Florist One · OpenAPI Overlay 1.0.0

API Evangelist enhancements for Florist One Affiliate API

5 actions 5 updates update extends openapi/florist-one-affiliate-api-openapi.yml
Generated by API Evangelist Written by API Evangelist tooling for Florist One's API. It is a proposal applied on top of the contract, not a document Florist One publishes.
View Overlay File View on GitHub Overlay Specification

What the actions change

x-apievangelist-profilex-contract-provenancex-docs-gatedx-base-url-notex-wire-formatx-rfc7617-conformantx-wire-format-notex-no-www-authenticate

Targets 5

$.info
$.servers
$.components.securitySchemes.basicAuth
$.paths
$.paths['/affiliate/legalagreement'].post

OpenAPI Overlay

Raw ↑
overlay: 1.0.0
info:
  title: API Evangelist enhancements for Florist One Affiliate API
  version: 1.0.0
x-generated: '2026-09-10'
x-method: generated
x-source: >-
  Derived from Florist One's own published sample code at
  https://github.com/fhwsolutions/FloristOne_API, the public documentation at
  https://www.floristone.com/api/how-it-works/ and
  https://www.floristone.com/api/flowers-api-faq/, the API Agreement at
  https://www.floristone.com/api/print_api_legal/, and one live probe of
  https://www.floristone.com/api/rest on 2026-09-10. Applies our findings without mutating
  the harvested description.
extends: openapi/florist-one-affiliate-api-openapi.yml
actions:
  - target: $.info
    update:
      x-apievangelist-profile: https://apis.io/provider/florist-one/
      x-contract-provenance: >-
        Florist One publishes no OpenAPI. This description was written by API Evangelist
        from the provider's public PHP and ColdFusion sample code and its public
        documentation. It is a third-party description, not a provider artifact.
      x-docs-gated: >-
        The endpoint-level documentation at
        https://www.floristone.com/api/technical-information/ is behind an API Key and
        password login, so parameter semantics beyond the names below are unverified.
  - target: $.servers
    update:
      x-base-url-note: >-
        The callable base is https://www.floristone.com/api/rest. The /api/ path is the
        marketing and documentation site and is not an API host.
  - target: $.components.securitySchemes.basicAuth
    update:
      x-wire-format: 'Authorization: <base64(apikey:password)>'
      x-rfc7617-conformant: false
      x-wire-format-note: >-
        Every published Florist One sample omits the "Basic " scheme prefix required by
        RFC 7617. See authentication/florist-one-authentication.yml.
      x-no-www-authenticate: >-
        An unauthenticated request returns 403 with no WWW-Authenticate challenge and a
        text/html IIS error page.
  - target: $.paths
    update:
      x-error-envelope: >-
        No error responses are declared by the provider and none are documented. The one
        observed failure (403, unauthenticated) returns text/html, not JSON and not
        application/problem+json. See errors/florist-one-problem-types.yml.
      x-response-field-casing: >-
        Response keys are UPPERCASE (PRODUCTS, CODE, PRICE, ORDERNO, SUBTOTAL, ITEMS,
        RECIPIENT). A case-sensitive client written against lowercase keys will fail.
      x-rate-limit-signal: >-
        None. No RateLimit-*, X-RateLimit-* or Retry-After header is emitted. See
        rate-limits/florist-one-rate-limits.yml.
      x-idempotency: >-
        Not supported anywhere on this API. See conventions/florist-one-conventions.yml.
  - target: $.paths['/affiliate/legalagreement'].post
    update:
      x-purpose: >-
        Returns the affiliate legal agreement text for display in the integrator's own
        signup flow, on a content field. The human-readable equivalents are published at
        https://www.floristone.com/api/print_affiliate_legal/ and
        https://www.floristone.com/api/print_api_legal/.
      x-read-only-in-effect: >-
        Declared as POST but retrieves content and mutates nothing.