Integration partners
Connect the system you already sell
You built a POS, an ERP, a payment product, a delivery network, a kitchen display. Your customers are hospitality operators, and the ones running SIDES are reachable through a single integration rather than one project each.
The fit
One integration instead of one per customer
The usual shape of this work is a project per operator: a slightly different export, a slightly different field mapping, a slightly different person to call when it breaks. It scales badly and it ages worse.
Building against SIDES replaces that with a single integration against a single versioned contract: one field mapping, one place it breaks, one place it gets fixed — instead of one of each per customer. When the platform grows a field, your integration keeps working. That is a rule, not a hope.
What you build against
Your slice of the contract
None of this is negotiated per partner. It is the same surface for our own portal, for SIDES-internal tooling, and for you.
- OAuth 2.0, scoped
-
Your integration authenticates as a machine client and receives a short-lived
access token. Scopes are hierarchical and nested by domain; a scope without
:writeis read-only. - Granted, not requested
- The granted scope is the intersection of what your client holds and what you asked for. Asking for more is not an error — the response tells you what you got, so read it.
- RFC 7807 errors
-
Every failure is a Problem Details document with a stable
code, a request id, and a documentation link. Branch on the code, never on the title. - Rate limits you can plan against
-
X-RateLimit-*headers report the daily budget on every counted response. A429carriesRetry-After. A missing header means "not counted" — never "nothing left". - A published changelog
- Every API change is announced before you meet it in production. Additions are free; removals need a new major version and at least six months of notice. The changelog itself is still being built — the commitment is not.
- Documentation from the spec
-
The OpenAPI specification is written before the handlers and served at
/api/docs. The service refuses to start if the two disagree.
Getting a token
Your first call
Form-encoded, per RFC 6749. The response says what your client was actually granted.
curl -X POST https://api.sideslabs.com/v1/oauth/token \
-H 'Content-Type: application/x-www-form-urlencoded' \
--data-urlencode 'grant_type=password' \
--data-urlencode "username=$CLIENT_ID" \
--data-urlencode "password=$CLIENT_SECRET"
{ "access_token": "…", "token_type": "Bearer",
"expires_in": 3600, "scope": "marketplace.apps" }
Do I need one client per customer?
No. A machine client is bound to at most one business partner — yours. An operator taking up your app does not become a machine client of ours on your behalf.
Can another partner see my apps or my numbers?
No. Every partner-scoped query is filtered by the business partner derived from the authenticated principal, server-side, on every request. It is not a filter in a screen that a different screen could forget.
What happens when the API changes?
Fields, endpoints and enum values are added without notice and your client must tolerate ones it does not know. Anything that could break you — a removal, a rename, a type or semantic change — is a new major version, announced in the changelog with at least six months of notice.
How do I know how the integration is doing?
Usage statistics, ratings and reviews for your listing come back to you in the partner area of the portal. They will come from the SIDES platform rather than being self-reported; which API supplies them is still being decided.
What exists today
The platform is being built in the open, and this page describes the platform being built. Today the API authenticates OAuth machine clients and reports the identity, scopes and rate limit of the calling principal. Partner registration and sign-in, the marketplace catalogue, the API changelog, the developer resources, usage statistics and the tier pages come in the phases after it — every commitment above is a commitment, not a screenshot.
Put your product where the operators already are
Registration creates your business partner, your first administrator and your tier. Approval to publish is a separate, recorded step.

