Fiest Developers

Fiest Partner API

Build reviewed integrations for restaurant operations, accounting, orders, menus, and catalog imports.

The Fiest Partner API gives approved integrations scoped access to the restaurants a Fiest owner or administrator explicitly authorizes. Read access and each write family are approved separately.

Partner access is reviewed

API clients are registered by Fiest. The public reference documents the contract, but it does not enable self-service production access or expose capabilities that are still in private review.

Sandbox preview is available

Approved partners can integrate against an isolated sandbox today. Production access uses a separate client registration and is enabled only after Fiest approves the integration. A documented operation may also be disabled in an environment until Fiest approves and enables that capability for the client.

How access works

  1. Contact Fiest to register the integration and its exact redirect URIs.
  2. Redirect the Fiest owner or administrator through OAuth 2.1 authorization code with PKCE S256.
  3. Request the mandatory baseline scopes fiest.restaurant.read and fiest.accounting.read, plus only the optional read or write scopes Fiest approved for the client.
  4. Send the audience-bound access token to the API resource registered for the connection.
  5. Treat access tokens as one-hour credentials while honoring expires_in. Keep longer-lived connections with a rotating 90-day refresh token. Every successful refresh replaces the previous refresh token, which cannot be replayed.

Tokens are bound to the Partner API audience and cannot be reused with the Fiest MCP server. Restaurant access is resolved from the current authorization grant on every request. These lifetimes are maximums, not a promise that a token remains valid: revocation, membership changes, or an invalid grant can end access earlier and require a new authorization.

For a Management organization authorization, also request fiest.organization.read. Request offline_access only when the integration needs to stay connected after the current access token expires.

Available capabilities

Looking for ChatGPT, Claude, Claude Code, or Codex? Open the Fiest MCP setup guide instead. MCP connections use a separate server, authorization audience, and setup flow from Partner API integrations.

Environments

Partners only need to choose between the sandbox and production. Fiest's internal development and staging environments are not part of the public integration surface.

EnvironmentStatusAPI resourceOAuth issuer
SandboxAvailable to approved partners for isolated read testinghttps://api-sandbox.fiest.iohttps://auth-sandbox.fiest.io
ProductionAvailable to approved partnershttps://api.fiest.iohttps://auth.fiest.io

Sandbox and production clients are registered separately, and their redirect URIs, issuers, audiences, tokens, and credentials must never be mixed.

The public contract also documents reviewed menu and catalog writes. Those operations are currently disabled on the shared sandbox and return capability_disabled there. Fiest confirms a controlled write-test environment and the exact approved scopes before a partner trials write access; production write access is enabled separately after review.

Interactive requests

The first public reference release provides schemas and generated request examples without accepting credentials in this site. Fiest maintains a local-only API Lab for partner acceptance testing. A partner-authenticated hosted “Try it” experience may be added later after a separate security review.

Machine-readable contract

The reference pages on this site are generated from the same OpenAPI 3.1 document that partners and AI agents can read directly:

The document's fiestOAuth security scheme lists every OAuth 2.1 scope with its meaning, and each operation's security entry names the scopes it requires, so a client can request least-privilege access without reading prose. The production API also publishes RFC 9728 protected-resource metadata at api.fiest.io/.well-known/oauth-protected-resource with the same scopes_supported, and the authorization server publishes RFC 8414 metadata at auth.fiest.io/.well-known/oauth-authorization-server. Every page on this site also answers Accept: text/markdown, or a .md suffix on the page URL.

On this page