The whole API, in one page
688 endpoints across fourteen modules. This is the map: what each module is for, how big it is, and where its reference page is. Use it to find the one endpoint you need, then go to that module's page for the paths and payloads.
The shape of every route
Two shapes, and knowing which one you are looking at tells you most of what you need:
# Global — one per deployment
/api/v2/{base}/{resource}
# Plugin-scoped — one per installed module instance
/api/v2/{base}/plugins/{pluginInstalledId}/{resource}
Nearly everything outside Core, Authentication and Ace is plugin-scoped, because a deployment can run
two casinos, three POS instances or a dozen camera servers and they each have their own data. The
pluginInstalledId comes from GET /api/v2/portal/installed-plugins — see
Getting Started.
The modules
| Module | Base path | Endpoints | What lives there |
|---|---|---|---|
| Authentication | auth | 5 | Sign in, refresh, switch group, sign out. Start here |
| Core | portal | 117 | Users, permissions, logical groups, system settings, saved queries, storage, session history. The platform every module sits on |
| Plugins | plugin-instances | 9 | Instance attributes and configuration for an installed module |
| Aggregates | portal-aggregate | 11 | Grouped totals over any module that supports aggregation — counts and sums without pulling rows |
| Point of Sale | pos | 51 | Transactions, terminals and employees, exception scoring, statistics |
| Casino | casino-connect | 109 | Ratings, bet sessions, TITO, gaming floor, roulette, countdown, player appraisals |
| Baccarat | casino-baccarat | 100 | Shoes, hands, results, table status and the trend-board logs |
| Object Analytics | oa | 140 | Faces, plates, subjects, tags and watch lists, zones, fusion, semantic search. The largest module |
| Cases | incident-tracker | 75 | Cases, activity tracking, people, locations, resolutions, attachments |
| Case media | incident-tracker-media | 2 | Preparing and removing the clips attached to a case |
| Cameras | witness | 30 | Devices, device groups, export servers, per-user deny lists |
| Camera streaming | witness-stream | 2 | Snapshots from a device |
| Media export | media-export | 5 | Request a video export, poll it, collect it |
| Ace | ai | 31 | The assistant: chat sessions, providers, scope policies, usage and instructions |
One endpoint sits outside the modules: GET /.well-known/econnect/jwks.json, the public keys for
verifying a token's signature. It needs no authentication — that is the point of it.
Finding what you need
| You want to… | Go to |
|---|---|
| Get a token and make your first call | Getting Started |
| Understand login, plugin discovery and permissions | Architecture |
| Push transactions, ratings, tickets or detections in | Pushing Data In |
| Generate a typed client | OpenAPI schema |
| Look up a specific path or payload | The module's reference page, above |
| Know which permission keys a call needs | Permission Keys |
What most modules have in common
Learn these once and they apply across the surface. They are why 688 endpoints are smaller than they look.
| Pattern | Where you will see it |
|---|---|
Saved queries — queries, queries/{id}, queries/count | POS, Casino, Baccarat, Object Analytics, Cases, Core. The same saved-query model the client uses |
Query subscriptions — query-subscriptions | The modules above. How a saved query drives a notification |
Aggregates — aggregate-report, aggregate-submit-query, aggregate-grouping-* | Every data module. Totals and groupings computed server-side |
Job actions — job-actions, job-actions/{id}/execute | Every data module. The scheduled work a module can run |
Logical group filters — logical-group-filters | Every data module. How visibility is scoped to a logical group |
Entities — entities, entities/by-familiar-id | POS, Casino, Baccarat, Cameras. The devices and people a module's data refers to. Read these before you push anything |
Paging — page, recordsPerPage, orderBy on query endpoints | Everywhere a result set can be long |
Where data goes in
Five ingress routes carry third-party data into eConnect. Each has its own page under Pushing Data In:
| Data | Endpoint |
|---|---|
| Casino ratings | POST casino-connect/plugins/{id}/ratings |
| TITO tickets | POST casino-connect/plugins/{id}/tito-tickets · /batch |
| POS transactions | POST pos/plugins/{id}/events · /batch |
| Face detections | POST oa/plugins/{id}/subject-detections |
| Plate reads | POST oa/plugins/{id}/license-plate-detections |
Baccarat, roulette and journal events have their own insert endpoints too — see the Casino and Baccarat reference pages.
Every path, parameter and payload on a reference page comes from the OpenAPI document the server publishes, so it describes the API the server actually serves rather than an API someone remembered. Regenerate the pages against a build and any drift shows up as a diff.