "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"-price"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"); omit the prefix for ascending order ("},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"price"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":")."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Sortable fields:"},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"name"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"price"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"createdAt"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"updatedAt"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"id"},"children":[]}]}]}],"example":"-price"},{"name":"filter","in":"query","schemaId":"schema_10","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Filters the collection items using space-separated "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"field:value"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" pairs."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Filterable fields:"},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"name"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"category"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"price"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"createdAt"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"id"},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Format:"},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"field1:value1 field2:value2"},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Supported operators:"},"children":[]}]}]}]},{"$$mdtype":"Node","type":"list","attributes":{"ordered":false,"marker":"-"},"children":[{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"field:value"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" - Exact match"},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"field:value1,value2"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" - Match any of the comma-separated values (OR)"},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Time ranges (on "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"createdAt"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"): Use "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"30d"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" (30 days), "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"7d"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" (7 days), "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"1h"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" (1 hour), etc."},"children":[]}]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Examples:"},"children":[]}]}]}]},{"$$mdtype":"Node","type":"list","attributes":{"ordered":false,"marker":"-"},"children":[{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"category:beverage"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" - Filter by a single category."},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"category:beverage,dessert"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" - Filter by multiple categories."},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"createdAt:7d"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" - Menu items created in the last 7 days."},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"name:Latte"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" - Filter by name."},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"category:beverage price:400"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" - Combine multiple filters."},"children":[]}]}]}]}],"example":"category:beverage"},{"name":"search","in":"query","schemaId":"schema_10","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Performs a case-insensitive text search across the searchable fields, returning"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"items where any of them contain the search term as a substring."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Searchable fields:"},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"name"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"photoTextDescription"},"children":[]}]}]}],"example":"Latte"},{"name":"limit","in":"query","schemaId":"schema_11","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Specify the number of results per page."},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"If there is more data, use in combination with "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"after"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" to page through all results."},"children":[]}]}]}],"example":10}],"pointer":"/paths/~1menu/get/parameters"}],"panels":[{"children":[{"kind":"code-sample","source":{"kind":"code-sample","operationType":"http","method":"GET","path":"/menu","servers":[{"url":"/_mock/openapi/cafe","description":"Mock server","isMockServer":true},{"url":"https://api.cafe.redocly.com","description":"Live server."}],"parameters":{"path":[],"query":[{"name":"after","in":"query","required":false,"schemaId":"schema_10"},{"name":"before","in":"query","required":false,"schemaId":"schema_10"},{"name":"sort","in":"query","required":false,"schemaId":"schema_10"},{"name":"filter","in":"query","required":false,"schemaId":"schema_10"},{"name":"search","in":"query","required":false,"schemaId":"schema_10"},{"name":"limit","in":"query","required":false,"example":10,"schemaId":"schema_11"}],"querystring":[],"header":[],"cookie":[]},"security":[],"responseCodes":["200","400","500"],"pointer":"/menu","href":"products/listmenuitems","openApiOperationId":"listMenuItems","summary":"List all menu items"},"isWebhook":false,"hideReplay":false,"servers":[{"url":"/_mock/openapi/cafe","description":"Mock server","isMockServer":true},{"url":"https://api.cafe.redocly.com","description":"Live server."}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Responses","labelTranslationKey":"responses","deepLinkSuffix":"responses"},{"nodeType":"item-content","variant":"responses","responses":[{"code":"200","description":"Successful operation.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/MenuItemList"}},"schemaId":"components/schemas/MenuItemList"},{"code":"400","description":"Bad request - invalid input parameters.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"500","description":"Internal server error.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"}],"pointer":"/paths/~1menu/get/responses"}],"panels":[{"children":[{"kind":"response","headerTitle":"Response","responseCodes":[{"code":"200","schemaId":"components/schemas/MenuItemList","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/MenuItemList"}}},{"code":"400","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"500","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"feedback","pageSlug":"/products/listmenuitems"}],"panels":[]}]},"httpPath":"/menu"},{"label":"Create menu item","deprecated":false,"httpVerb":"post","isAdditionalOperation":false,"isWebhook":false,"type":"link","link":"/openapi/cafe/products/createmenuitem","routeSlug":"/openapi/cafe/products/createmenuitem","metadata":{"seo":{"title":"Create menu item","description":"Create a new menu item."}},"content":{"contentType":"item","itemVariant":"httpItem","meta":{"sourceId":"createMenuItem","name":"Create menu item","isWebhook":false,"pointer":"/paths/~1menu/post","hasSamples":true},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"Create menu item","isWebhook":false,"showPageActions":true}],"panels":[]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Request","labelTranslationKey":"request","deepLinkSuffix":"request"},{"nodeType":"markdoc","content":"Create a new menu item."},{"nodeType":"security","requirements":[{"schemes":[{"name":"OAuth2","scopes":["menu:write"],"type":"oauth2","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"OAuth2 authorization for API access. The token endpoint accepts "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grant_type=authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grant_type=client_credentials"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grant_type=refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]},{"$$mdtype":"Node","type":"heading","attributes":{"level":3},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Differences from the OAuth2 specifications"},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"A standard OAuth2 client library can drive these flows, with the following to account for."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Two behaviors do not conform to the specifications:"},"children":[]}]}]},{"$$mdtype":"Node","type":"list","attributes":{"ordered":false,"marker":"-"},"children":[{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Errors use RFC 9457 problem+json, not RFC 6749 Section 5.2."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" Failures return "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"application/problem+json"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" with "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"type"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"title"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"status"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"instance"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". There is no "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"error"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" or "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"error_description"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" field, so the standard codes ("},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"invalid_grant"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"invalid_client"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"unsupported_grant_type"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":") never appear — branch on the HTTP status and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"title"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" instead. A refresh token that is expired, already rotated, or unrecognized returns "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"400"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" with a "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"title"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" of "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"Refresh token has expired"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" or "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"Invalid refresh token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", where a conformant server would return "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"error: invalid_grant"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" is not a registrable grant type."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" RFC 7591 Section 2 lists it, but "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"/oauth2/register"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" accepts only "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"client_credentials"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" in "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grantTypes"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". Refreshing requires no registration: holding a refresh token issued to the client is the authorization. A consequence is that refresh capability cannot be disabled per client — every "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" grant returns a refresh token, so a client intended for a shared or public device cannot be registered without one."},"children":[]}]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Two are choices the specifications leave to the server:"},"children":[]}]}]},{"$$mdtype":"Node","type":"list","attributes":{"ordered":false,"marker":"-"},"children":[{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Refresh tokens rotate on every use."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" A successful refresh retires the token presented and returns a replacement in "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", as RFC 6749 Section 6 permits and the OAuth2 Security Best Current Practice recommends. Store the new value; the old one stops working. Refresh tokens expire 30 days after they are issued, and rotation restarts that window. The authorization code flow returns a refresh token with every access token; the client credentials flow returns none (RFC 6749 Section 4.4.3)."},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"scope"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" accepts commas."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" The space-delimited form required by RFC 6749 is always accepted and recommended; comma-separated values are additionally tolerated."},"children":[]}]}]}]}],"flows":{"authorizationCode":{"authorizationUrl":"https://api.cafe.redocly.com/oauth2/authorize","tokenUrl":"https://api.cafe.redocly.com/oauth2/token","refreshUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}},"clientCredentials":{"tokenUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}}}}]}]},{"nodeType":"item-content","variant":"body","label":"Request Body","labelTranslationKey":"body","required":true,"mediaTypes":["multipart/form-data"],"mediaTypeSchemas":{"multipart/form-data":{"schemaId":"components/schemas/MenuItem","exampleIds":["paths/~1menu/post/requestBody/content/multipart~1form-data/examples/Beverage","paths/~1menu/post/requestBody/content/multipart~1form-data/examples/Dessert"]}},"schemaId":"components/schemas/MenuItem","exampleIds":["paths/~1menu/post/requestBody/content/multipart~1form-data/examples/Beverage","paths/~1menu/post/requestBody/content/multipart~1form-data/examples/Dessert"],"pointer":"/paths/~1menu/post/requestBody"}],"panels":[{"children":[{"kind":"code-sample","source":{"kind":"code-sample","operationType":"http","method":"POST","path":"/menu","servers":[{"url":"/_mock/openapi/cafe","description":"Mock server","isMockServer":true},{"url":"https://api.cafe.redocly.com","description":"Live server."}],"parameters":{"path":[],"query":[],"querystring":[],"header":[],"cookie":[]},"security":[{"schemes":[{"id":"OAuth2","type":"oauth2","flows":{"authorizationCode":{"authorizationUrl":"https://api.cafe.redocly.com/oauth2/authorize","tokenUrl":"https://api.cafe.redocly.com/oauth2/token","refreshUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}},"clientCredentials":{"tokenUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}}}}],"scopes":["menu:write"]}],"requestBody":{"multipart/form-data":{"schemaId":"components/schemas/MenuItem","exampleIds":["paths/~1menu/post/requestBody/content/multipart~1form-data/examples/Beverage","paths/~1menu/post/requestBody/content/multipart~1form-data/examples/Dessert"]}},"responseCodes":["201","400","401","403","409","500"],"pointer":"/menu","href":"products/createmenuitem","openApiOperationId":"createMenuItem","summary":"Create menu item"},"isWebhook":false,"hideReplay":false,"servers":[{"url":"/_mock/openapi/cafe","description":"Mock server","isMockServer":true},{"url":"https://api.cafe.redocly.com","description":"Live server."}],"schemaId":"components/schemas/MenuItem","exampleIds":["paths/~1menu/post/requestBody/content/multipart~1form-data/examples/Beverage","paths/~1menu/post/requestBody/content/multipart~1form-data/examples/Dessert"],"mediaTypes":["multipart/form-data"],"mediaTypeSchemas":{"multipart/form-data":{"schemaId":"components/schemas/MenuItem","exampleIds":["paths/~1menu/post/requestBody/content/multipart~1form-data/examples/Beverage","paths/~1menu/post/requestBody/content/multipart~1form-data/examples/Dessert"]}},"examples":[{},{}]}]}]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Responses","labelTranslationKey":"responses","deepLinkSuffix":"responses"},{"nodeType":"item-content","variant":"responses","responses":[{"code":"201","description":"Menu item created successfully.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/MenuItem","exampleIds":["paths/~1menu/post/responses/201/content/application~1json/examples/MenuItemResponse"]}},"schemaId":"components/schemas/MenuItem","exampleIds":["paths/~1menu/post/responses/201/content/application~1json/examples/MenuItemResponse"]},{"code":"400","description":"Bad request - invalid input parameters.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"401","description":"Unauthorized - authorization required.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"403","description":"Forbidden - insufficient permissions.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"409","description":"Conflict - entity already exists.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"500","description":"Internal server error.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"}],"pointer":"/paths/~1menu/post/responses"}],"panels":[{"children":[{"kind":"response","headerTitle":"Response","responseCodes":[{"code":"201","schemaId":"components/schemas/MenuItem","exampleIds":["paths/~1menu/post/responses/201/content/application~1json/examples/MenuItemResponse"],"mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/MenuItem","exampleIds":["paths/~1menu/post/responses/201/content/application~1json/examples/MenuItemResponse"]}}},{"code":"400","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"401","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"403","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"409","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"500","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"feedback","pageSlug":"/products/createmenuitem"}],"panels":[]}]},"httpPath":"/menu"},{"label":"Delete a menu item","deprecated":false,"httpVerb":"delete","isAdditionalOperation":false,"isWebhook":false,"type":"link","link":"/openapi/cafe/products/deletemenuitem","routeSlug":"/openapi/cafe/products/deletemenuitem","metadata":{"seo":{"title":"Delete a menu item","description":"Delete an existing menu item."}},"content":{"contentType":"item","itemVariant":"httpItem","meta":{"sourceId":"deleteMenuItem","name":"Delete a menu item","isWebhook":false,"pointer":"/paths/~1menu~1{menuItemId}/delete","hasSamples":false},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"Delete a menu item","isWebhook":false,"showPageActions":true}],"panels":[]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Request","labelTranslationKey":"request","deepLinkSuffix":"request"},{"nodeType":"markdoc","content":"Delete an existing menu item."},{"nodeType":"security","requirements":[{"schemes":[{"name":"OAuth2","scopes":["menu:write"],"type":"oauth2","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"OAuth2 authorization for API access. The token endpoint accepts "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grant_type=authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grant_type=client_credentials"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grant_type=refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]},{"$$mdtype":"Node","type":"heading","attributes":{"level":3},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Differences from the OAuth2 specifications"},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"A standard OAuth2 client library can drive these flows, with the following to account for."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Two behaviors do not conform to the specifications:"},"children":[]}]}]},{"$$mdtype":"Node","type":"list","attributes":{"ordered":false,"marker":"-"},"children":[{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Errors use RFC 9457 problem+json, not RFC 6749 Section 5.2."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" Failures return "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"application/problem+json"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" with "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"type"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"title"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"status"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"instance"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". There is no "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"error"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" or "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"error_description"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" field, so the standard codes ("},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"invalid_grant"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"invalid_client"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"unsupported_grant_type"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":") never appear — branch on the HTTP status and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"title"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" instead. A refresh token that is expired, already rotated, or unrecognized returns "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"400"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" with a "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"title"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" of "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"Refresh token has expired"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" or "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"Invalid refresh token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", where a conformant server would return "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"error: invalid_grant"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" is not a registrable grant type."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" RFC 7591 Section 2 lists it, but "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"/oauth2/register"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" accepts only "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"client_credentials"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" in "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grantTypes"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". Refreshing requires no registration: holding a refresh token issued to the client is the authorization. A consequence is that refresh capability cannot be disabled per client — every "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" grant returns a refresh token, so a client intended for a shared or public device cannot be registered without one."},"children":[]}]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Two are choices the specifications leave to the server:"},"children":[]}]}]},{"$$mdtype":"Node","type":"list","attributes":{"ordered":false,"marker":"-"},"children":[{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Refresh tokens rotate on every use."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" A successful refresh retires the token presented and returns a replacement in "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", as RFC 6749 Section 6 permits and the OAuth2 Security Best Current Practice recommends. Store the new value; the old one stops working. Refresh tokens expire 30 days after they are issued, and rotation restarts that window. The authorization code flow returns a refresh token with every access token; the client credentials flow returns none (RFC 6749 Section 4.4.3)."},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"scope"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" accepts commas."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" The space-delimited form required by RFC 6749 is always accepted and recommended; comma-separated values are additionally tolerated."},"children":[]}]}]}]}],"flows":{"authorizationCode":{"authorizationUrl":"https://api.cafe.redocly.com/oauth2/authorize","tokenUrl":"https://api.cafe.redocly.com/oauth2/token","refreshUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}},"clientCredentials":{"tokenUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}}}}]}]},{"nodeType":"item-content","variant":"path","label":"Path","labelTranslationKey":"path","parameters":[{"name":"menuItemId","in":"path","schemaId":"schema_12","description":"ID of the menu item to retrieve.","required":true}],"pointer":"/paths/~1menu~1{menuItemId}/delete/parameters"}],"panels":[{"children":[{"kind":"code-sample","source":{"kind":"code-sample","operationType":"http","method":"DELETE","path":"/menu/{menuItemId}","servers":[{"url":"/_mock/openapi/cafe","description":"Mock server","isMockServer":true},{"url":"https://api.cafe.redocly.com","description":"Live server."}],"parameters":{"path":[{"name":"menuItemId","in":"path","required":true,"schemaId":"schema_12"}],"query":[],"querystring":[],"header":[],"cookie":[]},"security":[{"schemes":[{"id":"OAuth2","type":"oauth2","flows":{"authorizationCode":{"authorizationUrl":"https://api.cafe.redocly.com/oauth2/authorize","tokenUrl":"https://api.cafe.redocly.com/oauth2/token","refreshUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}},"clientCredentials":{"tokenUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}}}}],"scopes":["menu:write"]}],"responseCodes":["204","400","401","403","404","500"],"pointer":"/menu/{menuItemId}","href":"products/deletemenuitem","openApiOperationId":"deleteMenuItem","summary":"Delete a menu item"},"isWebhook":false,"hideReplay":false,"servers":[{"url":"/_mock/openapi/cafe","description":"Mock server","isMockServer":true},{"url":"https://api.cafe.redocly.com","description":"Live server."}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Responses","labelTranslationKey":"responses","deepLinkSuffix":"responses"},{"nodeType":"item-content","variant":"responses","responses":[{"code":"204","description":"Menu item deleted successfully."},{"code":"400","description":"Bad request - invalid input parameters.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"401","description":"Unauthorized - authorization required.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"403","description":"Forbidden - insufficient permissions.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"404","description":"Resource not found.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"500","description":"Internal server error.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"}],"pointer":"/paths/~1menu~1{menuItemId}/delete/responses"}],"panels":[{"children":[{"kind":"response","headerTitle":"Response","responseCodes":[{"code":"204"},{"code":"400","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"401","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"403","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"404","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"500","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"feedback","pageSlug":"/products/deletemenuitem"}],"panels":[]}]},"httpPath":"/menu/{menuItemId}"},{"label":"Retrieve a menu item photo","deprecated":false,"httpVerb":"get","isAdditionalOperation":false,"isWebhook":false,"type":"link","link":"/openapi/cafe/products/getmenuitemphoto","routeSlug":"/openapi/cafe/products/getmenuitemphoto","metadata":{"seo":{"title":"Retrieve a menu item photo","description":"Retrieve the product photo image for a specific menu item."}},"content":{"contentType":"item","itemVariant":"httpItem","meta":{"sourceId":"getMenuItemPhoto","name":"Retrieve a menu item photo","isWebhook":false,"pointer":"/paths/~1menu-item-images~1{menuItemId}/get","hasSamples":false},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"Retrieve a menu item photo","isWebhook":false,"showPageActions":true}],"panels":[]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Request","labelTranslationKey":"request","deepLinkSuffix":"request"},{"nodeType":"markdoc","content":"Retrieve the product photo image for a specific menu item."},{"nodeType":"item-content","variant":"path","label":"Path","labelTranslationKey":"path","parameters":[{"name":"menuItemId","in":"path","schemaId":"schema_12","description":"ID of the menu item to retrieve.","required":true}],"pointer":"/paths/~1menu-item-images~1{menuItemId}/get/parameters"},{"nodeType":"item-content","variant":"query","label":"Query","labelTranslationKey":"query","parameters":[{"name":"photoSize","in":"query","schemaId":"schema_13","description":"Photo size to retrieve."}],"pointer":"/paths/~1menu-item-images~1{menuItemId}/get/parameters"}],"panels":[{"children":[{"kind":"code-sample","source":{"kind":"code-sample","operationType":"http","method":"GET","path":"/menu-item-images/{menuItemId}","servers":[{"url":"/_mock/openapi/cafe","description":"Mock server","isMockServer":true},{"url":"https://api.cafe.redocly.com","description":"Live server."}],"parameters":{"path":[{"name":"menuItemId","in":"path","required":true,"schemaId":"schema_12"}],"query":[{"name":"photoSize","in":"query","required":false,"schemaId":"schema_13"}],"querystring":[],"header":[],"cookie":[]},"security":[],"responseCodes":["200","404","500"],"pointer":"/menu-item-images/{menuItemId}","href":"products/getmenuitemphoto","openApiOperationId":"getMenuItemPhoto","summary":"Retrieve a menu item photo"},"isWebhook":false,"hideReplay":false,"servers":[{"url":"/_mock/openapi/cafe","description":"Mock server","isMockServer":true},{"url":"https://api.cafe.redocly.com","description":"Live server."}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Responses","labelTranslationKey":"responses","deepLinkSuffix":"responses"},{"nodeType":"item-content","variant":"responses","responses":[{"code":"200","description":"Menu item photo retrieved successfully.","mediaType":"image/png","mediaTypes":["image/png","text/plain"],"mediaTypeContent":{"image/png":{"schemaId":"schema_14"},"text/plain":{"schemaId":"schema_15"}},"schemaId":"schema_14"},{"code":"404","description":"Resource not found.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"500","description":"Internal server error.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"}],"pointer":"/paths/~1menu-item-images~1{menuItemId}/get/responses"}],"panels":[{"children":[{"kind":"response","headerTitle":"Response","responseCodes":[{"code":"200","schemaId":"schema_14","mediaTypes":["image/png","text/plain"],"mediaTypeContent":{"image/png":{"schemaId":"schema_14"},"text/plain":{"schemaId":"schema_15"}}},{"code":"404","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"500","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"feedback","pageSlug":"/products/getmenuitemphoto"}],"panels":[]}]},"httpPath":"/menu-item-images/{menuItemId}"}],"content":{"contentType":"group","meta":{"name":"Products"},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"Products","showPageActions":true},{"nodeType":"markdoc","content":"Operations related to products."}],"panels":[{"children":[{"kind":"group-items","title":"Operations","titleTranslationKey":"operations","items":[{"title":"/menu","summary":"List all menu items","prefix":{"name":"get","color":"get"},"badges":[],"link":"/products/listmenuitems","deprecated":false},{"title":"/menu","summary":"Create menu item","prefix":{"name":"post","color":"post"},"badges":[],"link":"/products/createmenuitem","deprecated":false},{"title":"/menu/{menuItemId}","summary":"Delete a menu item","prefix":{"name":"delete","color":"delete"},"badges":[],"link":"/products/deletemenuitem","deprecated":false},{"title":"/menu-item-images/{menuItemId}","summary":"Retrieve a menu item photo","prefix":{"name":"get","color":"get"},"badges":[],"link":"/products/getmenuitemphoto","deprecated":false}]}]}]}]}},{"type":"group","label":"Orders","link":"/openapi/cafe/orders","routeSlug":"/openapi/cafe/orders","items":[{"label":"List all orders","deprecated":false,"httpVerb":"get","isAdditionalOperation":false,"isWebhook":false,"type":"link","link":"/openapi/cafe/orders/listorders","routeSlug":"/openapi/cafe/orders/listorders","metadata":{"seo":{"title":"List all orders","description":"Retrieve a collection of orders with optional filtering and pagination."}},"content":{"contentType":"item","itemVariant":"httpItem","meta":{"sourceId":"listOrders","name":"List all orders","isWebhook":false,"pointer":"/paths/~1orders/get","hasSamples":false},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"List all orders","isWebhook":false,"showPageActions":true}],"panels":[]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Request","labelTranslationKey":"request","deepLinkSuffix":"request"},{"nodeType":"markdoc","content":"Retrieve a collection of orders with optional filtering and pagination."},{"nodeType":"security","requirements":[{"schemes":[{"name":"OAuth2","scopes":["orders:read"],"type":"oauth2","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"OAuth2 authorization for API access. The token endpoint accepts "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grant_type=authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grant_type=client_credentials"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grant_type=refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]},{"$$mdtype":"Node","type":"heading","attributes":{"level":3},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Differences from the OAuth2 specifications"},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"A standard OAuth2 client library can drive these flows, with the following to account for."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Two behaviors do not conform to the specifications:"},"children":[]}]}]},{"$$mdtype":"Node","type":"list","attributes":{"ordered":false,"marker":"-"},"children":[{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Errors use RFC 9457 problem+json, not RFC 6749 Section 5.2."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" Failures return "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"application/problem+json"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" with "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"type"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"title"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"status"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"instance"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". There is no "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"error"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" or "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"error_description"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" field, so the standard codes ("},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"invalid_grant"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"invalid_client"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"unsupported_grant_type"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":") never appear — branch on the HTTP status and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"title"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" instead. A refresh token that is expired, already rotated, or unrecognized returns "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"400"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" with a "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"title"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" of "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"Refresh token has expired"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" or "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"Invalid refresh token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", where a conformant server would return "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"error: invalid_grant"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" is not a registrable grant type."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" RFC 7591 Section 2 lists it, but "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"/oauth2/register"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" accepts only "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"client_credentials"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" in "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grantTypes"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". Refreshing requires no registration: holding a refresh token issued to the client is the authorization. A consequence is that refresh capability cannot be disabled per client — every "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" grant returns a refresh token, so a client intended for a shared or public device cannot be registered without one."},"children":[]}]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Two are choices the specifications leave to the server:"},"children":[]}]}]},{"$$mdtype":"Node","type":"list","attributes":{"ordered":false,"marker":"-"},"children":[{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Refresh tokens rotate on every use."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" A successful refresh retires the token presented and returns a replacement in "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", as RFC 6749 Section 6 permits and the OAuth2 Security Best Current Practice recommends. Store the new value; the old one stops working. Refresh tokens expire 30 days after they are issued, and rotation restarts that window. The authorization code flow returns a refresh token with every access token; the client credentials flow returns none (RFC 6749 Section 4.4.3)."},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"scope"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" accepts commas."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" The space-delimited form required by RFC 6749 is always accepted and recommended; comma-separated values are additionally tolerated."},"children":[]}]}]}]}],"flows":{"authorizationCode":{"authorizationUrl":"https://api.cafe.redocly.com/oauth2/authorize","tokenUrl":"https://api.cafe.redocly.com/oauth2/token","refreshUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}},"clientCredentials":{"tokenUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}}}}]}]},{"nodeType":"item-content","variant":"query","label":"Query","labelTranslationKey":"query","parameters":[{"name":"filter","in":"query","schemaId":"schema_10","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Filters the collection items using space-separated "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"field:value"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" pairs."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Filterable fields:"},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"customerName"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"status"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"totalPrice"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"createdAt"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"id"},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Format:"},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"field1:value1 field2:value2"},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Supported operators:"},"children":[]}]}]}]},{"$$mdtype":"Node","type":"list","attributes":{"ordered":false,"marker":"-"},"children":[{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"field:value"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" - Exact match"},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"field:value1,value2"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" - Match any of the comma-separated values (OR)"},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Time ranges (on "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"createdAt"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"): Use "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"30d"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" (30 days), "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"7d"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" (7 days), "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"1h"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" (1 hour), etc."},"children":[]}]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Examples:"},"children":[]}]}]}]},{"$$mdtype":"Node","type":"list","attributes":{"ordered":false,"marker":"-"},"children":[{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"status:placed"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" - Filter by a single status."},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"status:placed,completed"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" - Filter by multiple statuses."},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"createdAt:30d"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" - Orders created in the last 30 days."},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"id:ord_01h1s5z6vf2mm1mz3hevnn9va7"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" - Filter by a specific order ID."},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"status:placed createdAt:7d"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" - Combine multiple filters."},"children":[]}]}]}]}],"example":"status:placed"},{"name":"sort","in":"query","schemaId":"schema_10","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Sorts the collection by a single field. Prefix with "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"-"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" for descending order"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"(for example, "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"-createdAt"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"); omit the prefix for ascending order ("},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"createdAt"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":")."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Sortable fields:"},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"customerName"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"status"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"totalPrice"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"createdAt"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"updatedAt"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"id"},"children":[]}]}]}],"example":"-createdAt"},{"name":"limit","in":"query","schemaId":"schema_11","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Specify the number of results per page."},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"If there is more data, use in combination with "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"after"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" to page through all results."},"children":[]}]}]}],"example":10},{"name":"after","in":"query","schemaId":"schema_10","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Use the "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"endCursor"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" as a value for the "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"after"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" parameter to get the next page."},"children":[]}]}]}]},{"name":"before","in":"query","schemaId":"schema_10","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Use the "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"startCursor"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" as a value for the "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"before"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" parameter to get the previous page."},"children":[]}]}]}]},{"name":"search","in":"query","schemaId":"schema_10","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Performs a case-insensitive text search across the searchable fields, returning"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"items where any of them contain the search term as a substring."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Searchable fields:"},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"customerName"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"id"},"children":[]}]}]}],"example":"John"}],"pointer":"/paths/~1orders/get/parameters"}],"panels":[{"children":[{"kind":"code-sample","source":{"kind":"code-sample","operationType":"http","method":"GET","path":"/orders","servers":[{"url":"/_mock/openapi/cafe","description":"Mock server","isMockServer":true},{"url":"https://api.cafe.redocly.com","description":"Live server."}],"parameters":{"path":[],"query":[{"name":"filter","in":"query","required":false,"schemaId":"schema_10"},{"name":"sort","in":"query","required":false,"schemaId":"schema_10"},{"name":"limit","in":"query","required":false,"example":10,"schemaId":"schema_11"},{"name":"after","in":"query","required":false,"schemaId":"schema_10"},{"name":"before","in":"query","required":false,"schemaId":"schema_10"},{"name":"search","in":"query","required":false,"schemaId":"schema_10"}],"querystring":[],"header":[],"cookie":[]},"security":[{"schemes":[{"id":"OAuth2","type":"oauth2","flows":{"authorizationCode":{"authorizationUrl":"https://api.cafe.redocly.com/oauth2/authorize","tokenUrl":"https://api.cafe.redocly.com/oauth2/token","refreshUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}},"clientCredentials":{"tokenUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}}}}],"scopes":["orders:read"]}],"responseCodes":["200","400","401","403","500"],"pointer":"/orders","href":"orders/listorders","openApiOperationId":"listOrders","summary":"List all orders"},"isWebhook":false,"hideReplay":false,"servers":[{"url":"/_mock/openapi/cafe","description":"Mock server","isMockServer":true},{"url":"https://api.cafe.redocly.com","description":"Live server."}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Responses","labelTranslationKey":"responses","deepLinkSuffix":"responses"},{"nodeType":"item-content","variant":"responses","responses":[{"code":"200","description":"Successful operation.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/OrderList"}},"schemaId":"components/schemas/OrderList"},{"code":"400","description":"Bad request - invalid input parameters.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"401","description":"Unauthorized - authorization required.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"403","description":"Forbidden - insufficient permissions.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"500","description":"Internal server error.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"}],"pointer":"/paths/~1orders/get/responses"}],"panels":[{"children":[{"kind":"response","headerTitle":"Response","responseCodes":[{"code":"200","schemaId":"components/schemas/OrderList","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/OrderList"}}},{"code":"400","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"401","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"403","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"500","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"feedback","pageSlug":"/orders/listorders"}],"panels":[]}]},"httpPath":"/orders"},{"label":"Create order","deprecated":false,"httpVerb":"post","isAdditionalOperation":false,"isWebhook":false,"type":"link","link":"/openapi/cafe/orders/createorder","routeSlug":"/openapi/cafe/orders/createorder","metadata":{"seo":{"title":"Create order","description":"Create a new order. Order items cannot be changed - if they need to be updated, cancel the order and place a new one."}},"content":{"contentType":"item","itemVariant":"httpItem","meta":{"sourceId":"createOrder","name":"Create order","isWebhook":false,"pointer":"/paths/~1orders/post","hasSamples":true},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"Create order","isWebhook":false,"showPageActions":true}],"panels":[]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Request","labelTranslationKey":"request","deepLinkSuffix":"request"},{"nodeType":"markdoc","content":"Create a new order.\nOrder items cannot be changed - if they need to be updated, cancel the order and place a new one.\n"},{"nodeType":"security","requirements":[{"schemes":[{"name":"OAuth2","scopes":["orders:write"],"type":"oauth2","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"OAuth2 authorization for API access. The token endpoint accepts "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grant_type=authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grant_type=client_credentials"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grant_type=refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]},{"$$mdtype":"Node","type":"heading","attributes":{"level":3},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Differences from the OAuth2 specifications"},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"A standard OAuth2 client library can drive these flows, with the following to account for."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Two behaviors do not conform to the specifications:"},"children":[]}]}]},{"$$mdtype":"Node","type":"list","attributes":{"ordered":false,"marker":"-"},"children":[{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Errors use RFC 9457 problem+json, not RFC 6749 Section 5.2."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" Failures return "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"application/problem+json"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" with "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"type"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"title"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"status"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"instance"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". There is no "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"error"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" or "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"error_description"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" field, so the standard codes ("},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"invalid_grant"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"invalid_client"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"unsupported_grant_type"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":") never appear — branch on the HTTP status and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"title"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" instead. A refresh token that is expired, already rotated, or unrecognized returns "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"400"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" with a "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"title"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" of "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"Refresh token has expired"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" or "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"Invalid refresh token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", where a conformant server would return "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"error: invalid_grant"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" is not a registrable grant type."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" RFC 7591 Section 2 lists it, but "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"/oauth2/register"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" accepts only "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"client_credentials"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" in "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grantTypes"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". Refreshing requires no registration: holding a refresh token issued to the client is the authorization. A consequence is that refresh capability cannot be disabled per client — every "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" grant returns a refresh token, so a client intended for a shared or public device cannot be registered without one."},"children":[]}]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Two are choices the specifications leave to the server:"},"children":[]}]}]},{"$$mdtype":"Node","type":"list","attributes":{"ordered":false,"marker":"-"},"children":[{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Refresh tokens rotate on every use."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" A successful refresh retires the token presented and returns a replacement in "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", as RFC 6749 Section 6 permits and the OAuth2 Security Best Current Practice recommends. Store the new value; the old one stops working. Refresh tokens expire 30 days after they are issued, and rotation restarts that window. The authorization code flow returns a refresh token with every access token; the client credentials flow returns none (RFC 6749 Section 4.4.3)."},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"scope"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" accepts commas."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" The space-delimited form required by RFC 6749 is always accepted and recommended; comma-separated values are additionally tolerated."},"children":[]}]}]}]}],"flows":{"authorizationCode":{"authorizationUrl":"https://api.cafe.redocly.com/oauth2/authorize","tokenUrl":"https://api.cafe.redocly.com/oauth2/token","refreshUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}},"clientCredentials":{"tokenUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}}}}]}]},{"nodeType":"item-content","variant":"body","label":"Request Body","labelTranslationKey":"body","required":true,"mediaTypes":["application/json"],"mediaTypeSchemas":{"application/json":{"schemaId":"components/schemas/Order","exampleIds":["paths/~1orders/post/requestBody/content/application~1json/examples/OrderRequest"]}},"schemaId":"components/schemas/Order","exampleIds":["paths/~1orders/post/requestBody/content/application~1json/examples/OrderRequest"],"pointer":"/paths/~1orders/post/requestBody"}],"panels":[{"children":[{"kind":"code-sample","source":{"kind":"code-sample","operationType":"http","method":"POST","path":"/orders","servers":[{"url":"/_mock/openapi/cafe","description":"Mock server","isMockServer":true},{"url":"https://api.cafe.redocly.com","description":"Live server."}],"parameters":{"path":[],"query":[],"querystring":[],"header":[],"cookie":[]},"security":[{"schemes":[{"id":"OAuth2","type":"oauth2","flows":{"authorizationCode":{"authorizationUrl":"https://api.cafe.redocly.com/oauth2/authorize","tokenUrl":"https://api.cafe.redocly.com/oauth2/token","refreshUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}},"clientCredentials":{"tokenUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}}}}],"scopes":["orders:write"]}],"requestBody":{"application/json":{"schemaId":"components/schemas/Order","exampleIds":["paths/~1orders/post/requestBody/content/application~1json/examples/OrderRequest"]}},"responseCodes":["201","400","401","403","500"],"pointer":"/orders","href":"orders/createorder","openApiOperationId":"createOrder","summary":"Create order"},"isWebhook":false,"hideReplay":false,"servers":[{"url":"/_mock/openapi/cafe","description":"Mock server","isMockServer":true},{"url":"https://api.cafe.redocly.com","description":"Live server."}],"schemaId":"components/schemas/Order","exampleIds":["paths/~1orders/post/requestBody/content/application~1json/examples/OrderRequest"],"mediaTypes":["application/json"],"mediaTypeSchemas":{"application/json":{"schemaId":"components/schemas/Order","exampleIds":["paths/~1orders/post/requestBody/content/application~1json/examples/OrderRequest"]}},"examples":[{}]}]}]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Responses","labelTranslationKey":"responses","deepLinkSuffix":"responses"},{"nodeType":"item-content","variant":"responses","responses":[{"code":"201","description":"Order placed successfully.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/Order","exampleIds":["paths/~1orders/post/responses/201/content/application~1json/examples/OrderResponse"]}},"schemaId":"components/schemas/Order","exampleIds":["paths/~1orders/post/responses/201/content/application~1json/examples/OrderResponse"]},{"code":"400","description":"Bad request - invalid input parameters.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"401","description":"Unauthorized - authorization required.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"403","description":"Forbidden - insufficient permissions.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"500","description":"Internal server error.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"}],"pointer":"/paths/~1orders/post/responses"}],"panels":[{"children":[{"kind":"response","headerTitle":"Response","responseCodes":[{"code":"201","schemaId":"components/schemas/Order","exampleIds":["paths/~1orders/post/responses/201/content/application~1json/examples/OrderResponse"],"mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/Order","exampleIds":["paths/~1orders/post/responses/201/content/application~1json/examples/OrderResponse"]}}},{"code":"400","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"401","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"403","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"500","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"feedback","pageSlug":"/orders/createorder"}],"panels":[]}]},"httpPath":"/orders"},{"label":"Retrieve an order","deprecated":false,"httpVerb":"get","isAdditionalOperation":false,"isWebhook":false,"type":"link","link":"/openapi/cafe/orders/getorderbyid","routeSlug":"/openapi/cafe/orders/getorderbyid","metadata":{"seo":{"title":"Retrieve an order","description":"Retrieve a single order by its ID."}},"content":{"contentType":"item","itemVariant":"httpItem","meta":{"sourceId":"getOrderById","name":"Retrieve an order","isWebhook":false,"pointer":"/paths/~1orders~1{orderId}/get","hasSamples":false},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"Retrieve an order","isWebhook":false,"showPageActions":true}],"panels":[]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Request","labelTranslationKey":"request","deepLinkSuffix":"request"},{"nodeType":"markdoc","content":"Retrieve a single order by its ID."},{"nodeType":"security","requirements":[{"schemes":[{"name":"OAuth2","scopes":["orders:read"],"type":"oauth2","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"OAuth2 authorization for API access. The token endpoint accepts "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grant_type=authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grant_type=client_credentials"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grant_type=refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]},{"$$mdtype":"Node","type":"heading","attributes":{"level":3},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Differences from the OAuth2 specifications"},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"A standard OAuth2 client library can drive these flows, with the following to account for."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Two behaviors do not conform to the specifications:"},"children":[]}]}]},{"$$mdtype":"Node","type":"list","attributes":{"ordered":false,"marker":"-"},"children":[{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Errors use RFC 9457 problem+json, not RFC 6749 Section 5.2."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" Failures return "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"application/problem+json"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" with "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"type"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"title"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"status"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"instance"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". There is no "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"error"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" or "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"error_description"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" field, so the standard codes ("},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"invalid_grant"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"invalid_client"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"unsupported_grant_type"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":") never appear — branch on the HTTP status and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"title"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" instead. A refresh token that is expired, already rotated, or unrecognized returns "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"400"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" with a "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"title"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" of "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"Refresh token has expired"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" or "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"Invalid refresh token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", where a conformant server would return "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"error: invalid_grant"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" is not a registrable grant type."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" RFC 7591 Section 2 lists it, but "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"/oauth2/register"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" accepts only "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"client_credentials"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" in "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grantTypes"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". Refreshing requires no registration: holding a refresh token issued to the client is the authorization. A consequence is that refresh capability cannot be disabled per client — every "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" grant returns a refresh token, so a client intended for a shared or public device cannot be registered without one."},"children":[]}]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Two are choices the specifications leave to the server:"},"children":[]}]}]},{"$$mdtype":"Node","type":"list","attributes":{"ordered":false,"marker":"-"},"children":[{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Refresh tokens rotate on every use."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" A successful refresh retires the token presented and returns a replacement in "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", as RFC 6749 Section 6 permits and the OAuth2 Security Best Current Practice recommends. Store the new value; the old one stops working. Refresh tokens expire 30 days after they are issued, and rotation restarts that window. The authorization code flow returns a refresh token with every access token; the client credentials flow returns none (RFC 6749 Section 4.4.3)."},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"scope"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" accepts commas."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" The space-delimited form required by RFC 6749 is always accepted and recommended; comma-separated values are additionally tolerated."},"children":[]}]}]}]}],"flows":{"authorizationCode":{"authorizationUrl":"https://api.cafe.redocly.com/oauth2/authorize","tokenUrl":"https://api.cafe.redocly.com/oauth2/token","refreshUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}},"clientCredentials":{"tokenUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}}}}]}]},{"nodeType":"item-content","variant":"path","label":"Path","labelTranslationKey":"path","parameters":[{"name":"orderId","in":"path","schemaId":"schema_16","description":"ID of the order to retrieve.","required":true,"example":"ord_01h1s5z6vf2mm1mz3hevnn9va7"}],"pointer":"/paths/~1orders~1{orderId}/get/parameters"}],"panels":[{"children":[{"kind":"code-sample","source":{"kind":"code-sample","operationType":"http","method":"GET","path":"/orders/{orderId}","servers":[{"url":"/_mock/openapi/cafe","description":"Mock server","isMockServer":true},{"url":"https://api.cafe.redocly.com","description":"Live server."}],"parameters":{"path":[{"name":"orderId","in":"path","required":true,"example":"ord_01h1s5z6vf2mm1mz3hevnn9va7","schemaId":"schema_16"}],"query":[],"querystring":[],"header":[],"cookie":[]},"security":[{"schemes":[{"id":"OAuth2","type":"oauth2","flows":{"authorizationCode":{"authorizationUrl":"https://api.cafe.redocly.com/oauth2/authorize","tokenUrl":"https://api.cafe.redocly.com/oauth2/token","refreshUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}},"clientCredentials":{"tokenUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}}}}],"scopes":["orders:read"]}],"responseCodes":["200","400","401","403","404","500"],"pointer":"/orders/{orderId}","href":"orders/getorderbyid","openApiOperationId":"getOrderById","summary":"Retrieve an order"},"isWebhook":false,"hideReplay":false,"servers":[{"url":"/_mock/openapi/cafe","description":"Mock server","isMockServer":true},{"url":"https://api.cafe.redocly.com","description":"Live server."}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Responses","labelTranslationKey":"responses","deepLinkSuffix":"responses"},{"nodeType":"item-content","variant":"responses","responses":[{"code":"200","description":"Successful operation.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/Order","exampleIds":["paths/~1orders~1{orderId}/get/responses/200/content/application~1json/examples/OrderResponse"]}},"schemaId":"components/schemas/Order","exampleIds":["paths/~1orders~1{orderId}/get/responses/200/content/application~1json/examples/OrderResponse"]},{"code":"400","description":"Bad request - invalid input parameters.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"401","description":"Unauthorized - authorization required.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"403","description":"Forbidden - insufficient permissions.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"404","description":"Resource not found.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"500","description":"Internal server error.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"}],"pointer":"/paths/~1orders~1{orderId}/get/responses"}],"panels":[{"children":[{"kind":"response","headerTitle":"Response","responseCodes":[{"code":"200","schemaId":"components/schemas/Order","exampleIds":["paths/~1orders~1{orderId}/get/responses/200/content/application~1json/examples/OrderResponse"],"mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/Order","exampleIds":["paths/~1orders~1{orderId}/get/responses/200/content/application~1json/examples/OrderResponse"]}}},{"code":"400","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"401","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"403","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"404","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"500","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"feedback","pageSlug":"/orders/getorderbyid"}],"panels":[]}]},"httpPath":"/orders/{orderId}"},{"label":"Partially update an order","deprecated":false,"httpVerb":"patch","isAdditionalOperation":false,"isWebhook":false,"type":"link","link":"/openapi/cafe/orders/updateorder","routeSlug":"/openapi/cafe/orders/updateorder","metadata":{"seo":{"title":"Partially update an order","description":"Update an existing order status. Order items cannot be changed - if they need to be updated, cancel the order and place a new one."}},"content":{"contentType":"item","itemVariant":"httpItem","meta":{"sourceId":"updateOrder","name":"Partially update an order","isWebhook":false,"pointer":"/paths/~1orders~1{orderId}/patch","hasSamples":true},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"Partially update an order","isWebhook":false,"showPageActions":true}],"panels":[]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Request","labelTranslationKey":"request","deepLinkSuffix":"request"},{"nodeType":"markdoc","content":"Update an existing order status.\nOrder items cannot be changed - if they need to be updated, cancel the order and place a new one.\n"},{"nodeType":"security","requirements":[{"schemes":[{"name":"OAuth2","scopes":["orders:write"],"type":"oauth2","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"OAuth2 authorization for API access. The token endpoint accepts "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grant_type=authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grant_type=client_credentials"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grant_type=refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]},{"$$mdtype":"Node","type":"heading","attributes":{"level":3},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Differences from the OAuth2 specifications"},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"A standard OAuth2 client library can drive these flows, with the following to account for."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Two behaviors do not conform to the specifications:"},"children":[]}]}]},{"$$mdtype":"Node","type":"list","attributes":{"ordered":false,"marker":"-"},"children":[{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Errors use RFC 9457 problem+json, not RFC 6749 Section 5.2."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" Failures return "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"application/problem+json"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" with "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"type"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"title"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"status"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"instance"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". There is no "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"error"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" or "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"error_description"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" field, so the standard codes ("},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"invalid_grant"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"invalid_client"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"unsupported_grant_type"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":") never appear — branch on the HTTP status and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"title"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" instead. A refresh token that is expired, already rotated, or unrecognized returns "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"400"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" with a "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"title"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" of "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"Refresh token has expired"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" or "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"Invalid refresh token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", where a conformant server would return "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"error: invalid_grant"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" is not a registrable grant type."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" RFC 7591 Section 2 lists it, but "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"/oauth2/register"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" accepts only "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"client_credentials"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" in "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grantTypes"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". Refreshing requires no registration: holding a refresh token issued to the client is the authorization. A consequence is that refresh capability cannot be disabled per client — every "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" grant returns a refresh token, so a client intended for a shared or public device cannot be registered without one."},"children":[]}]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Two are choices the specifications leave to the server:"},"children":[]}]}]},{"$$mdtype":"Node","type":"list","attributes":{"ordered":false,"marker":"-"},"children":[{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Refresh tokens rotate on every use."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" A successful refresh retires the token presented and returns a replacement in "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", as RFC 6749 Section 6 permits and the OAuth2 Security Best Current Practice recommends. Store the new value; the old one stops working. Refresh tokens expire 30 days after they are issued, and rotation restarts that window. The authorization code flow returns a refresh token with every access token; the client credentials flow returns none (RFC 6749 Section 4.4.3)."},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"scope"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" accepts commas."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" The space-delimited form required by RFC 6749 is always accepted and recommended; comma-separated values are additionally tolerated."},"children":[]}]}]}]}],"flows":{"authorizationCode":{"authorizationUrl":"https://api.cafe.redocly.com/oauth2/authorize","tokenUrl":"https://api.cafe.redocly.com/oauth2/token","refreshUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}},"clientCredentials":{"tokenUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}}}}]}]},{"nodeType":"item-content","variant":"path","label":"Path","labelTranslationKey":"path","parameters":[{"name":"orderId","in":"path","schemaId":"schema_16","description":"ID of the order to retrieve.","required":true,"example":"ord_01h1s5z6vf2mm1mz3hevnn9va7"}],"pointer":"/paths/~1orders~1{orderId}/patch/parameters"},{"nodeType":"item-content","variant":"body","label":"Request Body","labelTranslationKey":"body","mediaTypes":["application/json"],"mediaTypeSchemas":{"application/json":{"schemaId":"schema_17"}},"schemaId":"schema_17","pointer":"/paths/~1orders~1{orderId}/patch/requestBody"}],"panels":[{"children":[{"kind":"code-sample","source":{"kind":"code-sample","operationType":"http","method":"PATCH","path":"/orders/{orderId}","servers":[{"url":"/_mock/openapi/cafe","description":"Mock server","isMockServer":true},{"url":"https://api.cafe.redocly.com","description":"Live server."}],"parameters":{"path":[{"name":"orderId","in":"path","required":true,"example":"ord_01h1s5z6vf2mm1mz3hevnn9va7","schemaId":"schema_16"}],"query":[],"querystring":[],"header":[],"cookie":[]},"security":[{"schemes":[{"id":"OAuth2","type":"oauth2","flows":{"authorizationCode":{"authorizationUrl":"https://api.cafe.redocly.com/oauth2/authorize","tokenUrl":"https://api.cafe.redocly.com/oauth2/token","refreshUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}},"clientCredentials":{"tokenUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}}}}],"scopes":["orders:write"]}],"requestBody":{"application/json":{"schemaId":"schema_17"}},"responseCodes":["200","400","401","403","404","500"],"pointer":"/orders/{orderId}","href":"orders/updateorder","openApiOperationId":"updateOrder","summary":"Partially update an order"},"isWebhook":false,"hideReplay":false,"servers":[{"url":"/_mock/openapi/cafe","description":"Mock server","isMockServer":true},{"url":"https://api.cafe.redocly.com","description":"Live server."}],"schemaId":"schema_17","mediaTypes":["application/json"],"mediaTypeSchemas":{"application/json":{"schemaId":"schema_17"}},"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Responses","labelTranslationKey":"responses","deepLinkSuffix":"responses"},{"nodeType":"item-content","variant":"responses","responses":[{"code":"200","description":"Order updated successfully.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/Order","exampleIds":["paths/~1orders~1{orderId}/patch/responses/200/content/application~1json/examples/OrderResponse"]}},"schemaId":"components/schemas/Order","exampleIds":["paths/~1orders~1{orderId}/patch/responses/200/content/application~1json/examples/OrderResponse"]},{"code":"400","description":"Bad request - invalid input parameters.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"401","description":"Unauthorized - authorization required.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"403","description":"Forbidden - insufficient permissions.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"404","description":"Resource not found.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"500","description":"Internal server error.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"}],"pointer":"/paths/~1orders~1{orderId}/patch/responses"}],"panels":[{"children":[{"kind":"response","headerTitle":"Response","responseCodes":[{"code":"200","schemaId":"components/schemas/Order","exampleIds":["paths/~1orders~1{orderId}/patch/responses/200/content/application~1json/examples/OrderResponse"],"mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/Order","exampleIds":["paths/~1orders~1{orderId}/patch/responses/200/content/application~1json/examples/OrderResponse"]}}},{"code":"400","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"401","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"403","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"404","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"500","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"feedback","pageSlug":"/orders/updateorder"}],"panels":[]}]},"httpPath":"/orders/{orderId}"},{"label":"Delete an order","deprecated":false,"httpVerb":"delete","isAdditionalOperation":false,"isWebhook":false,"type":"link","link":"/openapi/cafe/orders/deleteorder","routeSlug":"/openapi/cafe/orders/deleteorder","metadata":{"seo":{"title":"Delete an order","description":"Delete the order. To keep the order history, cancel the order instead of deleting it."}},"content":{"contentType":"item","itemVariant":"httpItem","meta":{"sourceId":"deleteOrder","name":"Delete an order","isWebhook":false,"pointer":"/paths/~1orders~1{orderId}/delete","hasSamples":false},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"Delete an order","isWebhook":false,"showPageActions":true}],"panels":[]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Request","labelTranslationKey":"request","deepLinkSuffix":"request"},{"nodeType":"markdoc","content":"Delete the order.\nTo keep the order history, cancel the order instead of deleting it.\n"},{"nodeType":"security","requirements":[{"schemes":[{"name":"OAuth2","scopes":["orders:write"],"type":"oauth2","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"OAuth2 authorization for API access. The token endpoint accepts "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grant_type=authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grant_type=client_credentials"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grant_type=refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]},{"$$mdtype":"Node","type":"heading","attributes":{"level":3},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Differences from the OAuth2 specifications"},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"A standard OAuth2 client library can drive these flows, with the following to account for."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Two behaviors do not conform to the specifications:"},"children":[]}]}]},{"$$mdtype":"Node","type":"list","attributes":{"ordered":false,"marker":"-"},"children":[{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Errors use RFC 9457 problem+json, not RFC 6749 Section 5.2."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" Failures return "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"application/problem+json"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" with "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"type"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"title"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"status"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"instance"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". There is no "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"error"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" or "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"error_description"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" field, so the standard codes ("},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"invalid_grant"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"invalid_client"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"unsupported_grant_type"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":") never appear — branch on the HTTP status and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"title"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" instead. A refresh token that is expired, already rotated, or unrecognized returns "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"400"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" with a "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"title"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" of "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"Refresh token has expired"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" or "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"Invalid refresh token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", where a conformant server would return "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"error: invalid_grant"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" is not a registrable grant type."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" RFC 7591 Section 2 lists it, but "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"/oauth2/register"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" accepts only "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"client_credentials"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" in "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grantTypes"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". Refreshing requires no registration: holding a refresh token issued to the client is the authorization. A consequence is that refresh capability cannot be disabled per client — every "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" grant returns a refresh token, so a client intended for a shared or public device cannot be registered without one."},"children":[]}]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Two are choices the specifications leave to the server:"},"children":[]}]}]},{"$$mdtype":"Node","type":"list","attributes":{"ordered":false,"marker":"-"},"children":[{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Refresh tokens rotate on every use."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" A successful refresh retires the token presented and returns a replacement in "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", as RFC 6749 Section 6 permits and the OAuth2 Security Best Current Practice recommends. Store the new value; the old one stops working. Refresh tokens expire 30 days after they are issued, and rotation restarts that window. The authorization code flow returns a refresh token with every access token; the client credentials flow returns none (RFC 6749 Section 4.4.3)."},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"scope"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" accepts commas."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" The space-delimited form required by RFC 6749 is always accepted and recommended; comma-separated values are additionally tolerated."},"children":[]}]}]}]}],"flows":{"authorizationCode":{"authorizationUrl":"https://api.cafe.redocly.com/oauth2/authorize","tokenUrl":"https://api.cafe.redocly.com/oauth2/token","refreshUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}},"clientCredentials":{"tokenUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}}}}]}]},{"nodeType":"item-content","variant":"path","label":"Path","labelTranslationKey":"path","parameters":[{"name":"orderId","in":"path","schemaId":"schema_16","description":"ID of the order to retrieve.","required":true,"example":"ord_01h1s5z6vf2mm1mz3hevnn9va7"}],"pointer":"/paths/~1orders~1{orderId}/delete/parameters"}],"panels":[{"children":[{"kind":"code-sample","source":{"kind":"code-sample","operationType":"http","method":"DELETE","path":"/orders/{orderId}","servers":[{"url":"/_mock/openapi/cafe","description":"Mock server","isMockServer":true},{"url":"https://api.cafe.redocly.com","description":"Live server."}],"parameters":{"path":[{"name":"orderId","in":"path","required":true,"example":"ord_01h1s5z6vf2mm1mz3hevnn9va7","schemaId":"schema_16"}],"query":[],"querystring":[],"header":[],"cookie":[]},"security":[{"schemes":[{"id":"OAuth2","type":"oauth2","flows":{"authorizationCode":{"authorizationUrl":"https://api.cafe.redocly.com/oauth2/authorize","tokenUrl":"https://api.cafe.redocly.com/oauth2/token","refreshUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}},"clientCredentials":{"tokenUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}}}}],"scopes":["orders:write"]}],"responseCodes":["204","400","401","403","404","500"],"pointer":"/orders/{orderId}","href":"orders/deleteorder","openApiOperationId":"deleteOrder","summary":"Delete an order"},"isWebhook":false,"hideReplay":false,"servers":[{"url":"/_mock/openapi/cafe","description":"Mock server","isMockServer":true},{"url":"https://api.cafe.redocly.com","description":"Live server."}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Responses","labelTranslationKey":"responses","deepLinkSuffix":"responses"},{"nodeType":"item-content","variant":"responses","responses":[{"code":"204","description":"Order deleted successfully."},{"code":"400","description":"Bad request - invalid input parameters.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"401","description":"Unauthorized - authorization required.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"403","description":"Forbidden - insufficient permissions.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"404","description":"Resource not found.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"500","description":"Internal server error.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"}],"pointer":"/paths/~1orders~1{orderId}/delete/responses"}],"panels":[{"children":[{"kind":"response","headerTitle":"Response","responseCodes":[{"code":"204"},{"code":"400","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"401","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"403","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"404","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"500","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"feedback","pageSlug":"/orders/deleteorder"}],"panels":[]}]},"httpPath":"/orders/{orderId}"},{"label":"List all order items with menu item details","deprecated":false,"httpVerb":"get","isAdditionalOperation":false,"isWebhook":false,"type":"link","link":"/openapi/cafe/orders/listorderitems","routeSlug":"/openapi/cafe/orders/listorderitems","metadata":{"seo":{"title":"List all order items with menu item details","description":"Returns an array of order items for a specific order.Use the filter parameter to filter by order ID."}},"content":{"contentType":"item","itemVariant":"httpItem","meta":{"sourceId":"listOrderItems","name":"List all order items with menu item details","isWebhook":false,"pointer":"/paths/~1order-items/get","hasSamples":false},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"List all order items with menu item details","isWebhook":false,"showPageActions":true}],"panels":[]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Request","labelTranslationKey":"request","deepLinkSuffix":"request"},{"nodeType":"markdoc","content":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Returns an array of order items for a specific order."},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Use the "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"filter"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" parameter to filter by order ID."},"children":[]}]}]}]},{"nodeType":"security","requirements":[{"schemes":[{"name":"OAuth2","scopes":["orders:read"],"type":"oauth2","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"OAuth2 authorization for API access. The token endpoint accepts "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grant_type=authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grant_type=client_credentials"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grant_type=refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]},{"$$mdtype":"Node","type":"heading","attributes":{"level":3},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Differences from the OAuth2 specifications"},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"A standard OAuth2 client library can drive these flows, with the following to account for."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Two behaviors do not conform to the specifications:"},"children":[]}]}]},{"$$mdtype":"Node","type":"list","attributes":{"ordered":false,"marker":"-"},"children":[{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Errors use RFC 9457 problem+json, not RFC 6749 Section 5.2."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" Failures return "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"application/problem+json"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" with "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"type"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"title"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"status"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"instance"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". There is no "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"error"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" or "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"error_description"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" field, so the standard codes ("},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"invalid_grant"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"invalid_client"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"unsupported_grant_type"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":") never appear — branch on the HTTP status and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"title"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" instead. A refresh token that is expired, already rotated, or unrecognized returns "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"400"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" with a "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"title"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" of "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"Refresh token has expired"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" or "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"Invalid refresh token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", where a conformant server would return "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"error: invalid_grant"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" is not a registrable grant type."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" RFC 7591 Section 2 lists it, but "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"/oauth2/register"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" accepts only "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"client_credentials"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" in "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grantTypes"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". Refreshing requires no registration: holding a refresh token issued to the client is the authorization. A consequence is that refresh capability cannot be disabled per client — every "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" grant returns a refresh token, so a client intended for a shared or public device cannot be registered without one."},"children":[]}]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Two are choices the specifications leave to the server:"},"children":[]}]}]},{"$$mdtype":"Node","type":"list","attributes":{"ordered":false,"marker":"-"},"children":[{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Refresh tokens rotate on every use."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" A successful refresh retires the token presented and returns a replacement in "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", as RFC 6749 Section 6 permits and the OAuth2 Security Best Current Practice recommends. Store the new value; the old one stops working. Refresh tokens expire 30 days after they are issued, and rotation restarts that window. The authorization code flow returns a refresh token with every access token; the client credentials flow returns none (RFC 6749 Section 4.4.3)."},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"scope"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" accepts commas."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" The space-delimited form required by RFC 6749 is always accepted and recommended; comma-separated values are additionally tolerated."},"children":[]}]}]}]}],"flows":{"authorizationCode":{"authorizationUrl":"https://api.cafe.redocly.com/oauth2/authorize","tokenUrl":"https://api.cafe.redocly.com/oauth2/token","refreshUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}},"clientCredentials":{"tokenUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}}}}]}]},{"nodeType":"item-content","variant":"query","label":"Query","labelTranslationKey":"query","parameters":[{"name":"filter","in":"query","schemaId":"schema_10","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Selects the order whose items to return, using a single "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"orderId:<value>"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" pair"},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"(for example, "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"orderId:ord_01h1s5z6vf2mm1mz3hevnn9va7"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":")."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"This filter is required and only the "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"orderId"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" field is supported."},"children":[]}]}]}],"required":true,"example":"orderId:ord_01h1s5z6vf2mm1mz3hevnn9va7"}],"pointer":"/paths/~1order-items/get/parameters"}],"panels":[{"children":[{"kind":"code-sample","source":{"kind":"code-sample","operationType":"http","method":"GET","path":"/order-items","servers":[{"url":"/_mock/openapi/cafe","description":"Mock server","isMockServer":true},{"url":"https://api.cafe.redocly.com","description":"Live server."}],"parameters":{"path":[],"query":[{"name":"filter","in":"query","required":false,"schemaId":"schema_10"}],"querystring":[],"header":[],"cookie":[]},"security":[{"schemes":[{"id":"OAuth2","type":"oauth2","flows":{"authorizationCode":{"authorizationUrl":"https://api.cafe.redocly.com/oauth2/authorize","tokenUrl":"https://api.cafe.redocly.com/oauth2/token","refreshUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}},"clientCredentials":{"tokenUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}}}}],"scopes":["orders:read"]}],"responseCodes":["200","400","401","403","404","500"],"pointer":"/order-items","href":"orders/listorderitems","openApiOperationId":"listOrderItems","summary":"List all order items with menu item details"},"isWebhook":false,"hideReplay":false,"servers":[{"url":"/_mock/openapi/cafe","description":"Mock server","isMockServer":true},{"url":"https://api.cafe.redocly.com","description":"Live server."}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Responses","labelTranslationKey":"responses","deepLinkSuffix":"responses"},{"nodeType":"item-content","variant":"responses","responses":[{"code":"200","description":"Successful operation.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"schema_18"}},"schemaId":"schema_18"},{"code":"400","description":"Bad request - invalid input parameters.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"401","description":"Unauthorized - authorization required.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"403","description":"Forbidden - insufficient permissions.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"404","description":"Resource not found.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"500","description":"Internal server error.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"}],"pointer":"/paths/~1order-items/get/responses"}],"panels":[{"children":[{"kind":"response","headerTitle":"Response","responseCodes":[{"code":"200","schemaId":"schema_18","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"schema_18"}}},{"code":"400","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"401","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"403","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"404","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"500","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"feedback","pageSlug":"/orders/listorderitems"}],"panels":[]}]},"httpPath":"/order-items"},{"type":"separator","label":"Webhooks","variant":"secondary","content":null},{"label":"Order notification webhook","deprecated":false,"httpVerb":"post","isAdditionalOperation":false,"isWebhook":true,"type":"link","link":"/openapi/cafe/orders/ordernotificationwebhook","routeSlug":"/openapi/cafe/orders/ordernotificationwebhook","metadata":{"seo":{"title":"Order notification webhook","description":"Webhook triggered when a new order is placed."}},"content":{"contentType":"item","itemVariant":"httpItem","meta":{"sourceId":"orderNotificationWebhook","name":"Order notification webhook","isWebhook":true,"pointer":"/paths/order-notification/post","hasSamples":true},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"Order notification webhook","isWebhook":true,"showPageActions":true}],"panels":[]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Request","labelTranslationKey":"request","deepLinkSuffix":"request"},{"nodeType":"markdoc","content":"Webhook triggered when a new order is placed."},{"nodeType":"item-content","variant":"body","label":"Request Body","labelTranslationKey":"body","required":true,"mediaTypes":["application/json"],"mediaTypeSchemas":{"application/json":{"schemaId":"components/schemas/OrderNotification"}},"schemaId":"components/schemas/OrderNotification","pointer":"/paths/order-notification/post/requestBody"}],"panels":[{"children":[{"kind":"code-sample","source":{"kind":"code-sample","operationType":"webhook","method":"POST","path":"order-notification","servers":[{"url":"/_mock/openapi/cafe","description":"Mock server","isMockServer":true},{"url":"https://api.cafe.redocly.com","description":"Live server."}],"parameters":{"path":[],"query":[],"querystring":[],"header":[],"cookie":[]},"security":[],"requestBody":{"application/json":{"schemaId":"components/schemas/OrderNotification"}},"responseCodes":["200","400","500"],"pointer":"order-notification","href":"orders/ordernotificationwebhook","openApiOperationId":"orderNotificationWebhook","summary":"Order notification webhook"},"isWebhook":true,"hideReplay":false,"servers":[{"url":"/_mock/openapi/cafe","description":"Mock server","isMockServer":true},{"url":"https://api.cafe.redocly.com","description":"Live server."}],"schemaId":"components/schemas/OrderNotification","mediaTypes":["application/json"],"mediaTypeSchemas":{"application/json":{"schemaId":"components/schemas/OrderNotification"}},"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Responses","labelTranslationKey":"responses","deepLinkSuffix":"responses"},{"nodeType":"item-content","variant":"responses","responses":[{"code":"200","description":"Webhook received successfully."},{"code":"400","description":"Bad request - invalid input parameters.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"500","description":"Internal server error.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"}],"pointer":"/paths/order-notification/post/responses"}],"panels":[{"children":[{"kind":"response","headerTitle":"Response","responseCodes":[{"code":"200"},{"code":"400","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"500","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"feedback","pageSlug":"/orders/ordernotificationwebhook"}],"panels":[]}]},"httpPath":"order-notification"}],"content":{"contentType":"group","meta":{"name":"Orders"},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"Orders","showPageActions":true},{"nodeType":"markdoc","content":"Order management operations."}],"panels":[{"children":[{"kind":"group-items","title":"Operations","titleTranslationKey":"operations","items":[{"title":"/orders","summary":"List all orders","prefix":{"name":"get","color":"get"},"badges":[],"link":"/orders/listorders","deprecated":false},{"title":"/orders","summary":"Create order","prefix":{"name":"post","color":"post"},"badges":[],"link":"/orders/createorder","deprecated":false},{"title":"/orders/{orderId}","summary":"Retrieve an order","prefix":{"name":"get","color":"get"},"badges":[],"link":"/orders/getorderbyid","deprecated":false},{"title":"/orders/{orderId}","summary":"Partially update an order","prefix":{"name":"patch","color":"patch"},"badges":[],"link":"/orders/updateorder","deprecated":false},{"title":"/orders/{orderId}","summary":"Delete an order","prefix":{"name":"delete","color":"delete"},"badges":[],"link":"/orders/deleteorder","deprecated":false},{"title":"/order-items","summary":"List all order items with menu item details","prefix":{"name":"get","color":"get"},"badges":[],"link":"/orders/listorderitems","deprecated":false}]},{"kind":"group-items","title":"Webhooks","titleTranslationKey":"webhooks","items":[{"title":"order-notification","summary":"Order notification webhook","prefix":{"name":"post","color":"post"},"badges":[],"link":"/orders/ordernotificationwebhook","deprecated":false}]}]}]}]}},{"type":"group","label":"Statistics","link":"/openapi/cafe/statistics","routeSlug":"/openapi/cafe/statistics","items":[{"label":"Get revenue statistics","deprecated":false,"httpVerb":"get","isAdditionalOperation":false,"isWebhook":false,"type":"link","link":"/openapi/cafe/statistics/getrevenue","routeSlug":"/openapi/cafe/statistics/getrevenue","metadata":{"seo":{"title":"Get revenue statistics","description":"Retrieve revenue statistics for a configurable date range. Returns revenue, order counts, average order amount, and other useful statistics."}},"content":{"contentType":"item","itemVariant":"httpItem","meta":{"sourceId":"getRevenue","name":"Get revenue statistics","isWebhook":false,"pointer":"/paths/~1revenue/get","hasSamples":false},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"Get revenue statistics","isWebhook":false,"showPageActions":true}],"panels":[]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Request","labelTranslationKey":"request","deepLinkSuffix":"request"},{"nodeType":"markdoc","content":"Retrieve revenue statistics for a configurable date range.\nReturns revenue, order counts, average order amount, and other useful statistics.\n"},{"nodeType":"security","requirements":[{"schemes":[{"name":"ApiKey","scopes":[],"type":"apiKey","in":"header","paramName":"X-API-Key","description":"API key for internal operations."}]},{"schemes":[{"name":"OAuth2","scopes":["revenue:read"],"type":"oauth2","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"OAuth2 authorization for API access. The token endpoint accepts "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grant_type=authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grant_type=client_credentials"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grant_type=refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]},{"$$mdtype":"Node","type":"heading","attributes":{"level":3},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Differences from the OAuth2 specifications"},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"A standard OAuth2 client library can drive these flows, with the following to account for."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Two behaviors do not conform to the specifications:"},"children":[]}]}]},{"$$mdtype":"Node","type":"list","attributes":{"ordered":false,"marker":"-"},"children":[{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Errors use RFC 9457 problem+json, not RFC 6749 Section 5.2."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" Failures return "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"application/problem+json"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" with "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"type"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"title"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"status"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"instance"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". There is no "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"error"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" or "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"error_description"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" field, so the standard codes ("},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"invalid_grant"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"invalid_client"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"unsupported_grant_type"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":") never appear — branch on the HTTP status and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"title"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" instead. A refresh token that is expired, already rotated, or unrecognized returns "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"400"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" with a "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"title"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" of "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"Refresh token has expired"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" or "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"Invalid refresh token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", where a conformant server would return "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"error: invalid_grant"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" is not a registrable grant type."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" RFC 7591 Section 2 lists it, but "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"/oauth2/register"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" accepts only "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"client_credentials"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" in "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grantTypes"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". Refreshing requires no registration: holding a refresh token issued to the client is the authorization. A consequence is that refresh capability cannot be disabled per client — every "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" grant returns a refresh token, so a client intended for a shared or public device cannot be registered without one."},"children":[]}]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Two are choices the specifications leave to the server:"},"children":[]}]}]},{"$$mdtype":"Node","type":"list","attributes":{"ordered":false,"marker":"-"},"children":[{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Refresh tokens rotate on every use."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" A successful refresh retires the token presented and returns a replacement in "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", as RFC 6749 Section 6 permits and the OAuth2 Security Best Current Practice recommends. Store the new value; the old one stops working. Refresh tokens expire 30 days after they are issued, and rotation restarts that window. The authorization code flow returns a refresh token with every access token; the client credentials flow returns none (RFC 6749 Section 4.4.3)."},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"scope"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" accepts commas."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" The space-delimited form required by RFC 6749 is always accepted and recommended; comma-separated values are additionally tolerated."},"children":[]}]}]}]}],"flows":{"authorizationCode":{"authorizationUrl":"https://api.cafe.redocly.com/oauth2/authorize","tokenUrl":"https://api.cafe.redocly.com/oauth2/token","refreshUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}},"clientCredentials":{"tokenUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}}}}]}]},{"nodeType":"item-content","variant":"query","label":"Query","labelTranslationKey":"query","parameters":[{"name":"startDate","in":"query","schemaId":"schema_19","description":"Start date for the revenue calculation period (ISO 8601 datetime format).\nDefaults to 30 days ago if not provided.\n","example":"2026-01-01T00:00:00Z"},{"name":"endDate","in":"query","schemaId":"schema_19","description":"End date for the revenue calculation period (ISO 8601 datetime format).\nDefaults to current time if not provided.\n","example":"2026-01-31T23:59:59Z"}],"pointer":"/paths/~1revenue/get/parameters"}],"panels":[{"children":[{"kind":"code-sample","source":{"kind":"code-sample","operationType":"http","method":"GET","path":"/revenue","servers":[{"url":"/_mock/openapi/cafe","description":"Mock server","isMockServer":true},{"url":"https://api.cafe.redocly.com","description":"Live server."}],"parameters":{"path":[],"query":[{"name":"startDate","in":"query","required":false,"example":"2026-01-01T00:00:00Z","schemaId":"schema_19"},{"name":"endDate","in":"query","required":false,"example":"2026-01-31T23:59:59Z","schemaId":"schema_19"}],"querystring":[],"header":[],"cookie":[]},"security":[{"schemes":[{"id":"ApiKey","type":"apiKey","name":"X-API-Key","in":"header"}],"scopes":[]},{"schemes":[{"id":"OAuth2","type":"oauth2","flows":{"authorizationCode":{"authorizationUrl":"https://api.cafe.redocly.com/oauth2/authorize","tokenUrl":"https://api.cafe.redocly.com/oauth2/token","refreshUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}},"clientCredentials":{"tokenUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}}}}],"scopes":["revenue:read"]}],"responseCodes":["200","400","401","403","500"],"pointer":"/revenue","href":"statistics/getrevenue","openApiOperationId":"getRevenue","summary":"Get revenue statistics","securityGroups":[{"ApiKey":[]},{"OAuth2":["revenue:read"]}]},"isWebhook":false,"hideReplay":false,"servers":[{"url":"/_mock/openapi/cafe","description":"Mock server","isMockServer":true},{"url":"https://api.cafe.redocly.com","description":"Live server."}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"header","level":4,"label":"Responses","labelTranslationKey":"responses","deepLinkSuffix":"responses"},{"nodeType":"item-content","variant":"responses","responses":[{"code":"200","description":"Revenue statistics retrieved successfully.","mediaType":"application/json","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/RevenueStatistics"}},"schemaId":"components/schemas/RevenueStatistics"},{"code":"400","description":"Bad request - invalid input parameters.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"401","description":"Unauthorized - authorization required.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"403","description":"Forbidden - insufficient permissions.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"},{"code":"500","description":"Internal server error.","mediaType":"application/problem+json","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}},"schemaId":"components/schemas/Error"}],"pointer":"/paths/~1revenue/get/responses"}],"panels":[{"children":[{"kind":"response","headerTitle":"Response","responseCodes":[{"code":"200","schemaId":"components/schemas/RevenueStatistics","mediaTypes":["application/json"],"mediaTypeContent":{"application/json":{"schemaId":"components/schemas/RevenueStatistics"}}},{"code":"400","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"401","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"403","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}},{"code":"500","schemaId":"components/schemas/Error","mediaTypes":["application/problem+json"],"mediaTypeContent":{"application/problem+json":{"schemaId":"components/schemas/Error"}}}],"examples":[]}]}]},{"nodeType":"container","children":[{"nodeType":"feedback","pageSlug":"/statistics/getrevenue"}],"panels":[]}]},"httpPath":"/revenue"}],"content":{"contentType":"group","meta":{"name":"Statistics"},"children":[{"nodeType":"container","children":[{"nodeType":"header","level":2,"label":"Statistics","showPageActions":true},{"nodeType":"markdoc","content":"Statistics operations."}],"panels":[{"children":[{"kind":"group-items","title":"Operations","titleTranslationKey":"operations","items":[{"title":"/revenue","summary":"Get revenue statistics","prefix":{"name":"get","color":"get"},"badges":[],"link":"/statistics/getrevenue","deprecated":false}]}]}]}]}}],"store":{"schemaStore":{"components/schemas/Page":{"id":"components/schemas/Page","kind":"json-schema","title":"Page","data":{"type":"object","properties":{"endCursor":{"type":["string","null"],"description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Use with the "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"after"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" query parameter to load the next page of data."},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"When "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"null"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", there is no data."},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"The cursor is opaque and internal structure is subject to change."},"children":[]}]}]}]},"startCursor":{"type":["string","null"],"description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Use with the "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"before"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" query parameter to load the previous page of data."},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"When "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"null"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", there is no data."},"children":[]},{"$$mdtype":"Node","type":"softbreak","inline":true,"attributes":{},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"The cursor is opaque and internal structure is subject to change."},"children":[]}]}]}]},"hasNextPage":{"type":"boolean","description":"Indicates if there is a next page with items."},"hasPrevPage":{"type":"boolean","description":"Indicates if there is a previous page with items."},"limit":{"type":"integer","minimum":1,"maximum":100,"default":10,"description":"Value showing how many items are in the page limit."},"total":{"type":"integer","description":"Count of items across all pages.","minimum":0}},"required":["endCursor","startCursor","hasNextPage","hasPrevPage","limit","total"]}},"components/schemas/MenuBaseItem":{"id":"components/schemas/MenuBaseItem","kind":"json-schema","title":"MenuBaseItem","data":{"type":"object","properties":{"createdAt":{"description":"Created date.","type":"string","format":"date-time","readOnly":true},"updatedAt":{"description":"Updated date.","type":"string","format":"date-time","readOnly":true},"id":{"description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Menu item ID. Unique identifier prefixed with "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"prd_"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]}],"type":"string","readOnly":true,"pattern":"^prd_[0-9abcdefghjkmnpqrstvwxyz]{26}$","example":"prd_01h1s5z6vf2mm1mz3hevnn9va7"},"object":{"description":"Entity name.","type":"string","const":"menuItem","readOnly":true},"name":{"description":"Menu item name.","type":"string","minLength":1,"maxLength":50},"price":{"description":"Price in cents.","type":"integer","minimum":0},"photo":{"writeOnly":true,"type":["string","null"],"format":"binary","description":"Photo of the menu item. Must be a PNG image less than 1MB in size."},"photoUrl":{"readOnly":true,"type":"string","format":"uri","description":"Photo URL of the menu item."},"photoTextDescription":{"type":["string","null"]}},"required":["id","name","price","createdAt","updatedAt","object"]}},"components/schemas/Beverage":{"id":"components/schemas/Beverage","kind":"json-schema","title":"Beverage","data":{"allOf":[{"type":"object","properties":{"category":{"description":"Menu item category.","type":"string","const":"beverage"},"volume":{"type":"number","description":"Size of the beverage in milliliters.","exclusiveMinimum":0},"containsCaffeine":{"type":"boolean","description":"Indicates if the beverage contains caffeine."}},"required":["category","volume","containsCaffeine"]},{"$ref":"#/components/schemas/MenuBaseItem"}]}},"components/schemas/Dessert":{"id":"components/schemas/Dessert","kind":"json-schema","title":"Dessert","data":{"allOf":[{"type":"object","properties":{"category":{"description":"Menu item category.","type":"string","const":"dessert"},"calories":{"type":"number","exclusiveMinimum":0,"description":"Amount of calories."}},"required":["category","calories"]},{"$ref":"#/components/schemas/MenuBaseItem"}]}},"components/schemas/MenuItem":{"id":"components/schemas/MenuItem","kind":"json-schema","title":"MenuItem","data":{"discriminator":{"propertyName":"category","mapping":{"beverage":"#/components/schemas/Beverage","dessert":"#/components/schemas/Dessert"}},"oneOf":[{"$ref":"#/components/schemas/Beverage"},{"$ref":"#/components/schemas/Dessert"}],"required":["category"]}},"components/schemas/MenuItemList":{"id":"components/schemas/MenuItemList","kind":"json-schema","title":"MenuItemList","data":{"type":"object","properties":{"object":{"type":"string","const":"list","description":"Entity name."},"page":{"$ref":"#/components/schemas/Page"},"items":{"type":"array","items":{"$ref":"#/components/schemas/MenuItem"}}},"required":["object","page","items"]}},"components/schemas/Error":{"id":"components/schemas/Error","kind":"json-schema","title":"Error","data":{"type":"object","properties":{"type":{"type":"string","format":"uri-reference","description":"URI reference that identifies the problem type.","default":"about:blank"},"title":{"type":"string","description":"Short summary of the problem type."},"status":{"type":"integer","format":"int32","description":"HTTP status code generated by the origin server for this occurrence of the problem.\n","minimum":100,"exclusiveMaximum":600},"instance":{"type":"string","format":"uri-reference","description":"URI reference that identifies the specific occurrence of the problem, e.g. by adding a fragment identifier or sub-path to the problem type.\nCan be used to locate the root of this problem in the source code.\n","example":"/some/uri-reference#specific-occurrence-context"},"details":{"description":"Additional error details.","type":"object","additionalProperties":true}},"required":["type","title","status"]}},"components/schemas/OrderStatus":{"id":"components/schemas/OrderStatus","kind":"json-schema","title":"OrderStatus","data":{"type":"string","description":"Order status.","enum":["placed","preparing","completed","canceled"]}},"components/schemas/Order":{"id":"components/schemas/Order","kind":"json-schema","title":"Order","data":{"type":"object","title":"Order","properties":{"id":{"description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Order ID. Unique identifier prefixed with "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"ord_"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]}],"type":"string","format":"ulid","readOnly":true,"pattern":"^ord_[0-9abcdefghjkmnpqrstvwxyz]{26}$","example":"ord_01h1s5z6vf2mm1mz3hevnn9va7"},"object":{"description":"Entity name.","type":"string","const":"order","readOnly":true},"customerName":{"description":"Name of the customer who placed the order.\nMust start and end with a letter, and can contain letters, spaces, hyphens, and apostrophes (e.g., \"John Doe\", \"Mary-Jane\", \"O'Brien\").\n","type":"string","pattern":"^[A-Za-z]+(?:[\\s'-][A-Za-z]+)*$","minLength":1,"maxLength":100},"status":{"allOf":[{"$ref":"#/components/schemas/OrderStatus"}],"readOnly":true},"totalPrice":{"description":"Total order price in cents.","type":"integer","minimum":0,"readOnly":true},"createdAt":{"description":"Created date.","type":"string","format":"date-time","readOnly":true},"updatedAt":{"description":"Updated date.","type":"string","format":"date-time","readOnly":true},"orderItems":{"type":"array","description":"List of items to include in the order.","minItems":1,"items":{"type":"object","properties":{"menuItemId":{"type":"string","format":"ulid","description":"ID of the menu item to add to the order."},"quantity":{"type":"integer","minimum":1,"description":"Quantity of the menu item."},"discount":{"type":"integer","minimum":0,"description":"Discount amount in cents (absolute value).","default":0},"comment":{"type":"string","maxLength":500,"description":"Optional comment for the order item (e.g., \"No sugar\")."}},"required":["menuItemId","quantity"]}}},"required":["customerName","orderItems"]}},"components/schemas/OrderList":{"id":"components/schemas/OrderList","kind":"json-schema","title":"OrderList","data":{"type":"object","properties":{"object":{"type":"string","const":"list","description":"Entity name."},"page":{"$ref":"#/components/schemas/Page"},"items":{"type":"array","items":{"$ref":"#/components/schemas/Order"}}},"required":["object","page","items"]}},"components/schemas/OrderItem":{"id":"components/schemas/OrderItem","kind":"json-schema","title":"OrderItem","data":{"type":"object","properties":{"menuItemId":{"type":"string","description":"ID of the menu item to add to the order.","writeOnly":true},"menuItem":{"allOf":[{"$ref":"#/components/schemas/MenuItem"}],"description":"Menu item that is part of the order.","readOnly":true},"quantity":{"type":"integer","minimum":1,"description":"Quantity of the menu item."},"discount":{"type":"integer","minimum":0,"description":"Discount amount in cents (absolute value).","default":0},"comment":{"type":"string","maxLength":500,"description":"Optional comment for the order item (e.g., \"No sugar\")."}},"required":["menuItemId","quantity"]}},"components/schemas/RevenueStatistics":{"id":"components/schemas/RevenueStatistics","kind":"json-schema","title":"RevenueStatistics","data":{"type":"object","description":"Revenue statistics for a given date range.","properties":{"revenue":{"type":"number","format":"float","description":"Total revenue in cents from completed orders.","minimum":0},"averageOrderAmount":{"type":"number","format":"float","description":"Average order amount in cents (calculated from completed orders only).","minimum":0},"totalOrders":{"type":"integer","description":"Total number of orders (all statuses) in the date range.","minimum":0},"placedOrders":{"type":"integer","description":"Number of placed orders.","minimum":0},"preparingOrders":{"type":"integer","description":"Number of preparing orders.","minimum":0},"completedOrders":{"type":"integer","description":"Number of completed orders.","minimum":0},"canceledOrders":{"type":"integer","description":"Number of canceled orders.","minimum":0},"startDate":{"type":"string","format":"date-time","description":"Start date of the revenue calculation period."},"endDate":{"type":"string","format":"date-time","description":"End date of the revenue calculation period."}},"required":["revenue","averageOrderAmount","totalOrders","placedOrders","preparingOrders","completedOrders","canceledOrders","startDate","endDate"]}},"components/schemas/RegisterClientObject":{"id":"components/schemas/RegisterClientObject","kind":"json-schema","title":"RegisterClientObject","data":{"type":"object","properties":{"name":{"type":"string","description":"Client name."},"redirectUris":{"type":"array","items":{"type":"string","format":"uri"},"default":[],"description":"List of redirect URIs (optional, defaults to empty array)."},"scopes":{"type":"array","items":{"type":"string","enum":["menu:read","menu:write","orders:read","orders:write","revenue:read"]},"default":["menu:read","menu:write","orders:read","orders:write","revenue:read"],"description":"List of scopes."},"grantTypes":{"type":"array","items":{"type":"string","enum":["authorization_code","client_credentials"]},"default":["authorization_code","client_credentials"],"description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"List of grant types. "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" is not registrable; any client holding a refresh token may present it at the token endpoint."},"children":[]}]}]}]}},"required":["name"]}},"components/schemas/OAuth2Client":{"id":"components/schemas/OAuth2Client","kind":"json-schema","title":"OAuth2Client","data":{"type":"object","description":"OAuth2 client registration response. Per RFC 7591, includes the client identifier, secret, timestamps, and all registered client metadata.","properties":{"clientId":{"type":"string","description":"Client identifier issued by the authorization server."},"clientSecret":{"type":"string","description":"Client secret issued by the authorization server."},"clientIdIssuedAt":{"type":"integer","format":"int64","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Time when the client_id is issued, represented as seconds since epoch (RFC7591)."},"children":[]}]}]}]},"clientSecretExpiresAt":{"type":"integer","format":"int64","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Time at which the client_secret expires, represented as seconds since epoch. 0 indicates the secret does not expire (RFC 7591)."},"children":[]}]}]}]},"name":{"type":"string","description":"Client name (registered metadata)."},"redirectUris":{"type":"array","items":{"type":"string","format":"uri"},"description":"List of redirect URIs (registered metadata)."},"registrationClientUri":{"type":"string","format":"uri","description":"URL of the client configuration endpoint for managing this client registration (RFC 7592)."},"registrationAccessToken":{"type":"string","description":"Access token to be used at the client configuration endpoint for managing this client registration (RFC 7592)."},"scopes":{"type":"array","items":{"type":"string","enum":["menu:read","menu:write","orders:read","orders:write","revenue:read"]},"description":"List of scopes (registered metadata)."},"grantTypes":{"type":"array","items":{"type":"string","enum":["authorization_code","client_credentials"]},"description":"List of grant types (registered metadata)."}},"required":["clientId","clientSecret","clientIdIssuedAt","clientSecretExpiresAt","registrationClientUri","registrationAccessToken"]}},"components/schemas/OrderNotification":{"id":"components/schemas/OrderNotification","kind":"json-schema","title":"OrderNotification","data":{"type":"object","required":["orderId","orderStatus","timestamp"],"properties":{"orderId":{"type":"string","description":"Unique order identifier."},"orderStatus":{"$ref":"#/components/schemas/OrderStatus"},"timestamp":{"type":"string","format":"date-time","description":"When the event occurred."}}}},"schema_10":{"kind":"json-schema","data":{"type":"string"},"id":"schema_10"},"schema_11":{"kind":"json-schema","data":{"type":"integer","minimum":1,"maximum":100,"default":10},"id":"schema_11"},"schema_12":{"kind":"json-schema","data":{"type":"string","pattern":"^prd_[0-9abcdefghjkmnpqrstvwxyz]{26}$"},"id":"schema_12"},"schema_13":{"kind":"json-schema","data":{"type":"string","enum":["thumbnail","medium","large"],"default":"medium"},"id":"schema_13"},"schema_14":{"kind":"json-schema","data":{"type":"string","format":"binary"},"id":"schema_14"},"schema_15":{"kind":"json-schema","data":{"description":"Alternative image text.","type":"string"},"id":"schema_15"},"schema_16":{"kind":"json-schema","data":{"type":"string","pattern":"^ord_[0-9abcdefghjkmnpqrstvwxyz]{26}$"},"id":"schema_16"},"schema_17":{"kind":"json-schema","data":{"type":"object","description":"Partial order update using JSON Merge Patch - only include fields to update.\n","properties":{"status":{"$ref":"#/components/schemas/OrderStatus"}},"required":["status"]},"id":"schema_17"},"schema_18":{"kind":"json-schema","data":{"type":"array","description":"List of menu items that are part of the order.","items":{"$ref":"#/components/schemas/OrderItem"}},"id":"schema_18"},"schema_19":{"kind":"json-schema","data":{"type":"string","format":"date-time"},"id":"schema_19"}},"exampleStore":{"paths/~1oauth2~1register/post/requestBody/content/application~1json/examples/RegisterClientObject":{"value":{"name":"auth","scopes":["menu:read","menu:write","orders:read","orders:write","revenue:read"],"grantTypes":["client_credentials"]},"key":"RegisterClientObject","summary":"RegisterClientObject","id":"paths/~1oauth2~1register/post/requestBody/content/application~1json/examples/RegisterClientObject"},"paths/~1oauth2~1register/post/requestBody/content/application~1json/examples/RegisterClientForAuthorizationCode":{"value":{"name":"pos-terminal","redirectUris":["https://api.cafe.redocly.com/callback"],"scopes":["menu:read","orders:read","orders:write"],"grantTypes":["authorization_code"]},"key":"RegisterClientForAuthorizationCode","summary":"RegisterClientForAuthorizationCode","id":"paths/~1oauth2~1register/post/requestBody/content/application~1json/examples/RegisterClientForAuthorizationCode"},"paths/~1menu/post/requestBody/content/multipart~1form-data/examples/Beverage":{"value":{"name":"Cappuccino","price":4500,"category":"beverage","volume":250,"containsCaffeine":true,"photoTextDescription":"A hot cappuccino in a white ceramic cup."},"key":"Beverage","summary":"Create a beverage","id":"paths/~1menu/post/requestBody/content/multipart~1form-data/examples/Beverage"},"paths/~1menu/post/requestBody/content/multipart~1form-data/examples/Dessert":{"value":{"name":"Chocolate-Brownie","price":3500,"category":"dessert","calories":420,"photoTextDescription":"A rich chocolate brownie square dusted with cocoa."},"key":"Dessert","summary":"Create a dessert","id":"paths/~1menu/post/requestBody/content/multipart~1form-data/examples/Dessert"},"paths/~1menu/post/responses/201/content/application~1json/examples/MenuItemResponse":{"value":{"id":"prd_01khr487f7qm7p44xn427m43vb","object":"menuItem","name":"coffee","price":4000,"category":"beverage","createdAt":"2026-02-18T10:20:38.228Z","updatedAt":"2026-02-18T10:20:38.228Z","volume":600,"containsCaffeine":false},"key":"MenuItemResponse","summary":"MenuItemResponse","id":"paths/~1menu/post/responses/201/content/application~1json/examples/MenuItemResponse"},"paths/~1orders/post/requestBody/content/application~1json/examples/OrderRequest":{"value":{"customerName":"Mary Ann","orderItems":[{"menuItemId":"prd_01h1s5z6vf2mm1mz3hevnn9va7","quantity":2,"comment":"No sugar!","discount":0}]},"key":"OrderRequest","summary":"OrderRequest","id":"paths/~1orders/post/requestBody/content/application~1json/examples/OrderRequest"},"paths/~1orders/post/responses/201/content/application~1json/examples/OrderResponse":{"value":{"id":"ord_01h1s5z6vf2mm1mz3hevnn9va7","customerName":"Mary Ann","orderItems":[{"menuItemId":"prd_01h1s5z6vf2mm1mz3hevnn9va7","quantity":2,"comment":"No sugar!","discount":0}],"object":"order","status":"placed","totalPrice":200,"createdAt":"2026-08-24T14:15:22Z","updatedAt":"2026-08-24T14:15:22Z"},"key":"OrderResponse","summary":"OrderResponse","id":"paths/~1orders/post/responses/201/content/application~1json/examples/OrderResponse"},"paths/~1orders~1{orderId}/get/responses/200/content/application~1json/examples/OrderResponse":{"value":{"id":"ord_01h1s5z6vf2mm1mz3hevnn9va7","customerName":"Mary Ann","orderItems":[{"menuItemId":"prd_01h1s5z6vf2mm1mz3hevnn9va7","quantity":2,"comment":"No sugar!","discount":0}],"object":"order","status":"placed","totalPrice":200,"createdAt":"2026-08-24T14:15:22Z","updatedAt":"2026-08-24T14:15:22Z"},"key":"OrderResponse","summary":"OrderResponse","id":"paths/~1orders~1{orderId}/get/responses/200/content/application~1json/examples/OrderResponse"},"paths/~1orders~1{orderId}/patch/responses/200/content/application~1json/examples/OrderResponse":{"value":{"id":"ord_01h1s5z6vf2mm1mz3hevnn9va7","customerName":"Mary Ann","orderItems":[{"menuItemId":"prd_01h1s5z6vf2mm1mz3hevnn9va7","quantity":2,"comment":"No sugar!","discount":0}],"object":"order","status":"completed","totalPrice":200,"createdAt":"2026-08-24T14:15:22Z","updatedAt":"2026-08-24T14:15:22Z"},"key":"OrderResponse","summary":"OrderResponse","id":"paths/~1orders~1{orderId}/patch/responses/200/content/application~1json/examples/OrderResponse"}},"securitySchemeStore":{"OAuth2":{"id":"OAuth2","type":"oauth2","description":[{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"OAuth2 authorization for API access. The token endpoint accepts "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grant_type=authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grant_type=client_credentials"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grant_type=refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]},{"$$mdtype":"Node","type":"heading","attributes":{"level":3},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Differences from the OAuth2 specifications"},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"A standard OAuth2 client library can drive these flows, with the following to account for."},"children":[]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Two behaviors do not conform to the specifications:"},"children":[]}]}]},{"$$mdtype":"Node","type":"list","attributes":{"ordered":false,"marker":"-"},"children":[{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Errors use RFC 9457 problem+json, not RFC 6749 Section 5.2."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" Failures return "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"application/problem+json"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" with "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"type"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"title"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"status"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"instance"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". There is no "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"error"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" or "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"error_description"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" field, so the standard codes ("},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"invalid_grant"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"invalid_client"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"unsupported_grant_type"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":") never appear — branch on the HTTP status and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"title"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" instead. A refresh token that is expired, already rotated, or unrecognized returns "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"400"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" with a "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"title"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" of "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"Refresh token has expired"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" or "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"Invalid refresh token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", where a conformant server would return "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"error: invalid_grant"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"."},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" is not a registrable grant type."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" RFC 7591 Section 2 lists it, but "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"/oauth2/register"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" accepts only "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" and "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"client_credentials"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" in "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"grantTypes"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":". Refreshing requires no registration: holding a refresh token issued to the client is the authorization. A consequence is that refresh capability cannot be disabled per client — every "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"authorization_code"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" grant returns a refresh token, so a client intended for a shared or public device cannot be registered without one."},"children":[]}]}]}]},{"$$mdtype":"Node","type":"paragraph","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Two are choices the specifications leave to the server:"},"children":[]}]}]},{"$$mdtype":"Node","type":"list","attributes":{"ordered":false,"marker":"-"},"children":[{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":"Refresh tokens rotate on every use."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" A successful refresh retires the token presented and returns a replacement in "},"children":[]},{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"refresh_token"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":", as RFC 6749 Section 6 permits and the OAuth2 Security Best Current Practice recommends. Store the new value; the old one stops working. Refresh tokens expire 30 days after they are issued, and rotation restarts that window. The authorization code flow returns a refresh token with every access token; the client credentials flow returns none (RFC 6749 Section 4.4.3)."},"children":[]}]}]},{"$$mdtype":"Node","type":"item","attributes":{},"children":[{"$$mdtype":"Node","type":"inline","attributes":{},"children":[{"$$mdtype":"Node","type":"strong","inline":true,"attributes":{"marker":"**"},"children":[{"$$mdtype":"Node","type":"code","inline":true,"attributes":{"content":"scope"},"children":[]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" accepts commas."},"children":[]}]},{"$$mdtype":"Node","type":"text","inline":true,"attributes":{"content":" The space-delimited form required by RFC 6749 is always accepted and recommended; comma-separated values are additionally tolerated."},"children":[]}]}]}]}],"flows":{"authorizationCode":{"authorizationUrl":"https://api.cafe.redocly.com/oauth2/authorize","tokenUrl":"https://api.cafe.redocly.com/oauth2/token","refreshUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}},"clientCredentials":{"tokenUrl":"https://api.cafe.redocly.com/oauth2/token","scopes":{"menu:read":"Read access to menu items and images","menu:write":"Write access to menu items (create, delete)","orders:read":"Read access to orders","orders:write":"Write access to orders (create, update, delete)","revenue:read":"Read access to revenue statistics"}}}},"ApiKey":{"id":"ApiKey","type":"apiKey","description":"API key for internal operations.","in":"header","paramName":"X-API-Key"}},"servers":[{"url":"/_mock/openapi/cafe","isMockServer":true,"description":"Mock server"},{"url":"https://api.cafe.redocly.com","description":"Live server."}]},"options":{"hideSidebar":true,"mockServer":{"url":"/_mock/openapi/cafe","position":"first","description":"Mock server"},"disableRouter":true,"downloadUrls":[{"url":"/_bundle/openapi/cafe.json?download"},{"url":"/_bundle/openapi/cafe.yaml?download"}],"excludeFromSearch":false,"specType":"openapi","markdocOptions":{"tags":{},"nodes":{},"components":{}},"metadata":{"title":"Redocly Cafe","description":"Demo API for cafe operators (not customers) to manage menus, orders, and revenue.\nCreate API credentials and try it yourself in a realistic OpenAPI workflow.\n"}},"baseSlug":"/openapi/cafe","routesMapping":{}}