Fiest Partner API
Build reviewed integrations for restaurant operations, accounting, orders, menus, and catalog imports.
The Fiest Partner API gives approved integrations scoped access to the restaurants a Fiest owner or administrator explicitly authorizes. Read access and each write family are approved separately.
Partner access is reviewed
API clients are registered by Fiest. The public reference documents the contract, but it does not enable self-service production access or expose capabilities that are still in private review.
Sandbox preview is available
Approved partners can integrate against an isolated sandbox today. Production access uses a separate client registration and is enabled only after Fiest approves the integration. A documented operation may also be disabled in an environment until Fiest approves and enables that capability for the client.
How access works
- Contact Fiest to register the integration and its exact redirect URIs.
- Redirect the Fiest owner or administrator through OAuth 2.1 authorization
code with PKCE
S256. - Request the mandatory baseline scopes
fiest.restaurant.readandfiest.accounting.read, plus only the optional read or write scopes Fiest approved for the client. - Send the audience-bound access token to the API resource registered for the connection.
- Treat access tokens as one-hour credentials while honoring
expires_in. Keep longer-lived connections with a rotating 90-day refresh token. Every successful refresh replaces the previous refresh token, which cannot be replayed.
Tokens are bound to the Partner API audience and cannot be reused with the Fiest MCP server. Restaurant access is resolved from the current authorization grant on every request. These lifetimes are maximums, not a promise that a token remains valid: revocation, membership changes, or an invalid grant can end access earlier and require a new authorization.
For a Management organization authorization, also request
fiest.organization.read. Request offline_access only when the integration
needs to stay connected after the current access token expires.
Available capabilities
Quick start
Configure OAuth, implement the callback, and give an AI coding agent the reviewed setup prompt.
API terminology
Define restaurants, menus, sold orders, payment reports, and identifiers before mapping them into your app.
Menus, items, and prices
List every item in a menu and read its effective price without confusing menu IDs with item IDs.
Authorized restaurants
Discover only the restaurants included in the reviewed grant.
Restaurant profile
Read general restaurant and operational context.
Accounting summary
Retrieve a reconciliation-aware summary for a date range.
Settlement attribution
Distinguish how an order was settled from how it entered Fiest.
Orders
Find bounded sold-order history and fetch exact details using opaque order IDs.
Menus
List menus, create drafts, and use stable public UUIDs for reviewed changes.
Direct item editing
Inspect the exact draft item and version before applying a guarded update.
Catalog import
Plan and apply bounded, idempotent catalog creation with server-issued IDs.
Looking for ChatGPT, Claude, Claude Code, or Codex? Open the Fiest MCP setup guide instead. MCP connections use a separate server, authorization audience, and setup flow from Partner API integrations.
Environments
Partners only need to choose between the sandbox and production. Fiest's internal development and staging environments are not part of the public integration surface.
| Environment | Status | API resource | OAuth issuer |
|---|---|---|---|
| Sandbox | Available to approved partners for isolated read testing | https://api-sandbox.fiest.io | https://auth-sandbox.fiest.io |
| Production | Available to approved partners | https://api.fiest.io | https://auth.fiest.io |
Sandbox and production clients are registered separately, and their redirect URIs, issuers, audiences, tokens, and credentials must never be mixed.
The public contract also documents reviewed menu and catalog writes. Those
operations are currently disabled on the shared sandbox and return
capability_disabled there. Fiest confirms a controlled write-test environment
and the exact approved scopes before a partner trials write access; production
write access is enabled separately after review.
Interactive requests
The first public reference release provides schemas and generated request examples without accepting credentials in this site. Fiest maintains a local-only API Lab for partner acceptance testing. A partner-authenticated hosted “Try it” experience may be added later after a separate security review.
Machine-readable contract
The reference pages on this site are generated from the same OpenAPI 3.1 document that partners and AI agents can read directly:
- JSON: docs.fiest.io/openapi.json
- YAML: docs.fiest.io/openapi.yaml
The document's fiestOAuth security scheme lists every OAuth 2.1 scope with
its meaning, and each operation's security entry names the scopes it
requires, so a client can request least-privilege access without reading
prose. The production API also publishes RFC 9728 protected-resource metadata
at
api.fiest.io/.well-known/oauth-protected-resource
with the same scopes_supported, and the authorization server publishes
RFC 8414 metadata at
auth.fiest.io/.well-known/oauth-authorization-server.
Every page on this site also answers Accept: text/markdown, or a .md
suffix on the page URL.