OpenAPI Specification
swagger: '2.0'
info:
version: '1.0'
title: NewStore address token-operations API
description: NewStore public APIs
contact:
email: support@newstore.com
name: NewStore API Support
url: https://developer.newstore.com
host: dodici-demo.p.newstore.net
basePath: /
schemes:
- https
consumes:
- application/json
produces:
- application/json
security: []
tags:
- name: token-operations
description: Tokens
paths:
/customer/tokens:
post:
description: "\n<div style=\"background-color: rgba(243, 156, 18, 0.15); border: 1px solid #f39c12; border-left: 4px solid #f39c12; padding: 12px; margin: 10px 0; border-radius: 4px; color: #f39c12;\">\n <strong>\U0001F6A7 BETA:</strong> This endpoint is in beta and may change.\n <br />\n See <a href=\"https://docs.newstore.com/docs/api-lifecycle\" target=\"_blank\" style=\"color: #f39c12; text-decoration: underline;\">API Lifecycle Documentation</a> for details.\n</div>\n\nThere are two possible operations:\n- **tokenize**\n - Tokenizes PII data that is not related to a profile, tokens are only valid for 30 days.\n- **detokenize**\n - Detokenizes a list of tokens for profiles, addresses, or data entries.\n"
summary: createTokensOperations
tags:
- token-operations
operationId: createTokensOperations
deprecated: false
produces:
- application/problem+json
- application/json
consumes:
- application/json
parameters:
- name: Content-Type
in: header
required: false
enum:
- application/json
type: string
description: ''
- name: body
in: body
required: true
description: Token operation request payload containing the data to tokenize or detokenize
schema:
$ref: '#/definitions/TokensRequest'
- name: operation
in: query
required: false
enum:
- tokenize
- detokenize
default: tokenize
type: string
description: The token operation that will be performed. By default it's **tokenize**.
responses:
default:
description: Unexpected error
schema:
$ref: '#/definitions/Problem'
headers: {}
'200':
description: The response contains a list of data (tokens/plain text) according to the operation and a list of errors per keys that failed to perform the operation.
schema:
$ref: '#/definitions/TokensResponse'
headers: {}
'400':
description: Bad request.
schema:
$ref: '#/definitions/Problem'
headers: {}
'403':
description: Forbidden.
schema:
$ref: '#/definitions/Problem'
headers: {}
'429':
description: Too Many Requests
schema:
$ref: '#/definitions/Problem'
headers:
Retry-After:
type: string
'500':
description: Internal Server Error.
schema:
$ref: '#/definitions/Problem'
headers: {}
'502':
description: Bad Gateway
schema:
$ref: '#/definitions/Problem'
headers: {}
'503':
description: Service Unavailable
schema:
$ref: '#/definitions/Problem'
headers: {}
security:
- oauth:
- customer:profile:write
- customer:profile:read
definitions:
TokensRequest:
title: TokensRequest
description: Tokens request.
type: object
properties:
data:
description: Sensitive data to be tokenized or detokenized, according to the operation.
example:
key1: foo
key2: bar
type: object
minProperties: 1
maxProperties: 25
required:
- data
Problem:
title: Problem
type: object
properties:
detail:
description: A human readable explanation specific to this occurrence of the problem that is helpful to locate the problem and give advice on how to proceed. Written in English and readable for engineers, usually not suited for non technical stakeholders and not localized.
example: some description for the error situation
type: string
error_code:
type: string
instance:
description: A URI reference that identifies the specific occurrence of the problem, e.g. by adding a fragment identifier or sub-path to the problem type. May be used to locate the root of this problem in the source code.
example: /some/uri-reference#specific-occurrence-context
type: string
message:
type: string
messages:
type: array
items:
type: string
request_id:
type: string
status:
description: The HTTP status code generated by the origin server for this occurrence of the problem.
type: integer
minimum: 100.0
maximum: 600.0
exclusiveMaximum: true
format: int32
title:
description: A short summary of the problem type. Written in English and readable for engineers, usually not suited for non technical stakeholders and not localized.
example: some title for the error situation
type: string
type:
description: A URI reference that uniquely identifies the problem type only in the context of the provided API. Opposed to the specification in RFC-7807, it is neither recommended to be dereferenceable and point to a human-readable documentation nor globally unique for the problem type.
example: /some/uri-reference
type: string
default: about:blank
TokensResponse:
title: TokensResponse
description: Tokens response.
type: object
properties:
data:
description: Keys with tokens or detokenized plaintext data, according to the operation.
example:
key1: john.doe@example.org
type: object
maxProperties: 25
errors:
description: Keys with error codes.
example:
key2: token_not_found_error
type: object
maxProperties: 25
required:
- data
- errors
securityDefinitions:
oauth:
type: oauth2
flow: application
tokenUrl: https://id.p.newstore.net/auth/realms/dodici-demo/protocol/openid-connect/token
scopes:
catalog:import-schemas:read: Grants privileges to read import schema
catalog:import-schemas:write: Grants privileges to write import schema
catalog:pricebook-export:read: Grants privileges to export pricebook data
catalog:product-export:read: Grants privileges to export product data
checkout:carts:read: Grants privileges to read cart data
checkout:carts:write: Grants privileges to write cart data
clienteling:profile:read: Grants privileges to read clienteling profiles
customer:profile:read: Grants privileges to read API customer data
customer:profile:write: Grants privileges to modify API customer data
newstore:configuration:read: Grants privileges to read configuration
newstore:configuration:write: Grants privileges to write configuration
fiscalization:orders:read: View orders with fiscal transactions and signatures
fiscalization:orders:write: Create orders with fiscal transactions and signatures
shipments:read: Read Shipping Options and Audits
iam:providers:read: ' Grants read privileges to provider resources'
iam:providers:write: ' Grants write privileges to provider resources'
iam:roles:read: ' Grants privileges to read roles data'
iam:roles:write: ' Grants privileges to write roles data'
iam:users:read: ' Grants privileges to read user data'
iam:users:write: ' Grants privileges to write user data'
inventory:reservations:read: Allows access to retrieve reservations
inventory:reservations:write: Allows access to create and update reservations
promotions:config:read: Grants privileges to read configuration
promotions:config:write: Grants privileges to write into configuration
promotions:reason-codes:read: Grants privileges to list reason codes
promotions:reason-codes:write: Grants privileges to create and update reason codes
audit-events:read: Grants read access to the tenant's audit events.
taxes:preview-transactions:write: Preview tax transactions
taxes:transactions:read: Read tax transactions