Quick start

Make your first Waffy API call

From an API client to a registered customer in a few minutes, using the sandbox.

1Get an API client

Waffy organizations register in the business portal. Once your organization is set up, create an API client under Settings, API clients. You get a client_id and a client_secret. The secret is shown only once, so copy it right away.

Signed in here with the same account, the dashboard lists your clients.

2Download the Postman collection (optional)

Prefer Postman over curl? On the dashboard, press Environment on your client for a ready-made environment file, and download the collection from the Postman page. You only add your secret and password.

3Get an org token

bash
export ID_BASE_URL=https://id-dev.waffyapp.com
export CLIENT_ID=<your client_id>
export CLIENT_SECRET=<your client_secret>

curl -s -X POST "$ID_BASE_URL/realms/waffy/protocol/openid-connect/token" \
  --data-urlencode "grant_type=client_credentials" \
  --data-urlencode "client_id=$CLIENT_ID" \
  --data-urlencode "client_secret=$CLIENT_SECRET"

Copy the access_token from the response into ORG_TOKEN. More on tokens in Authentication.

4Register or link a customer

bash
export ORG_TOKEN=<the access_token above>

curl -s -X POST "$ID_BASE_URL/realms/waffy/waffy-partner/customers" \
  -H "Authorization: Bearer $ORG_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"phoneNumber":"+9665XXXXXXXX","firstName":"Sara","lastName":"Al-Otaibi"}'
json
{ "waffyUserId": 2264, "userIdentification": 39311497 }

The customer is created, or linked to your organization if they already have a Waffy account. They stay PENDING until they give consent.

Consent comes next

Calls that act for the customer, such as getting a payment ticket, fail with consent_required until consent is established. Add "consentMethod": "sms" to this call to send the consent link, verify an OTP yourself, or let the customer log in at checkout.

What next