{"product":"Flip Agent API","auth":{"header":"X-API-Key","description":"Authenticate every request with an X-API-Key header. Issue/rotate/revoke keys via the api-keys endpoints (needs the api-keys:write scope)."},"scopes":{"resources":["orders","catalog","menus","inventory","kds","analytics","crm","loyalty","reservations","reviews","fiscal","discounts","delivery","supply","finance","network","staff","storefront","webhooks","aggregators","api-keys"],"actions":["read","write"],"catalog":["*","orders:*","orders:read","orders:write","catalog:*","catalog:read","catalog:write","menus:*","menus:read","menus:write","inventory:*","inventory:read","inventory:write","kds:*","kds:read","kds:write","analytics:*","analytics:read","analytics:write","crm:*","crm:read","crm:write","loyalty:*","loyalty:read","loyalty:write","reservations:*","reservations:read","reservations:write","reviews:*","reviews:read","reviews:write","fiscal:*","fiscal:read","fiscal:write","discounts:*","discounts:read","discounts:write","delivery:*","delivery:read","delivery:write","supply:*","supply:read","supply:write","finance:*","finance:read","finance:write","network:*","network:read","network:write","staff:*","staff:read","staff:write","storefront:*","storefront:read","storefront:write","webhooks:*","webhooks:read","webhooks:write","aggregators:*","aggregators:read","aggregators:write","api-keys:*","api-keys:read","api-keys:write"],"rule":"A request needs <resource>:<action> for the endpoint. A key grants it via the global \"*\", a per-resource \"<resource>:*\", or the exact \"<resource>:<action>\". Deny-by-default: an endpoint outside this scoped surface needs \"*\"."},"rate_limit":{"default_per_min":600,"headers":["X-RateLimit-Limit","X-RateLimit-Remaining","X-RateLimit-Reset","Retry-After"],"on_exceed":"HTTP 429 TOO_MANY_REQUESTS with Retry-After (seconds)."},"sandbox":{"description":"A sandbox organization holds only throwaway data. A sandbox key is confined to it and can never read or mutate a real organization, so you can exercise the API safely.","org_header_hint":"Use a key issued against the sandbox org; isolation is enforced automatically by tenant scoping."},"links":{"openapi":"/openapi.json","swagger_ui":"/docs","mcp_tools":"/mcp/tools"}}