Skip to main content
Draft v0.1 — directional. This contract shows which information the two REKOM endpoints exchange with OnlinePOS. Every field name, header, enum value and JSON structure in it is directional: none has been aligned, OnlinePOS stated on 6 Oct 2026 that POS/mPOS define the basket object, and REKOM will adopt OnlinePOS’s default names and structures rather than require any of these. Request fields keep the Version 1 names wherever they existed. If OnlinePOS already has a field or flow that does the same job, REKOM wants to use that instead; see the banner on the introduction page.

Endpoints

The full schema, with request and response examples, is on the two endpoint pages that follow. The source is api-reference/openapi.yaml in this repository.

Hosts

Both hosts serve TLS 1.2+ only. Secrets differ per environment; a venue mapped to one environment is rejected with 422 venue_not_configured on the other.

Headers (directional names)

Request

Response

Conventions

Errors

Errors are JSON with a stable code:

How the POS treats each response

For POST /v1/onlinepos/basket: For POST /v1/onlinepos/sale:

Test data

On staging, REKOM provides a test member whose loyalty ID yields a deterministic 20 % line discount on every discountable line, plus a loyalty ID that yields unchanged and one that yields member_not_found. Values are shared with the staging secret.