Danvas
Danvas
DashboardSupportWelcome

👤 USER DOCS

User Guides

Getting Started

Getting StartedDashboard & OnboardingApp Settings

Tutorials

Tutorial: Setting Up Shift Tasks & ClosersTutorial: Managing Incidents in the InboxTutorial: Tracking Compliance & Sync StatusTutorial: Operational Workflows with the AI AssistantTutorial: Building & Deploying Custom Checklists

Daily Operations (Staff)

Shift Workspace & TasksService Day SetupDaily Line-UpStaff Service Day ReportsForms

Communication & Chat

Messages & AnnouncementsUnified Operations InboxAI Assistant

Manager & Admin Guides

Daily Line-Up SetupStaff SchedulingManaging LocationsNPS and Guest FeedbackCouponsContacts and Guest HistoryManager CloseoutsDaily Line-Up & ComplianceAnalyticsIncident ReportingWhistleblower Concerns & FeedbackAdmin Tools

⚙️ DEVELOPER DOCS

Getting Started

Getting StartedDevelopmentDeployment Guide

Architecture

Architecture OverviewExplanation: AI Integration & Tenant SecurityExplanation: Dynamic Forms Engine DesignExplanation: Compliance Ledger DesignExplanation: Live Sync & Data FreshnessData FlowArchitecture Decision Records

Core Domain

Core DomainDatabase ReferenceLocations DomainAuth & RBACScheduling DomainReports DomainIncidents DomainUnified Operations InboxLive Sync Data FreshnessToast Sync PipelineNotifications DomainCoupons and Guest NPSAudit Log & Compliance ArchitectureDesign Audit FindingsAI Chat IntegrationAnalytics & Tips Integration

Frontend

Frontend ArchitectureFormsLoading SkeletonsComponentsPWA & Offline ShellScreenshots

API Reference

API Reference

Endpoints

POS Sales APIOptimization Data APISchedule Shifts APIEmployee Export APIReports APIIncidents APIAI Chat APIPush Notifications APIWebhooks APICron API

Contributing

ContributingCode Examples

Security

Security & Compliance

Release Notes

What's New

API Reference

Programmatic access to the Danvas platform

Overview

The Danvas API provides programmatic access to the restaurant operations platform. All endpoints are REST-based and return JSON responses. The API is primarily consumed by the internal @repo/telemetry and @repo/ai packages, but is also available for external integrations.

Live Service Status

API Gateway (apps/api)…Checking
Main Dashboard (apps/app)…Checking
Guest Experience (apps/guest)…Checking
Slack Operations (apps/slack-bot)…Checking
Analytics MCP (apps/analytics-mcp)…Checking

Base URL

EnvironmentURL
Productionhttps://danvas.hartalliance.com
Developmenthttp://localhost:4000

Authentication

Danvas uses multiple authentication methods depending on the endpoint:

MethodUse Case
Bearer TokenUser authentication via Clerk JWT
Session CookieBrowser session authentication
Webhook SignatureVerification for Clerk and Svix webhooks
Bearer (Cron Secret)Authentication for scheduled cron jobs

Rate Limiting

The API implements rate limiting via Upstash Redis.

  • Chat Endpoint: Limited to 20 requests per minute per user.
  • Push Notifications: Rate-limited per user (5/min for sending, 10/min for subscriptions).
  • Cron Jobs: Restricted to internal infrastructure and verified secrets.

API Categories

AI Chat

Streaming SSE responses for conversational data queries.

Push Notifications

Management of Web Push subscriptions and delivery.

Webhooks

Handlers for external lifecycle events. Idempotency is enforced via @repo/idempotency.

Cron Jobs

Internal endpoints for scheduled operational tasks.

Error Handling

All API errors follow a consistent format:

{
  "error": "Error message description",
  "code": "MACHINE_READABLE_CODE"
}
Status CodeMeaning
200Success
400Bad request — invalid parameters or payload
401Unauthorized — missing or invalid authentication
403Forbidden — insufficient permissions for this resource
429Too many requests — rate limit exceeded
500Internal server error

OpenAPI Specification

The curated API schema is available as an OpenAPI 3.0 specification in content/docs/api-reference/openapi.json. It covers stable documented integration endpoints; internal cron and application routes that are not intended for external callers are omitted. This file is manually maintained and must change with the documented endpoint contracts. The interactive specification follows:

Related

Auth & RBAC

Database Schema

Frontend Architecture

Screenshots

Adding UI screenshots to documentation

POS Sales API

Real-time sales data from Toast POS

On this page

OverviewBase URLAuthenticationRate LimitingAPI CategoriesError HandlingOpenAPI SpecificationRelated