Build on LUXPOS
One REST API for the whole register: transactions, products, invoices, customers, and loyalty. Pull your data, sync your catalogue, and automate reporting on top of Luxembourg's cloud POS.
curl https://api.luxpos.lu/api/v1/public/me \
-H "Authorization: Bearer lpk_live_..."
# → the business your key belongs to
{
"data": {
"id": "biz_9f3a…",
"name": "Café de la Gare",
"currency": "EUR",
"locations": 2
}
}Base URL
https://api.luxpos.lu/api/v1All public endpoints live under /public. Authenticate with a Bearer API key on every request.
Access
Create scoped API keys in your LUXPOS dashboard. Keys are default-deny: a key can only do what you explicitly grant it, and only ever for its own business. Never billing, payout, or Stripe data.
Quickstart
From zero to your first response in three steps.
Create a key
In the dashboard, open Settings → API Keys, pick your scopes, and copy the key. You see the full value once.
Authenticate
Send the key as a Bearer token in the Authorization header of every request.
Authorization: Bearer lpk_live_…Call an endpoint
List paginated resources with page and limit. Responses are wrapped in a data envelope.
curl "https://api.luxpos.lu/api/v1\
/public/transactions?limit=20" \
-H "Authorization: Bearer lpk_live_…"What you can build
The public API exposes the parts of the register you own — read most of it, write a conservative, audited slice.
Transactions & Sessions
Pull every POS sale, line item, and cash-drawer session — the raw ledger of the register.
transactions:readProducts & Inventory
Read the catalogue and per-location stock, create products, and post signed stock adjustments.
products:writeInvoices
Fetch issued sales invoices with their line items for accounting and reconciliation.
invoices:readCustomers
Read profiles and visit history, create and link customers without duplicating people.
customers:writeLoyalty
Read loyalty cards and members with their live points and stamp balances.
loyalty:readReports
Aggregated revenue reports and breakdowns, ready to drop into dashboards.
reports:readPredictable responses
Single objects come back under a data key. Lists add a meta object with pagination, so you always know how many pages remain.
{
"data": [
{ "id": "txn_1a2b…", "total": 24.50 },
{ "id": "txn_3c4d…", "total": 9.90 }
],
"meta": {
"total": 128,
"page": 1,
"lastPage": 7
}
}Conventions
JSON everywhere
Requests and responses are JSON. Send an Accept: application/json header.
ISO 8601 timestamps
All dates and times are UTC in ISO 8601, e.g. 2026-07-01T14:32:00Z.
Decimal amounts
Money is a decimal number in the business currency — never cents.
Opaque identifiers
IDs are opaque strings. Store them as-is; do not parse their structure.
Business-scoped
Every key is bound to one business. It can never touch another's data.
Consistent errors
Every error shares one envelope: statusCode, message, error.
Getting Started
API keys, first request, pagination, and error envelopes.
Open →Authentication
Scopes, the security model, and key rotation.
Open →Writing data
Idempotent writes for products, stock, and customers.
Open →Endpoints
Every path, its required scope, and the safe fields it returns.
Open →API Reference
Interactive docs for every endpoint and schema.
Open →