Base URL
/apiAuth
Bearer JWT (
Authorization header)Format
application/jsonRate limit
120 req / min (login 10/min)
Endpoints
36+ across 8 groups
Multi-tenant
Per-store, JWT-scoped
All /api routes require a Bearer token except /api/auth/* and /api/health. Obtain a token via POST /api/auth/login, then send Authorization: Bearer <token>.
Endpoint reference
Authentication
POST
/api/auth/register
Create a store (tenant) + owner account
POST
/api/auth/login
Sign in β JWT access token
GET
/api/auth/me
Current authenticated user
POST
/api/auth/change-password
Change your password
POST
/api/auth/forgot-password
Request a reset link (email)
POST
/api/auth/reset-password
Set a new password from a token
Catalog
GET
/api/products
List products (stock, expiry, batches)
POST
/api/products
Create a product
POST
/api/products/import
Bulk import products
GET
/api/batches
List batches (expiry / MRP / qty)
POST
/api/batches/:id/adjust
Stock movement (ledger-backed)
Partners
GET
/api/suppliers
List suppliers
POST
/api/suppliers/import
Bulk import suppliers
GET
/api/customers
List customers
GET
/api/stores/current
Current store profile
Purchasing
POST
/api/purchases
Record inward stock (batches + ledger)
POST
/api/purchases/scan
AI bill scan β purchase draft
GET
/api/purchase-orders/suggestions
Auto-reorder suggestions
PATCH
/api/purchase-orders/:id/status
Advance PO status
Sales
GET
/api/sales/catalog
Sellable products (price + stock)
POST
/api/sales
Create a sale (FEFO + GST)
POST
/api/sales/scan-medicine
AI medicine recognition
POST
/api/sales/:id/void
Void a sale (restock)
POST
/api/sale-returns
Credit note / return
Accounts & GST
GET
/api/receivables
Outstanding customer credit
GET
/api/payables
Outstanding supplier dues
GET
/api/gst/gstr1
GSTR-1 (B2B / B2C / CDNR / HSN)
GET
/api/gst/gstr3b
GSTR-3B summary
Insights
GET
/api/reports/dashboard
KPIs + 7-day sales trend
GET
/api/reports/summary
Sales, GST rate-wise, top products
GET
/api/reports/alerts
Low-stock / expiring / expired
GET
/api/reports/h1-register
Schedule H1 register
Sync & Admin
POST
/api/sync/pull
Pull deltas since a cursor (offline-first)
POST
/api/sync/push
Replay queued offline writes
GET
/api/users
List staff (OWNER)
GET
/api/health
Liveness + DB probe