Punchh · OpenAPI Overlay 1.0.0
API Evangelist conversational phrasing for Online Ordering and SSO User Sign-up and SSO API
9 actions
9 updates
phrasing
extends
openapi/punchh-user-sign-up-and-sso-api-openapi.yml
Generated by API Evangelist
Written by API Evangelist tooling for Punchh's API. It is a proposal applied on top of the contract, not a document Punchh publishes.
What the actions change
x-apievangelist-phrasing
Targets 9
$.info
$.paths['/api/auth/customers.json'].post
$.paths['/api/auth/customers/sign_in'].post
$.paths['/api/auth/sso'].post
$.paths['/api/auth/users/reset_password_token'].post
$.paths['/oauth/token'].post
$.paths['/api/auth/users/connect_with_facebook'].post
$.paths['/api/auth/users/connect_with_apple'].post
$.paths['/api/auth/users/connect_with_google'].post
OpenAPI Overlay
# Generated by API Evangelist (build-phrasing.py). Our phrasing, not observed demand.
overlay: 1.0.0
info:
title: API Evangelist conversational phrasing for Online Ordering and SSO User Sign-up and SSO API
version: 1.0.0
extends: openapi/punchh-user-sign-up-and-sso-api-openapi.yml
actions:
- target: $.info
update:
x-apievangelist-phrasing:
method: generated
generated: '2026-10-01'
generator: build-phrasing.py
label: Generated by API Evangelist
operations: 8
- target: $.paths['/api/auth/customers.json'].post
update:
x-apievangelist-phrasing:
intent: Register a new guest account online
effect: write
questions:
- How does an online ordering site register a new loyalty guest with email and password?
- Do I need first and last name when the guest signs up with a referral code?
instructions:
- text: Sign up a new guest with details {user}.
slots:
user: requestBody.user
- text: Create a loyalty account for {user} under business client {client}.
slots:
user: requestBody.user
client: requestBody.client
method: generated
generated: '2026-10-01'
- target: $.paths['/api/auth/customers/sign_in'].post
update:
x-apievangelist-phrasing:
intent: Log a guest in with email and password
effect: write
questions:
- How do I sign an existing guest in with their email and password?
- What do I get back when a guest logs in successfully?
instructions:
- text: Log in the guest with credentials {user}.
slots:
user: requestBody.user
- text: Sign in {user} using email and password for client {client}.
slots:
user: requestBody.user
client: requestBody.client
method: generated
generated: '2026-10-01'
- target: $.paths['/api/auth/sso'].post
update:
x-apievangelist-phrasing:
intent: Exchange a security token for an auth token
effect: write
questions:
- How does a partner site turn its SSO security token into a guest authentication token?
- What's needed to create an SSO access token?
instructions:
- text: Create an SSO access token from security token {security_token}.
slots:
security_token: requestBody.security_token
- text: Exchange {security_token} for a guest authentication token.
slots:
security_token: requestBody.security_token
method: generated
generated: '2026-10-01'
- target: $.paths['/api/auth/users/reset_password_token'].post
update:
x-apievangelist-phrasing:
intent: Get a password reset token for a guest
effect: write
questions:
- How can a guest who forgot their password get a reset token?
- Can the site request a password reset token for a specific user?
instructions:
- text: Get a password reset token for {user}.
slots:
user: requestBody.user
- text: Start a password reset for the guest {user}.
slots:
user: requestBody.user
method: generated
generated: '2026-10-01'
- target: $.paths['/oauth/token'].post
update:
x-apievangelist-phrasing:
intent: Exchange an OAuth code for an SSO token
effect: write
questions:
- After a guest logs in on the hosted sign-in form, how do I get an access token from the authorization code?
- Which grant type and redirect URI does the SSO token exchange need?
instructions:
- text: Exchange authorization code {code} for an access token with client {client_id}, secret {client_secret}, redirect {redirect_uri}, grant {grant_type}.
slots:
code: requestBody.code
client_id: requestBody.client_id
client_secret: requestBody.client_secret
redirect_uri: requestBody.redirect_uri
grant_type: requestBody.grant_type
- text: Get the SSO token for code {code} returned to {redirect_uri}.
slots:
code: requestBody.code
redirect_uri: requestBody.redirect_uri
method: generated
generated: '2026-10-01'
- target: $.paths['/api/auth/users/connect_with_facebook'].post
update:
x-apievangelist-phrasing:
intent: Sign a guest in or up with Facebook
effect: write
questions:
- Can guests register for loyalty using their Facebook account?
- What profile details can I send along when a guest connects with Facebook?
instructions:
- text: Log in with Facebook token {access_token} for {email}.
slots:
access_token: requestBody.access_token
email: requestBody.email
- text: Register {email} via Facebook token {access_token} with phone {phone}.
slots:
email: requestBody.email
access_token: requestBody.access_token
phone: requestBody.phone
method: generated
generated: '2026-10-01'
- target: $.paths['/api/auth/users/connect_with_apple'].post
update:
x-apievangelist-phrasing:
intent: Sign a guest in with Apple
effect: write
questions:
- Can guests use Sign in with Apple on the web ordering site?
- Why does Sign in with Apple need a redirect URI?
instructions:
- text: Sign in the guest with Apple using details {user}.
slots:
user: requestBody.user
- text: Complete Apple sign-in for {user} with redirect URI {redirect_uri}.
slots:
user: requestBody.user
redirect_uri: requestBody.redirect_uri
method: generated
generated: '2026-10-01'
- target: $.paths['/api/auth/users/connect_with_google'].post
update:
x-apievangelist-phrasing:
intent: Sign a guest in with Google
effect: write
questions:
- How do I let guests log in with their Google account on the web?
- What has to be configured before Google sign-in works?
instructions:
- text: Log in the guest with Google ID token {google_id_token}.
slots:
google_id_token: requestBody.google_id_token
- text: Sign up {first_name} {last_name} with Google token {google_id_token}.
slots:
first_name: requestBody.first_name
last_name: requestBody.last_name
google_id_token: requestBody.google_id_token
method: generated
generated: '2026-10-01'