Products
Generated from Malapos's own code: every route in this area, what it takes and how to call it.
List products
GET /api/v1/products
Query parameters
| Name |
Type |
Required |
Notes |
active |
any |
no |
|
categoryId |
any |
no |
|
q |
any |
no |
|
Example
curl -X GET "https://malapos.com/api/v1/products" \
-H "Authorization: Bearer sk_live_…"
Create a product
POST /api/v1/products
Body
| Field |
Type |
Required |
Notes |
name |
string |
yes |
min length 1; max length 160 |
description |
string |
no |
max length 2000; may be null |
categoryId |
string |
no |
may be null |
kind |
GOODS or SERVICE |
no |
default "GOODS" |
trackStock |
boolean |
no |
|
requiresBatch |
boolean |
no |
default false |
imageUrl |
string |
no |
max length 600; may be null |
isActive |
boolean |
no |
default true |
variants |
array of object |
yes |
|
Example
curl -X POST "https://malapos.com/api/v1/products" \
-H "Authorization: Bearer sk_live_…" \
-H "Content-Type: application/json" \
-d '{"name":"…","description":"…","categoryId":"…","kind":"GOODS","trackStock":false,"requiresBatch":false,"imageUrl":"…","isActive":true,"variants":[]}'
Delete a product
DELETE /api/v1/products/{id}
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
Example
curl -X DELETE "https://malapos.com/api/v1/products/:id" \
-H "Authorization: Bearer sk_live_…"
Get a product
GET /api/v1/products/{id}
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
Example
curl -X GET "https://malapos.com/api/v1/products/:id" \
-H "Authorization: Bearer sk_live_…"
Update a product
PATCH /api/v1/products/{id}
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
Body
| Field |
Type |
Required |
Notes |
name |
string |
no |
min length 1; max length 160 |
description |
string |
no |
max length 2000; may be null |
categoryId |
string |
no |
may be null |
kind |
GOODS or SERVICE |
no |
|
trackStock |
boolean |
no |
|
requiresBatch |
boolean |
no |
|
imageUrl |
string |
no |
max length 600; may be null |
isActive |
boolean |
no |
|
variants |
array of object |
no |
|
Example
curl -X PATCH "https://malapos.com/api/v1/products/:id" \
-H "Authorization: Bearer sk_live_…" \
-H "Content-Type: application/json" \
-d '{"name":"…","description":"…","categoryId":"…","kind":"GOODS","trackStock":false,"requiresBatch":false,"imageUrl":"…","isActive":false,"variants":[]}'
Variants a product
POST /api/v1/products/{id}/variants
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
Body
| Field |
Type |
Required |
Notes |
name |
string |
no |
default "Default"; min length 1; max length 80 |
sku |
string |
no |
max length 64; may be null |
barcode |
string |
no |
max length 64; may be null |
price |
integer |
yes |
min 0; max 1000000000 |
cost |
integer |
no |
default 0; min 0; max 1000000000 |
sortOrder |
integer |
no |
default 0; min 0 |
Example
curl -X POST "https://malapos.com/api/v1/products/:id/variants" \
-H "Authorization: Bearer sk_live_…" \
-H "Content-Type: application/json" \
-d '{"name":"Default","sku":"…","barcode":"…","price":0,"cost":0,"sortOrder":0}'
Delete a variant
DELETE /api/v1/products/{id}/variants/{vid}
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
vid |
string |
yes |
|
Example
curl -X DELETE "https://malapos.com/api/v1/products/:id/variants/:vid" \
-H "Authorization: Bearer sk_live_…"
Update a variant
PATCH /api/v1/products/{id}/variants/{vid}
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
vid |
string |
yes |
|
Body
| Field |
Type |
Required |
Notes |
name |
string |
no |
default "Default"; min length 1; max length 80 |
sku |
string |
no |
max length 64; may be null |
barcode |
string |
no |
max length 64; may be null |
price |
integer |
no |
min 0; max 1000000000 |
cost |
integer |
no |
default 0; min 0; max 1000000000 |
sortOrder |
integer |
no |
default 0; min 0 |
Example
curl -X PATCH "https://malapos.com/api/v1/products/:id/variants/:vid" \
-H "Authorization: Bearer sk_live_…" \
-H "Content-Type: application/json" \
-d '{"name":"Default","sku":"…","barcode":"…","price":0,"cost":0,"sortOrder":0}'
List recipe
GET /api/v1/products/{id}/variants/{vid}/recipe
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
vid |
string |
yes |
|
Example
curl -X GET "https://malapos.com/api/v1/products/:id/variants/:vid/recipe" \
-H "Authorization: Bearer sk_live_…"
Replace-all the components of a variant + set its isComposite flag.
PUT /api/v1/products/{id}/variants/{vid}/recipe
Path parameters
| Name |
Type |
Required |
Notes |
id |
string |
yes |
|
vid |
string |
yes |
|
Body
| Field |
Type |
Required |
Notes |
isComposite |
boolean |
yes |
|
components |
array of object |
no |
default [] |
Example
curl -X PUT "https://malapos.com/api/v1/products/:id/variants/:vid/recipe" \
-H "Authorization: Bearer sk_live_…" \
-H "Content-Type: application/json" \
-d '{"isComposite":false,"components":[]}'
Create a bulk category
POST /api/v1/products/bulk-category
Body
| Field |
Type |
Required |
Notes |
productIds |
array of string |
yes |
|
categoryId |
string |
yes |
min length 1; may be null |
Example
curl -X POST "https://malapos.com/api/v1/products/bulk-category" \
-H "Authorization: Bearer sk_live_…" \
-H "Content-Type: application/json" \
-d '{"productIds":[],"categoryId":"…"}'
Sell-screen lookup: exact barcode match first, else fuzzy name/sku.
GET /api/v1/products/lookup
Query parameters
| Name |
Type |
Required |
Notes |
barcode |
any |
no |
|
q |
any |
no |
|
Example
curl -X GET "https://malapos.com/api/v1/products/lookup" \
-H "Authorization: Bearer sk_live_…"