Skip to content

Complete REST API Specifications ​

1. Global Request & Response Specifications ​

  • Base URL: https://[DOMAIN_PRODUKSI]/api (Production) or http://localhost:3000/api (Development).
  • Default Content-Type: application/json.
  • Authentication Header: Authorization: Bearer <JWT_TOKEN>.

Standard Error Response Format ​

json
{
  "success": false,
  "error": "Detailed error message describing failure reason",
  "code": "ERROR_CODE_ENUM"
}

2. Authentication API Module (/api/auth) ​

  • Endpoint: POST /api/auth/login
  • Request Body:
    json
    {
      "whatsappNumber": "628123456789",
      "turnstileToken": "0.xxxxxx"
    }
  • Response (200 OK):
    json
    {
      "success": true,
      "token": "tok_9f8a2b3c4d",
      "magicLink": "https://wa.me/6285100000000?text=VERIFY_tok_9f8a2b3c4d",
      "expiresIn": 90
    }

2.2 Poll Login Status ​

  • Endpoint: GET /api/auth/poll-status?token=tok_9f8a2b3c4d
  • Response (200 OK - When Verified):
    json
    {
      "success": true,
      "status": "VERIFIED",
      "token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",
      "user": {
        "id": "usr_uuid_123",
        "name": "Jane Doe",
        "whatsappNumber": "628123456789",
        "role": "CUSTOMER"
      }
    }

3. Order Management Module (/api/orders) ​

3.1 Create Order ​

  • Endpoint: POST /api/orders
  • Security: Bearer <JWT>
  • Request Body:
    json
    {
      "shippingType": "DELIVERY",
      "shippingAddress": "Jl. Pahlawan No. 45",
      "shippingCity": "Mojokerto",
      "shippingPhone": "628123456789",
      "shippingLat": -7.4726,
      "shippingLng": 112.4385,
      "notes": "Bumbu kacang dipisah",
      "items": [
        {
          "menuId": "menu_satay_ayam_123",
          "quantity": 2,
          "notes": "Pedas sedang"
        }
      ]
    }
  • Response (201 Created):
    json
    {
      "success": true,
      "order": {
        "id": "ord_uuid_9988",
        "orderNumber": "SML-20260928-001",
        "status": "PENDING_PAYMENT",
        "totalPrice": 45000,
        "shippingCost": 5000,
        "qbizPaymentUrl": "https://qbiz.id/pay/inv_12345"
      }
    }

4. Payment & QBiz QRIS Module (/api/payments) ​

4.1 Upload Manual Payment Receipt ​

  • Endpoint: POST /api/payments/upload-proof
  • Headers: Content-Type: multipart/form-data
  • Body: orderId (string), paymentProof (file image), bankInfo (string).
  • Response (200 OK):
    json
    {
      "success": true,
      "message": "Bukti pembayaran berhasil diunggah. Menunggu verifikasi admin."
    }

4.2 QBiz Payment Webhook Callback ​

  • Endpoint: POST /api/payments/qbiz-webhook
  • Headers: x-qbiz-signature: <HMAC_SHA256>
  • Request Body:
    json
    {
      "invoiceId": "inv_12345",
      "merchantId": "mrc_sml_01",
      "amount": 50000,
      "status": "PAID",
      "paidAt": "2026-09-28T09:40:00Z"
    }
  • Response (200 OK): { "success": true }.