API & MCP

Last updated 20 August 2026

Two ways to connect

OrderRestro exposes two separate integrations, each with its own kind of API key, both managed from Settings > API Keys once you’re signed in:

  • MCP server — connect an AI client (Claude Desktop, or any Model Context Protocol client) using a personal access token. It acts as you, with your exact staff permissions.
  • Integration API — a plain REST API for your own website’s backend to use OrderRestro directly: browse the menu, place orders, and book tables for a location you choose. Not tied to any staff account — you grant it only the permissions it needs.

MCP server

Point your MCP client at https://your-domain/api/v1/mcp with header Authorization: Bearer <key>. It’s a deliberately curated set of tools — nothing destructive (no deletes, no user/role management, no backup restore) is reachable through MCP, and every tool re-checks the same permission the equivalent page in the app would require.

  • list_locations, dashboard_summary — read-only, any staff member
  • list_open_orders, get_order, create_order — requires the Create Orders permission
  • list_reservations, create_reservation, update_reservation_status — requires the Manage Reservations permission

Integration API

Base URL: https://your-domain/api/v1/integrations. This is meant for server-to-server calls — your website’s own backend calling OrderRestro, not embedding the key in browser JavaScript.

GET  /locations                              (scope: locations:read)
GET  /locations/:branchId/menu               (scope: menu:read)
POST /locations/:branchId/orders             (scope: orders:write)
GET  /locations/:branchId/orders/:id         (scope: orders:read)
POST /locations/:branchId/reservations       (scope: reservations:write)
GET  /locations/:branchId/reservations/:id   (scope: reservations:read)

Placing an order:

curl -X POST https://your-domain/api/v1/integrations/locations/<branchId>/orders \
  -H "Authorization: Bearer ordr_ext_..." \
  -H "Content-Type: application/json" \
  -d '{
    "type": "TAKEAWAY",
    "customerName": "Jane Doe",
    "customerPhone": "+15550100",
    "items": [{ "menuItemId": "...", "quantity": 2 }]
  }'

Booking a table:

curl -X POST https://your-domain/api/v1/integrations/locations/<branchId>/reservations \
  -H "Authorization: Bearer ordr_ext_..." \
  -H "Content-Type: application/json" \
  -d '{
    "customerName": "Jane Doe",
    "phone": "+15550100",
    "guestCount": 4,
    "reservedAt": "2026-08-25T19:00:00Z"
  }'

Security model

  • Integration keys carry no staff identity — a leaked key can only do exactly what its scopes and location allow.
  • Personal (MCP) keys inherit your exact role permissions — revoke one immediately if you suspect it leaked, same as a password.
  • Every key is shown in full exactly once, at creation. Only a masked last four characters are ever stored or displayed again.
  • Revoking a key takes effect immediately.

Full reference

For the complete endpoint reference, error codes, and rate limits, see docs/integrations-api.md in the repository.