Boring Order TrackerIntegrations · API documentation

Operator API · v1

Consent-bound integration, documented end to end.

Use the machine contract, fixed privacy allowlist and operational guides below. API access requires an environment-specific BOT client certificate; the sandbox contains synthetic data only.

AI implementation promptsCopy safe prompts for your integration backend Operator guideRead the canonical guide Sandbox, review, and productionRead the canonical guide Field catalogue and privacy allowlistRead the canonical guide Consent and revocationRead the canonical guide mTLS certificatesRead the canonical guide Webhook setup and operationsRead the canonical guide Versioning and deprecationRead the canonical guide

From idea to production

One visible path, with an explicit final activation.

  1. Register securely.Verify your email, create a passkey, and store the one-time recovery codes.
  2. Accept the current terms.The standard API license is non-commercial. Ads and every other monetization require a separate written agreement; mixed-source output needs item-level BOT attribution.
  3. Describe the integration.Add purpose, public policies, logo, linking URL, scopes, and the required BOT credit.
  4. Build in the sandbox.Use an environment-specific certificate and only synthetic orders, histories, revocations, vehicles, and statistics.
  5. Submit for review.BOT reviews the exact profile and scopes. Material changes create a new review version.
  6. Activate deliberately.After approval, the owner uses the prominent production activation button; approval alone never releases data.
  7. Operate and delete safely.Poll with cursors and ETags, process tombstones immediately, and acknowledge deletion.

Reference implementations

Production access requires manual BOT approval and a separate owner activation. A sandbox certificate can never access production data.