# BackResto Partner API

> Read-only HTTP API and hosted MCP server for a restaurant's own HACCP compliance records, kept in BackResto, the compliance app food-service teams fill in during service. Goods-in checks with per-product temperatures and photographs, plus twenty-four further record types: fridge and sensor temperatures, cooling, freezing, reheating, transport, cleaning tasks and their photographic proof, fryer oil checks, cooking temperatures, surface analyses, traceability labels, drive files, and the equipment, areas, suppliers, products and staff behind them.

This documentation is served in 7 locales (de, en, es, fr, it, pt, zh) under a path prefix; French is the default and the slugs are the same in every language, so https://developers.backresto.com/de/docs/collections and https://developers.backresto.com/en/docs/collections are the same page.

## When to use this

Reach for this API when a user asks about a restaurant's food safety records and that restaurant uses BackResto. Good fits:

- Checking compliance: "was every delivery this week checked for temperature?", "did anyone record the walk-in fridge yesterday?", "which cleaning tasks were missed?"
- Pulling evidence for an inspection or an audit: the goods-in photo of a damaged package, the cooling log of a batch, a surface analysis result.
- Feeding another system: a multi-site dashboard, a quality tool or an accounting package that needs deliveries, temperatures or traceability labels.

Use the MCP server when a model answers a person in conversation; use the REST API when code syncs or exports records. Both read the same data with the same key.

Do not use it to create or change records (it never writes), to reach a restaurant that has not granted your key access, or for food safety rules in general: this is one restaurant's own data, not regulation. Without a key, send the user to https://developers.backresto.com/en/docs/access.

## How access works

There is no sign-up. A partner key is issued by hand, scoped to named restaurants and named scopes, and only once those restaurants have agreed to it. A key reaches what it was granted and nothing else, and no request widens that. Ask for one by email or through the form on the access page below.

- Authentication: `Authorization: Bearer brp_<prefix>.<secret>`, on every request.
- Scopes: 26, all ending in `:read`, one per collection: `deliveries:read`, `delivery-pictures:read`, `cooling:read` and so on. No partner scope writes.
- Rate limit: 300 requests per minute per key, shared between HTTP and MCP.
- Errors: RFC 9457 problem documents, never HTML.

## Machine-readable entry points

- [OpenAPI specification](https://api.backresto.com/openapi.json): generated from the running service, so it is authoritative for what is deployed. Load it into a client generator or an LLM tool definition.
- [Hosted MCP server](https://api.backresto.com/mcp): streamable HTTP, authenticated with the same partner key. Five read-only tools: `backresto_list_restaurants`, `backresto_list_collections`, `backresto_list_records`, `backresto_get_record`, `backresto_list_record_assets`.
- [MCP server card](https://api.backresto.com/.well-known/mcp/server-card.json): every tool's name, title and description as JSON, readable without a key, built from the same catalogue the server registers its tools from.
- [API catalog](https://developers.backresto.com/.well-known/api-catalog): RFC 9727 linkset of all of the above.
- [Readiness probe](https://api.backresto.com/health/ready): no authentication.

## Documentation

Every page below is also served as markdown: request it with `Accept: text/markdown`, or add `.md` to a documentation URL. [The whole documentation in one file](https://developers.backresto.com/llms-full.txt) suits a model that wants all of it in context.

- [Introduction](https://developers.backresto.com/en/docs/introduction): What the BackResto Partner API exposes today, what it deliberately does not, and who decides.
- [Getting a key](https://developers.backresto.com/en/docs/access): How to ask for a Partner API key, what to put in the request, and what comes back.
- [Quickstart](https://developers.backresto.com/en/docs/quickstart): From a key to your first records and a delivery photograph in five minutes, with curl.
- [Authentication](https://developers.backresto.com/en/docs/authentication): Partner keys, the twenty-six scopes, what a grant means, and how to rotate without downtime.
- [Errors](https://developers.backresto.com/en/docs/errors): One machine-readable problem document for every failure, and what each type means for your retry logic.
- [Pagination](https://developers.backresto.com/en/docs/pagination): How to walk any collection with an opaque cursor, and how to keep a copy of it up to date.
- [Rate limits](https://developers.backresto.com/en/docs/rate-limits): The per-key budget, the one header that describes it, and how to stay under it.
- [Collections & records](https://developers.backresto.com/en/docs/collections): The twenty-six record collections, the snapshot envelope they share, and how to walk one.
- [Temperatures](https://developers.backresto.com/en/docs/temperatures): Fridge and cooking temperatures, taken by a person or reported by a sensor. Three collections, and what tells them apart.
- [Traceability labels](https://developers.backresto.com/en/docs/traceability-labels): The secondary labels staff print and stick on a container, with the printed file attached and a group id per print run.
- [Deliveries](https://developers.backresto.com/en/docs/deliveries): Goods-in checks and the photographs taken at reception: two collections, every field, and what they mean on the shop floor.
- [Cleaning](https://developers.backresto.com/en/docs/cleaning): The cleaning plan, the tasks actually done and the photographs proving it. Three collections, and what a missing record does not prove.
- [Fryers](https://developers.backresto.com/en/docs/fryers): The fryers and their oil quality checks. Two collections, and why the measured value can be missing while the decision never is.
- [Cooling & food processes](https://developers.backresto.com/en/docs/food-processes): Cooling, freezing, reheating and transport. Four collections recording a temperature transition, and what an unfinished one looks like.
- [Surface analyses](https://developers.backresto.com/en/docs/surface-analyses): Surface swabs. What was tested, whether it passed, and the action plan when it did not.
- [Documents](https://developers.backresto.com/en/docs/drive-files): The restaurant's own document store (certificates, procedures, reports), each record a filed file with its own media type.
- [Catalogue](https://developers.backresto.com/en/docs/catalogue): Suppliers, products and in-house preparations, the reference lists the rest of the record points at.
- [Facilities & people](https://developers.backresto.com/en/docs/facilities): The site, its staff, its zones and its machines. The fixed map every temperature reading hangs off.
- [MCP server](https://developers.backresto.com/en/docs/mcp): Connect Claude, Cursor, Codex or any MCP client to a restaurant's compliance records with one URL and your API key.
- [Support & data completeness](https://developers.backresto.com/en/docs/support): What the current data does and does not cover, how the API is versioned, and how to reach a human.

## What this API does not do

- It never writes. Compliance data is created in the app, by the person accountable for it.
- There are no webhooks: you poll.
- It holds what was captured after a restaurant enabled the feature, and does not backfill. **An empty result is not proof that nothing happened.** Do not present a count from this API as an audit figure.
- Collection records are snapshots of what the API received, marked `stateKind: received-shadow-snapshot`. They diverge from the restaurant's app exactly when a device has not uploaded yet.

## Optional

- [Sitemap](https://developers.backresto.com/sitemap.xml): every documentation URL across the 7 locales
- [auth.md](https://developers.backresto.com/auth.md): how an agent obtains and uses credentials
- [ARD capability manifest](https://developers.backresto.com/.well-known/ai-catalog.json): the MCP server, OpenAPI contract and skills as one catalog
- [About](https://developers.backresto.com/en/about) and [Privacy](https://developers.backresto.com/en/privacy)
- Contact: contact@backresto.com for key requests, scope changes, revocations, and anything the documentation does not answer
