User model
The User resource represents people and operational roles within an Ordering.co project, including administrators, business managers, customers, drivers, waiters, professionals, and call-center agents.
API routes use the shared base https://api.ordering.co/{version}/{lang}/{project}. Replace each variable with values authorized for your project.
Core operations
| Action | Method | Resource | Purpose |
|---|---|---|---|
| List users | GET | /users | Return users visible to the authenticated caller. |
| Get a user | GET | /users/{user} | Return one user by numeric ID. |
| Create a user | POST | /users | Create a user under operation-specific rules. |
| Update a user | POST | /users/{user} | Partially update one user. This API uses POST, not PUT or PATCH. |
| Delete a user | DELETE | /users/{user} | Delete one user when the caller and user state permit it. |
Permissions, request fields, relations, responses, and errors can vary by operation.
Sanitized request example
curl --request GET \
--url 'https://api.ordering.co/v400/en/YOUR_PROJECT/users/42' \
--header 'Authorization: Bearer YOUR_ACCESS_TOKEN'
All uppercase values are placeholders. Never put a real token in documentation, a URL, source control, or logs.
Conservative public fields
The public base projection groups commonly available fields as follows. Sparse responses can omit fields, and nullable fields can be null.
| Group | Representative fields |
|---|---|
| Identity | id, name, middle_name, lastname, second_lastname, email, photo, birthdate |
| Contact and address | cellphone, country_phone_code, address, address_notes, zipcode, location |
| Role and status | level, busy, available, enabled, email_verified, phone_verified |
| Timestamps | created_at, updated_at |
The model may contain additional fields, relations, and project extensions. They are not necessarily included in every public response.
User levels
| Level | Meaning |
|---|---|
0 | Administrator |
1 | Legacy role; confirm its project-specific meaning before use |
2 | Business manager |
3 | Customer |
4 | Driver |
5 | Driver manager |
6 | Waiter |
7 | Waiter manager |
8 | Professional |
9 | Call-center agent |
Role creation, visibility, and permitted actions depend on the operation and authenticated caller.
Field behavior
idis the numeric user identifier.country_phone_codeis normalized without plus signs or spaces in relevant flows.locationand other structured fields can vary by operation.created_atandupdated_atare date-time values in the current schema.passwordis not included in the public user response.- Authentication tokens belong to session responses, not the
Userresource.
Where supported, params selects a sparse field projection; id remains included when a valid projection is applied.
For authentication context, see the User authentication guide.