Every API here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for apis
7 MCP tools reach this
find_apisBrowse and filter every API in the catalog.
get_api_artifactsOne API's artifacts, grouped by type.
get_openapiThe primary OpenAPI for this API.
find_similar_apisAPIs that look like this one.
apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
resolveTurn a domain, URL or GitHub org into the provider it belongs to.
find_cohortsEvery scored population of providers in the catalog.
All 92 tools →
Call it yourself
curl for this page
This API
curl "https://apis.io/api/v1/apis/otter-organization-endpoints-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
title: Public Organization Endpoints API
description: '# Overview
The API endpoints are developed around RESTful principles secure via the OAuth2.0 protocol.'
version: v1
license:
name: Proprietary
contact:
name: Kin Lane
email: kin@apievangelist.com
x-generated-from: documentation
x-source-url: https://developer-guides.tryotter.com/api-reference/
x-last-validated: '2026-06-03'
servers:
- url: https://{public-api-url}/
description: Otter Public API base URL. The concrete host is provisioned per integration partner/account via your Otter account representative; substitute the value provided during onboarding.
variables:
public-api-url:
default: public-api-url
description: Account-specific Public API host provided by Otter during onboarding.
tags:
- name: Organization Endpoints
description: Endpoints to interact with with organizations/brands/stores and with integration connections.
x-displayName: Organization
paths:
/organization/v1/organization:
get:
tags:
- Organization Endpoints
summary: Otter Get the Organization Managed by the User
operationId: organizationGetOrganization
responses:
'200':
description: The organization managed by the user.
content:
application/json:
schema:
$ref: '#/components/schemas/Organization'
examples:
OrganizationGetOrganization200Example:
summary: Default organizationGetOrganization 200 response
x-microcks-default: true
value:
id: 9208071e-5f7a-444a-b3a7-4a57ff3f614e
name: Organization name 1
'400':
$ref: '#/components/responses/400'
'401':
$ref: '#/components/responses/401'
'403':
$ref: '#/components/responses/403'
'404':
$ref: '#/components/responses/404'
'422':
$ref: '#/components/responses/422'
security:
- OAuth2.0:
- organization.read
x-microcks-operation:
delay: 0
dispatcher: FALLBACK
/organization/v1/organization/brands/{brandId}:
get:
tags:
- Organization Endpoints
summary: Otter Get a Brand of the Organization Managed by the User
operationId: organizationGetBrand
parameters:
- $ref: '#/components/parameters/brandId'
responses:
'200':
description: The requested brand.
content:
application/json:
schema:
$ref: '#/components/schemas/Brand'
examples:
OrganizationGetBrand200Example:
summary: Default organizationGetBrand 200 response
x-microcks-default: true
value:
id: 9208071e-5f7a-444a-b3a7-4a57ff3f614e
name: Brand name 1
'400':
$ref: '#/components/responses/400'
'401':
$ref: '#/components/responses/401'
'403':
$ref: '#/components/responses/403'
'404':
$ref: '#/components/responses/404'
'422':
$ref: '#/components/responses/422'
security:
- OAuth2.0:
- organization.read
x-microcks-operation:
delay: 0
dispatcher: FALLBACK
/organization/v1/organization/brands:
get:
tags:
- Organization Endpoints
summary: Otter Get the List of Brands of the Organization Managed by the User
operationId: organizationListBrands
parameters:
- $ref: '#/components/parameters/limit-2'
- $ref: '#/components/parameters/opaquePaginationToken'
responses:
'200':
description: The list of brands that belong to the organization.
content:
application/json:
schema:
$ref: '#/components/schemas/ListBrandsResponse'
examples:
OrganizationListBrands200Example:
summary: Default organizationListBrands 200 response
x-microcks-default: true
value:
items:
- id: 9208071e-5f7a-444a-b3a7-4a57ff3f614e
name: Brand name 1
offsetToken: H12MAF2fFaFFFa
'400':
$ref: '#/components/responses/400'
'401':
$ref: '#/components/responses/401'
'403':
$ref: '#/components/responses/403'
'404':
$ref: '#/components/responses/404'
'422':
$ref: '#/components/responses/422'
security:
- OAuth2.0:
- organization.read
x-microcks-operation:
delay: 0
dispatcher: FALLBACK
/organization/v1/organization/brands/{brandId}/stores/{storeId}:
get:
tags:
- Organization Endpoints
summary: Otter Get a Store of the Organization Managed by the User
operationId: organizationGetStore
parameters:
- $ref: '#/components/parameters/brandId'
- $ref: '#/components/parameters/storeId'
responses:
'200':
description: The requested store.
content:
application/json:
schema:
$ref: '#/components/schemas/Store'
examples:
OrganizationGetStore200Example:
summary: Default organizationGetStore 200 response
x-microcks-default: true
value:
id: 9208071e-5f7a-444a-b3a7-4a57ff3f614e
name: Store name 1
address:
fullAddress: 123 Sample Street Ste 100, San Francisco, CA 94103
postalCode: '20500'
city: Washington
state: DC
countryCode: US
addressLines:
- 1600 Pennsylvania Avenue NW
- 123 Sample Street Ste 100, San Francisco, CA 94103
linesOfAddress:
- 1600 Pennsylvania Avenue NW
- 123 Sample Street Ste 100, San Francisco, CA 94103
location: {}
'400':
$ref: '#/components/responses/400'
'401':
$ref: '#/components/responses/401'
'403':
$ref: '#/components/responses/403'
'404':
$ref: '#/components/responses/404'
'422':
$ref: '#/components/responses/422'
security:
- OAuth2.0:
- organization.read
x-microcks-operation:
delay: 0
dispatcher: FALLBACK
/organization/v1/organization/brands/{brandId}/stores:
get:
tags:
- Organization Endpoints
summary: Otter Get the List of Stores of a Given Brand
operationId: organizationListStores
parameters:
- $ref: '#/components/parameters/brandId'
- $ref: '#/components/parameters/limit-2'
- $ref: '#/components/parameters/opaquePaginationToken'
responses:
'200':
description: The list of stores of the selected brand.
content:
application/json:
schema:
$ref: '#/components/schemas/ListStoresResponse'
examples:
OrganizationListStores200Example:
summary: Default organizationListStores 200 response
x-microcks-default: true
value:
items:
- id: 9208071e-5f7a-444a-b3a7-4a57ff3f614e
name: Store name 1
address: {}
offsetToken: H12MAF2fFaFFFa
'400':
$ref: '#/components/responses/400'
'401':
$ref: '#/components/responses/401'
'403':
$ref: '#/components/responses/403'
'404':
$ref: '#/components/responses/404'
'422':
$ref: '#/components/responses/422'
security:
- OAuth2.0:
- organization.read
x-microcks-operation:
delay: 0
dispatcher: FALLBACK
/organization/v1/organization/brands/{brandId}/stores/{storeId}/connection:
get:
tags:
- Organization Endpoints
summary: Otter Get the Partner Application Connection with the Selected Store
operationId: organizationGetConnection
parameters:
- $ref: '#/components/parameters/brandId'
- $ref: '#/components/parameters/storeId'
responses:
'200':
description: The information about the partner application connection.
content:
application/json:
schema:
$ref: '#/components/schemas/Connection'
examples:
OrganizationGetConnection200Example:
summary: Default organizationGetConnection 200 response
x-microcks-default: true
value:
storeId: 9208071e-5f7a-444a-b3a7-4a57ff3f614e
'400':
$ref: '#/components/responses/400'
'401':
$ref: '#/components/responses/401'
'403':
$ref: '#/components/responses/403'
'404':
$ref: '#/components/responses/404'
'422':
$ref: '#/components/responses/422'
security:
- OAuth2.0:
- organization.service_integration
x-microcks-operation:
delay: 0
dispatcher: FALLBACK
post:
tags:
- Organization Endpoints
summary: Otter Create a Connection for the Partner Application with the Selected Store
operationId: organizationCreateConnection
parameters:
- $ref: '#/components/parameters/brandId'
- $ref: '#/components/parameters/storeId'
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/CreateConnectionRequest'
examples:
OrganizationCreateConnectionRequestExample:
summary: Default organizationCreateConnection request
x-microcks-default: true
value:
storeId: 9208071e-5f7a-444a-b3a7-4a57ff3f614e
required: true
responses:
'204':
description: The connection was successfully created.
'400':
$ref: '#/components/responses/400'
'401':
$ref: '#/components/responses/401'
'403':
$ref: '#/components/responses/403'
'404':
$ref: '#/components/responses/404'
'409':
$ref: '#/components/responses/409'
'422':
$ref: '#/components/responses/422'
security:
- OAuth2.0:
- organization.service_integration
x-microcks-operation:
delay: 0
dispatcher: FALLBACK
delete:
tags:
- Organization Endpoints
summary: Otter Delete the Connection Between the Partner Application and the Selected…
operationId: organizationDeleteConnection
parameters:
- $ref: '#/components/parameters/brandId'
- $ref: '#/components/parameters/storeId'
responses:
'204':
description: The connection was successfully deleted.
'400':
$ref: '#/components/responses/400'
'401':
$ref: '#/components/responses/401'
'403':
$ref: '#/components/responses/403'
'404':
$ref: '#/components/responses/404'
'422':
$ref: '#/components/responses/422'
security:
- OAuth2.0:
- organization.service_integration
x-microcks-operation:
delay: 0
dispatcher: FALLBACK
components:
responses:
'401':
description: Invalid authorization.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorMessage'
'409':
description: The connection between the partner application and the store already exists.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorMessage'
'404':
description: Resource not found.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorMessage'
'403':
description: Authorization not valid for the requested resource.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorMessage'
'400':
description: The request is malformed.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorMessage'
'422':
description: The request body is not valid.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorMessage'
schemas:
ListStoresResponse:
required:
- items
type: object
properties:
items:
type: array
description: Array of Stores
items:
$ref: '#/components/schemas/Store'
offsetToken:
type: string
description: Opaque token used to fetch the following page. If not set, no more stores are available.
example: H12MAF2fFaFFFa
Brand:
required:
- id
- name
type: object
properties:
id:
type: string
description: Brand identifier.
example: 9208071e-5f7a-444a-b3a7-4a57ff3f614e
name:
type: string
description: Brand name.
example: Brand name 1
Location:
required:
- latitude
- longitude
type:
- object
- 'null'
properties:
latitude:
type: number
description: The latitude of the location.
format: double
example: 38.8977
longitude:
type: number
description: The longitude of the location.
format: double
example: 77.0365
description: Latitude and longitude of the address.
ListBrandsResponse:
required:
- items
type: object
properties:
items:
type: array
description: Array of brands.
items:
$ref: '#/components/schemas/Brand'
offsetToken:
type: string
description: Opaque token used to fetch the following page. If not set, no more brands are available.
example: H12MAF2fFaFFFa
ErrorDetail:
type: object
properties:
attribute:
type: string
description: The error attribute.
example: Order Currency Code
message:
type: string
description: The error detail description.
example: Order Currency Code must be exactly 3 characters
description: The error detail response object.
Organization:
required:
- id
- name
type: object
properties:
id:
type: string
description: Organization identifier.
example: 9208071e-5f7a-444a-b3a7-4a57ff3f614e
name:
type: string
description: Organization name.
example: Organization name 1
ErrorMessage:
type: object
properties:
message:
type: string
description: The error description.
example: The request body is invalid.
details:
type: array
description: The error details.
items:
$ref: '#/components/schemas/ErrorDetail'
description: The error response object.
Connection:
required:
- storeId
type: object
properties:
storeId:
type: string
description: The unique identifier of the store in the partner application. This is the ID, along with the Application ID, used to match the correct store when performing operations.
example: 9208071e-5f7a-444a-b3a7-4a57ff3f614e
Address:
type:
- object
- 'null'
properties:
fullAddress:
type:
- string
- 'null'
description: Full, human comprehensible address. It is usually formatted in the order appropriate for your locale.
example: 123 Sample Street Ste 100, San Francisco, CA 94103
postalCode:
type: string
description: Postal code of the address.
example: '20500'
city:
type: string
description: The city/town portion of the address.
example: Washington
state:
type: string
description: Highest administrative subdivision which is used for postal addresses of a country or region. For example, this can be a state, a province, or a prefecture.
example: DC
countryCode:
type: string
description: CLDR country code. See http://cldr.unicode.org/
example: US
addressLines:
type:
- array
- 'null'
description: Address lines (e.g. street, PO Box, or company name) or the full single line address (e.g. street, city, state, country, zip).
example:
- 1600 Pennsylvania Avenue NW
- 123 Sample Street Ste 100, San Francisco, CA 94103
items:
type: string
linesOfAddress:
type:
- array
- 'null'
deprecated: true
description: 'Deprecated: use addressLines. Address lines (e.g. street, PO Box, or company name) or the full single line address (e.g. street, city, state, country, zip).'
example:
- 1600 Pennsylvania Avenue NW
- 123 Sample Street Ste 100, San Francisco, CA 94103
items:
type: string
location:
$ref: '#/components/schemas/Location'
description: Order delivery address.
CreateConnectionRequest:
required:
- storeId
type: object
properties:
storeId:
type: string
description: The unique identifier of the store in the partner application. This is the ID, along with the Application ID, used to match the correct store when performing operations.
example: 9208071e-5f7a-444a-b3a7-4a57ff3f614e
Store:
required:
- id
- name
- address
type: object
properties:
id:
type: string
description: Store identifier.
example: 9208071e-5f7a-444a-b3a7-4a57ff3f614e
name:
type: string
description: Store name.
example: Store name 1
address:
$ref: '#/components/schemas/Address'
parameters:
storeId:
name: storeId
in: path
required: true
schema:
type: string
description: A unique identifier of a store in a UUID format.
example: 295f76b4-5725-4bf5-a8ab-97943dbdc3b4
opaquePaginationToken:
name: token
in: query
required: false
schema:
type: string
description: Opaque token used for paging. Query parameters must be URL encoded.
example: CgwI09+kjQYQwOvF2AM=/(urlencoded:CgwI09%2BkjQYQwOvF2AM%3D)
brandId:
name: brandId
in: path
required: true
schema:
type: string
description: A unique identifier of a brand in a UUID format.
example: 295f76b4-5725-4bf5-a8ab-97943dbdc3b4
limit-2:
name: limit
in: query
required: true
schema:
type: string
description: Max number of stores to retrieve
example: 5
securitySchemes:
OAuth2.0:
type: oauth2
description: "The **Authorization API** is based on the [OAuth2.0 protocol](https://tools.ietf.org/html/rfc6749), supporting the (Client Credentials)[https://datatracker.ietf.org/doc/html/rfc6749#section-4.4] and the (Authorization Code)[https://datatracker.ietf.org/doc/html/rfc6749#section-4.1] flows. Resources expect a valid token sent as a `Bearer` token in the HTTP `Authorization` header.\n### Scopes\nScopes must be configured by our internal team to be enabled for an app. Once the scopes are configured they can be enabled on the Application Settings Page in Developer Portal. Each endpoint requires a given scope that can be verified on each endpoint documentation. When generating an OAuth2.0 token multiple scopes can be requested.\n\n### Authorization Code Flow\nTo perform this flow, the authorization code flow must be enabled in the Application Settings Page in Developer Portal. When enabling the flow it is mandatory to provide a redirect URI pointing to your application. Once the flow is complete we will redirect the user to this URI passing the 'code' and 'state' parameters.\nThe Authorization Code flow provides a temporary code that the client application can exchange for an access token. To start the flow the application must request the user authorization. This is done by sending a request to https://{{public-api-url}}/v1/auth/oauth2/authorize.\nExample\n```\ncurl --location 'https://{{public-api-url}}/v1/auth/oauth2/authorize?client_id=[CLIENT_ID]&redirect_uri=[REDIRECT_URI]&response_type=code&scope=organization.read&state=8A9D16B4C3E25F6A'\n```\nThis call will return a 302 redirecting the user to our authorization page. If the user approves the application, we will redirect to configured URI passing the authorization code in the query parameter 'code'. The 'state' parameter is also sent to ensure the source of the data.\nWith the authorization code, the client application can generate the token.\n### Client Credentials Flow\nThe client_credentials flow does not require any steps before generating the token. Once your application is ready, and the client_id and client_secret are available, the token can be generated by following the instructions in the next section.\n\n### Generate Token\nTo generate the token, use the `Client ID` and `Client Secret` (provided during onboarding), and optionally the authorization code obtained after performing the Authorization Code flow, to the [Token Auth endpoint](#operation/requestToken) endpoint. The result of this invocation is a token that is valid for a pre-determined time or until it is manually revoked.\n\nThe access token obtained will be sent as a `Bearer` value of the `Authorization` HTTP header.\n\nClient credentials in the request-body and HTTP Basic Auth are supported.\n\n#### Request Example for client_credentials\n```\ncurl --location --request POST 'https://{{public-api-url}}/v1/auth/token' \\\n --header 'Content-Type: application/x-www-form-urlencoded' \\\n --data-urlencode 'scope=ping' \\\n --data-urlencode 'grant_type=client_credentials' \\\n --data-urlencode 'client_id=[APPLICATION_ID]' \\\n --data-urlencode 'client_secret=[CLIENT_SECRET]'\n\n```\n#### Request Example for authorization_code\n```\ncurl --location --request POST 'https://{{public-api-url}}/v1/auth/token' \\\n --header 'Content-Type: application/x-www-form-urlencoded' \\\n --data-urlencode 'scope=ping' \\\n --data-urlencode 'grant_type=authorization_code' \\\n --data-urlencode 'client_id=[APPLICATION_ID]' \\\n --data-urlencode 'client_secret=[CLIENT_SECRET]' \\\n --data-urlencode 'code=[code]' \\\n --data-urlencode 'redirect_uri=[redirect_uri]'\n\n```\n#### Response Example\n```\n{\n \"access_token\": \"oMahtBwBbnZeh4Q66mSuLFmk2V0_CLCKVt0aYcNJlcg.yditzjwCP7yp0PgR6AzQR3wQ1rTdCjkcPeAMuyfK-NU\",\n \"expires_in\": 2627999,\n \"scope\": \"ping orders.create\",\n \"token_type\": \"bearer\"\n}\n```\n\n### Token Usage\n\nThe token provided in field `access_token` is used to authenticate when consuming the API endpoints. Send the token value in the `Authorization` header of every request. The token expiration time is represented in the field `expired_in`, in seconds. Currently, all tokens are valid for 30 days and should be stored and re-used while still valid.\n\nNote that occasionally, a 401 error may be returned for a valid token due to an internal service issue. Such occurrences should be rare. To prevent exposing potential vulnerabilities to attackers, the Public API does not disclose other types of errors in the authentication flow if for any reason the token can't be validated (when it's a valid token then it's ok to return 5XX or other 4XX though - such as 403). In such scenarios, although the internal auth flow avoids retries to prevent attacks, if the token is known to be valid and not expired, a retry with a backoff interval by the client is advised. Another option is to request a new token.\n\n#### Example\n\n```\ncurl --location --request GET 'https://{{public-api-url}}/v1/ping' \\\n --header 'Authorization: Bearer <access_token>' \\\n --header 'X-Store-Id: <storeId>'\n\n```\n"
flows:
clientCredentials:
tokenUrl: /v1/auth/token
scopes:
catalog: Permission to interact with product inventory for existing stores.
delivery.provider: Permission to provide delivery services for existing orders.
finance: Permission to provide financial data for orders/stores.
manager.menus: Permission to manage menus.
manager.orders: Permission to manage orders.
manager.storefront: Permission to manage storefront.
menus.async_job.read: Permission to read the status of a menu upsert job.
menus.entity_suspension: Permission to notify the result of a menu entity availability update, after being requested by a webhook event.
menus.get_current: Permission to send the current state of a menu, after being requested by a webhook event.
menus.publish: Permission to notify the result of a publish menus operation for a given store.
menus.read: Permission to read the current menus for a given store.
menus.upsert: Permission to create/update menus for a given store.
menus.upsert_hours: Permission to notify the receiving of the upsert hours menu event, after being requested by a webhook event.
orders.create: Permission to create new order for a given store.
orders.read: Permission to read orders and connected data.
orders.update: Permission to create and update new orders for a given store.
ping: Permission to ping the system.
reports.generate_report: Permission to request reports for given store(s) and period of time.
reviews.reply: Permission to reply to reviews.
storefront.store_pause_unpause: Permission to notify the result of a pause/unpause operation, after being requested by a webhook event.
storefront.store_availability: Permission to send the current state of store.
storefront.store_hours_configuration: Permission to send the current store hours configuration.
stores.manage: Permission to onboard stores and update the identifier.
callback.error.write: Token has permission to send failed webhook event results.
manager.loyalty: Permission to interact with loyalty services.
direct.orders: Permission to interact with direct order services.
store.read: Permission to query store information.
authorizationCode:
authorizationUrl: /v1/auth/oauth2/authorize
tokenUrl: /v1/auth/token
scopes:
organization.read: Permission to read data for organization/brands/stores on behalf of a user.
organization.service_integration: Permission to manage the your integration with a given store on behalf of a user.
x-tagGroups:
- name: Endpoints
tags:
- Account Pairing Endpoints
- Auth Endpoints
- Callback Endpoints
- Delivery Endpoints
- Finance Endpoints
- Inventory Endpoints
- Manager Menu Endpoints
- Manager Order Endpoints
- Manager Storefront Endpoints
- Menus Endpoints
- Orders Endpoints
- Organization Endpoints
- Ping Endpoints
- Reports Endpoints
- Reviews Endpoints
- Storefront Endpoints
- Manager Loyalty Endpoints
- Direct Orders Endpoints
- Store Endpoints
- name: Webhooks
tags:
- Account Pairing Webhooks
- Delivery Webhooks
- Manager Orders Webhooks
- Menus Webhooks
- Orders Webhooks
- Ping Webhooks
- Reports Webhooks
- Storefront Webhooks