Skip to content

Fundamentals

Getting started

Create an API key, send your first request and read your venue, its menu and its tables in a few minutes.

The Cibusy API lets your venue's own website, app or software work with your Cibusy account. It reads your venue, menu and tables, prices a basket, sends an order straight to your kitchen and follows it until the venue closes the bill.

In this guide you will create an API key, send your first request and read your menu. None of the requests here places an order.

Warning: The Cibusy API has no separate test environment. An order placed with a real key is a real order at your venue, and its ticket prints in the kitchen. Try everything about orders by pricing the basket first.

Before you start#

  • A Cibusy venue account. The venue's owner creates keys, signed in to the panel as the venue itself; staff accounts cannot.
  • An active subscription, for orders and reservations. Reading the menu and the tables does not need one: a key of a venue whose subscription has lapsed keeps reading.
  • An HTTP client. The examples in this guide use curl; the API reference also shows every request in Node.js, PHP, Python and C#.

1. Create an API key#

  1. Sign in to the Cibusy panel with your venue account and open the API Keys page.
  2. Select New Key and name the key after the website or software that will use it, such as "Website". The name also appears on the orders the key sends.
  3. For this guide, Can read the menu is enough; every key has it. When you are ready to send orders or take reservations, you also turn on Can send orders or Can take reservations.
  4. Select Create Key and copy the key that appears.

A key starts with cbk_ and is shown only once. Cibusy does not keep the key itself: if you lose it, you revoke it and create a new one.

The key is your venue's credential. Keep it in your server's configuration, never in a web page, a mobile app or a code repository. Authentication explains why.

2. Send your first request#

Put the key in an environment variable and list the venues it reaches:

Shell
export CIBUSY_API_KEY="cbk_..."

curl https://api.cibusy.com/public/v1/venues \
  -H "X-Api-Key: $CIBUSY_API_KEY"

The list starts with the venue the key was made for. A headquarter's key also lists the headquarter's active branches:

JSON
{
  "success": true,
  "timestamp": "2026-10-01T09:30:00.123Z",
  "traceId": null,
  "data": [
    {
      "id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
      "name": "Moda Köfte",
      "username": "modakofte",
      "type": "Headquarter",
      "parentVenueId": null
    },
    {
      "id": "9b2d4f61-8c3a-4e75-a1d0-6f4b2c8e9d13",
      "name": "Moda Köfte Bostancı",
      "username": "modakoftebostanci",
      "type": "Branch",
      "parentVenueId": "3fa85f64-5717-4562-b3fc-2c963f66afa6"
    }
  ],
  "message": "Operation completed successfully"
}

Every successful answer comes in this envelope, with the result in data. Every call about one venue takes that venue's id in its path.

If you received a 401, the X-Api-Key header is missing or the key is not recognised: check that you copied the whole key and that it has not been revoked.

3. Read your menu#

Ask for the menu with the venue's id. lang chooses the language the menu comes in:

Shell
curl "https://api.cibusy.com/public/v1/venues/3fa85f64-5717-4562-b3fc-2c963f66afa6/menu?lang=en" \
  -H "X-Api-Key: $CIBUSY_API_KEY"

The answer holds the categories and the products in them: each product's portions and prices (VAT included), extras, option groups, removable ingredients, allergens and stock status. Only what the venue shows its guests is on it.

Do not ask for the menu again for every visitor of your website. Reading the menu shows how to keep a copy on your server and keep it current.

4. Get ready for orders#

To send orders, the key needs the Can send orders permission. Turn it on with Edit in the panel; the change applies from the key's next request.

To price a basket without ordering it, call POST /venues/{venueId}/orders/preview. It takes the same body as an order and checks the basket the way an order does; it says what the basket comes to and sends nothing to the kitchen.

curl -X POST "https://api.cibusy.com/public/v1/venues/3fa85f64-5717-4562-b3fc-2c963f66afa6/orders/preview" \
  -H "X-Api-Key: $CIBUSY_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "type": "DineIn",
    "tableId": "2f4e6a8c-0b1d-4c3e-9f5a-7b9d1e3c5a70",
    "note": "Bir misafirin fıstık alerjisi var.",
    "lines": [
      {
        "productId": "5d2c8a41-7b0e-4c36-8f1d-9e4a6b3c2d10",
        "portionId": "a8e1f6c3-2d94-4b70-b5a6-1c7d9e0f3a24",
        "quantity": 2,
        "note": "Köfteler ayrı paketlensin.",
        "extraIds": [
          "f1a2b3c4-d5e6-4f70-8192-a3b4c5d6e7f8",
          "b4c5d6e7-f8a9-4b1a-8c2d-3e4f5a6b7c8d"
        ],
        "removedIngredientIds": [
          "b7c8d9e0-f1a2-4b3c-8d4e-5f6a7b8c9d0e"
        ]
      }
    ]
  }'

The server always does the pricing: a request carries no prices. total in the answer is what the same basket comes to when it is ordered.

Next steps#

  • Authentication: a key's permissions, replacing a key and revoking one.
  • Placing orders: order types, retrying safely and following an order.
  • Taking reservations: a venue's bookable times, sending a booking in, telling the guest and cancelling.
  • Webhooks: signed notifications to your server whenever an order or a reservation changes.
  • Errors and Rate limits: what to read before you go live.
  • API reference: every endpoint's parameters, fields and samples.