Technical Documentation
Authentication and permissions
Session, owner, and staff.
The API requires a valid session. The owner sees and changes the whole business, including fiscal setup and the plan. Staff run the floor and do not receive the fiscal snapshot or charge the plan.
Invites bind an account to an employee row. Revoking access does not delete payroll.
Payment and e-CF secrets do not leave for the client.