API & MCP
Last updated 20 August 2026
Two ways to connect
OrderRestro exposes two separate integrations, each with its own kind of API key, both managed from Settings > API Keys once you’re signed in:
- MCP server — connect an AI client (Claude Desktop, or any Model Context Protocol client) using a personal access token. It acts as you, with your exact staff permissions.
- Integration API — a plain REST API for your own website’s backend to use OrderRestro directly: browse the menu, place orders, and book tables for a location you choose. Not tied to any staff account — you grant it only the permissions it needs.
MCP server
Point your MCP client at https://your-domain/api/v1/mcp with header Authorization: Bearer <key>. It’s a deliberately curated set of tools — nothing destructive (no deletes, no user/role management, no backup restore) is reachable through MCP, and every tool re-checks the same permission the equivalent page in the app would require.
- list_locations, dashboard_summary — read-only, any staff member
- list_open_orders, get_order, create_order — requires the Create Orders permission
- list_reservations, create_reservation, update_reservation_status — requires the Manage Reservations permission
Integration API
Base URL: https://your-domain/api/v1/integrations. This is meant for server-to-server calls — your website’s own backend calling OrderRestro, not embedding the key in browser JavaScript.
GET /locations (scope: locations:read)
GET /locations/:branchId/menu (scope: menu:read)
POST /locations/:branchId/orders (scope: orders:write)
GET /locations/:branchId/orders/:id (scope: orders:read)
POST /locations/:branchId/reservations (scope: reservations:write)
GET /locations/:branchId/reservations/:id (scope: reservations:read)Placing an order:
curl -X POST https://your-domain/api/v1/integrations/locations/<branchId>/orders \
-H "Authorization: Bearer ordr_ext_..." \
-H "Content-Type: application/json" \
-d '{
"type": "TAKEAWAY",
"customerName": "Jane Doe",
"customerPhone": "+15550100",
"items": [{ "menuItemId": "...", "quantity": 2 }]
}'Booking a table:
curl -X POST https://your-domain/api/v1/integrations/locations/<branchId>/reservations \
-H "Authorization: Bearer ordr_ext_..." \
-H "Content-Type: application/json" \
-d '{
"customerName": "Jane Doe",
"phone": "+15550100",
"guestCount": 4,
"reservedAt": "2026-08-25T19:00:00Z"
}'Security model
- Integration keys carry no staff identity — a leaked key can only do exactly what its scopes and location allow.
- Personal (MCP) keys inherit your exact role permissions — revoke one immediately if you suspect it leaked, same as a password.
- Every key is shown in full exactly once, at creation. Only a masked last four characters are ever stored or displayed again.
- Revoking a key takes effect immediately.
Full reference
For the complete endpoint reference, error codes, and rate limits, see docs/integrations-api.md in the repository.