Skip to main content

User model

The User resource represents people and operational roles within an Ordering.co project, including administrators, business managers, customers, drivers, waiters, professionals, and call-center agents.

API routes use the shared base https://api.ordering.co/{version}/{lang}/{project}. Replace each variable with values authorized for your project.

Core operations​

ActionMethodResourcePurpose
List usersGET/usersReturn users visible to the authenticated caller.
Get a userGET/users/{user}Return one user by numeric ID.
Create a userPOST/usersCreate a user under operation-specific rules.
Update a userPOST/users/{user}Partially update one user. This API uses POST, not PUT or PATCH.
Delete a userDELETE/users/{user}Delete one user when the caller and user state permit it.

Permissions, request fields, relations, responses, and errors can vary by operation.

Sanitized request example​

curl --request GET \
--url 'https://api.ordering.co/v400/en/YOUR_PROJECT/users/42' \
--header 'Authorization: Bearer YOUR_ACCESS_TOKEN'

All uppercase values are placeholders. Never put a real token in documentation, a URL, source control, or logs.

Conservative public fields​

The public base projection groups commonly available fields as follows. Sparse responses can omit fields, and nullable fields can be null.

GroupRepresentative fields
Identityid, name, middle_name, lastname, second_lastname, email, photo, birthdate
Contact and addresscellphone, country_phone_code, address, address_notes, zipcode, location
Role and statuslevel, busy, available, enabled, email_verified, phone_verified
Timestampscreated_at, updated_at

The model may contain additional fields, relations, and project extensions. They are not necessarily included in every public response.

User levels​

LevelMeaning
0Administrator
1Legacy role; confirm its project-specific meaning before use
2Business manager
3Customer
4Driver
5Driver manager
6Waiter
7Waiter manager
8Professional
9Call-center agent

Role creation, visibility, and permitted actions depend on the operation and authenticated caller.

Field behavior​

  • id is the numeric user identifier.
  • country_phone_code is normalized without plus signs or spaces in relevant flows.
  • location and other structured fields can vary by operation.
  • created_at and updated_at are date-time values in the current schema.
  • password is not included in the public user response.
  • Authentication tokens belong to session responses, not the User resource.

Where supported, params selects a sparse field projection; id remains included when a valid projection is applied.

For authentication context, see the User authentication guide.