Register your application
Applications are registered by EatNow. Send us your application name, its logo, the redirect URIs (compared character for character: scheme, host, port, path and query) and the scopes you need. You receive aclient_id and a
client_secret, shown once: keep the secret on your server only.
An application published by EatNow (such as ClubNow) works on every
restaurant. A third-party application also requires the restaurant’s API
option, like a hand-made key.
1. Send the user to the consent page
Generate acode_verifier (43 to 128 characters among A-Z a-z 0-9 - . _ ~)
and a random state, keep both in the user’s session, then redirect the browser
to:
2. Handle the return
EatNow redirects the browser to yourredirect_uri with state and either a
code, or an error:
An unknown or disabled
client_id, or a redirect_uri that is not registered,
is never redirected: the user sees the error on EatNow.
The code is valid 5 minutes and once.
3. Exchange the code for a token
From your server,POST https://app.eat-now.io/api/oauth/token with
application/x-www-form-urlencoded (JSON is also accepted). Authenticate the
client with HTTP Basic (client_id:client_secret, each form-encoded) or
with client_id and client_secret in the body, not both.
Cache-Control: no-store. Store the token server-side,
with the restaurant id.
4. Call the Partner API
WEBHOOKS_WRITE, subscribe an HTTPS URL to events with
POST /api/partner/v1/webhook-endpoints. The signing secret is returned only
in that response. Each event type needs the matching read scope, and contact
details are included in payloads only with RESERVATIONS_READ_SENSITIVE. See
Manage endpoints through the API.
Connection lifecycle
- Reconnection. A new authorization for the same restaurant does not
revoke the previous token: once the new connection is in place, revoke the
previous token with
POST /api/oauth/revoke(below). At most 3 tokens stay active per restaurant and application: issuing a fourth revokes the oldest and deletes the webhook endpoints it created. - Disconnection by the restaurant. Settings › Integrations › Connected apps
lists the connected applications; Disconnect revokes every active token
of the application on that restaurant and deletes their webhook endpoints. Your calls then return
401 INVALID_AUTHENTICATION: ask the user to connect again. - Disconnection by your application.
POST /api/oauth/revoke(RFC 7009) withtokenand the same client authentication as the token endpoint. The answer is200even for an unknown or already revoked token.