Access and API keys
Protect restaurant access and treat API-key presence separately from public API support.
Current status: partial. Settings and API-key routes exist; complete self-service role management and a supported public API contract are not yet documented as released.
Give each person an individual account. Remove access promptly when responsibility changes. Store API keys only in an approved secret manager, scope them narrowly, rotate after suspected exposure, and never paste them into tickets or screenshots.
An API key does not authorize use of private handbook endpoints. Follow only the interfaces explicitly documented under Developers.