PetExec Authentication API

OAuth2 password-grant token issuance.

OpenAPI Specification

petexec-authentication-api-openapi.yml Raw ↑
openapi: 3.0.3
info:
  title: PetExec Authentication API
  description: The PetExec API is a REST API for existing PetExec customers and their developers to extend the PetExec pet-care business management platform (daycare, boarding, grooming, training, and scheduled services). Every endpoint, path, and scope in this document is transcribed directly from PetExec's own public GitHub examples repository (https://github.com/PetExec/API-Examples), which is the only complete source of PetExec API technical detail publicly available - PetExec's interactive apidoc reference at https://secure.petexec.net/api/apidoc/index.html is a JavaScript-rendered single-page app and does not expose a machine-readable spec. Access requires an active PetExec account. Client credentials (client_id / client_secret) are self-issued from Company Preferences > Misc. Settings > Maintain API Applications inside the PetExec console, then exchanged for a scoped Bearer token via an OAuth2 Resource Owner Password Credentials (password) grant against POST /token. PetExec was acquired by Togetherwork in November 2024 and is being migrated toward Gingr; PetExec is no longer accepting new customers, but this API surface is documented as live for existing accounts as of the review date. Some of PetExec's own published examples are internally inconsistent (mixed "user-card" / "userCard" casing, a menu example that appears to call the wrong path) - those inconsistencies are called out inline below rather than silently corrected.
  version: '1.0'
  contact:
    name: PetExec
    url: https://www.petexec.net/features/api-for-developers
servers:
- url: https://secure.petexec.net/api
  description: PetExec production API (used by nearly all official PHP and most JavaScript examples)
- url: https://beta.petexec.net/api
  description: PetExec beta/staging API (referenced by some official JavaScript examples for the same paths; not separately documented)
security:
- bearerAuth: []
tags:
- name: Authentication
  description: OAuth2 password-grant token issuance.
paths:
  /token:
    post:
      operationId: getAccessToken
      tags:
      - Authentication
      summary: Obtain an access token (password grant)
      description: Exchanges a PetExec username/password plus a client_id/client_secret (sent as an HTTP Basic Authorization header) for a scoped Bearer access token. `scope` is a space-separated list, e.g. "owner_read owner_update". Public clients (e.g. browser JavaScript) should not expose client_secret.
      security: []
      parameters:
      - name: Authorization
        in: header
        required: true
        description: Basic base64(client_id:client_secret)
        schema:
          type: string
      requestBody:
        required: true
        content:
          application/x-www-form-urlencoded:
            schema:
              type: object
              required:
              - grant_type
              - username
              - password
              properties:
                grant_type:
                  type: string
                  enum:
                  - password
                username:
                  type: string
                password:
                  type: string
                scope:
                  type: string
                  description: Space-separated list of requested scopes (e.g. owner_read, owner_update, usercard_read, menu_read, report_read).
      responses:
        '200':
          description: Access token issued.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TokenResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
components:
  schemas:
    TokenResponse:
      type: object
      properties:
        access_token:
          type: string
        token_type:
          type: string
        expires_in:
          type: integer
        scope:
          type: string
    Error:
      type: object
      additionalProperties: true
  responses:
    Unauthorized:
      description: Missing, invalid, or expired Bearer token, or insufficient scope.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: 'OAuth2 password-grant access token obtained from POST /token. Passed as `Authorization: Bearer YOUR_ACCESS_TOKEN`.'