Issue a tokenOwner or admin opens Settings → API, or POST /api/v1/developer/tokens.
Copy it onceBookey stores a hash. Paste bey_… into the POS vault immediately.
Call JSONSend Authorization: Bearer $BOOKEY_TOKEN. Cookie sessions still need CSRF; Bearer does not.
Authentication
Send Authorization: Bearer <token> on every JSON call. A user session from /api/v1/auth/login works for people. Unattended POS and warehouse clients must use a Bookey API token that starts with bey_. Cookie sessions still need X-CSRF-Token; Bearer skips CSRF. API tokens work only on /api/v1/… — they cannot open Settings or mint other tokens.
Kind
Header
Use
User session
Authorization: Bearer
People. From /api/v1/auth/login.
API token
Authorization: Bearer bey_…
Unattended POS and warehouse. JSON /api/v1 only.
Issuance
Owner or admin issues a token from Settings → API or POST /api/v1/developer/tokens with a name, scopes, and expiry (30 / 90 / 365 days). Bookey shows the secret once. Copy it into the POS or vault immediately. At most 20 active tokens per workspace.
Roles and scopes
People keep Bookey roles (owner, admin, accountant, member). Tokens do not inherit a human role. Each token has scopes only — sales.read / sales.write / inventory.read / inventory.write / receipts.read / receipts.ingest / banking.read / banking.write. Write or ingest implies the matching read. A stolen sales or ingest token cannot open QuickBooks, billing, Team, or approve receipts.
Scope
Can
sales.read
List tickets and hourly sales. Does not post tickets or sync Clover.
sales.write
Create sales tickets. Includes sales.read. Never syncs Clover or loads sample data.
inventory.read
Read stock, locations, and movement. Does not receive, transfer, or waste.
inventory.write
Create items and post receive / transfer / waste. Includes inventory.read.
receipts.read
List and fetch expense receipts and images. Does not upload or approve.
receipts.ingest
Upload JPEG / PNG / PDF and poll the OCR job. Includes receipts.read. Never approve, reject, or post to QuickBooks.
banking.read
List bac_ accounts and btx_ feed transactions. Not the QBO ledger.
banking.write
Register accounts, ingest feed lines, match or ignore. Includes banking.read. Unchecked by default. Never a QBO Banking Match write.
Revoke
Revoke from Settings → API or POST /api/v1/developer/tokens/{id}/revoke. The secret stops working on the next request. Revoke immediately if a device is lost or a contractor leaves. The row is archived and leaves Settings → API. Bookey never shows the secret again.
Renew
Renew rotates the secret in place (POST /api/v1/developer/tokens/{id}/renew). The old secret dies immediately. The same token id and scopes stay. Expiry restarts from now using 90 days unless you pass another allowed value. Update the POS before you renew, then paste the new secret.
Expiry
Every token expires. Allowed lifetimes are 30, 90, or 365 days — there is no forever token. Expired secrets return 401. Renew before the date, or issue a replacement and revoke the old one.
Developer
GET/api/v1/developersession · owner/admin
Specification plus the token list (prefix only).
Accepts No body. Session Bearer only — API tokens cannot mint tokens.
Revoke immediately. The secret dies; the row is archived and leaves the Tokens list.
Accepts path id. No body. Session Bearer only.
Receipts
POST/api/v1/receipts/uploadreceipts.ingest
Store the image, start OCR, land in pending_review. Returns a job. Poll GET /api/v1/jobs/{id}. SHA256 duplicate is not a new receipt. Not JSON. Does not approve or post to QBO.
Accepts multipart field file — JPEG, PNG, or PDF. One file per request.