Talstok
Try it free

A POS API for your products, stock and orders

Most of what a shop does in Talstok can also be done through the API: 128 operations on products, stock, orders, customers and settings. Selling at the till, suppliers and purchase orders, staff and payment settings stay in the dashboard. AI assistants connect over MCP with the same key.

{"mcpServers": {"my-shop": { "type": "http", "url": "https://api.talstok.com/mcp", "headers": {"Authorization": "Bearer your API key"}}}}
An MCP client’s settings for one shop: the address and the shop’s key.

Three ways in

The REST API and the MCP server take a key, and the key’s role decides what they may do. The catalogue is public, for a shop’s own website.

REST API

128 operations, described in an OpenAPI 3.1 document. Lists page with a cursor, and errors come as problem+json.

GET https://api.talstok.com/api/v1/products?limit=50 Authorization: Bearer your API key 200 OK {"data": [ {"id": "prd_…", "handle": "clothbound-notebook", "name": "Clothbound Notebook", "status": "active", …}], "next": "…"}

MCP server

131 tools for AI assistants, with the key’s permissions. It speaks protocol 2026-07-28, and 2025-11-25, 2025-06-18 and 2025-03-26 for older clients.

POST https://api.talstok.com/mcp

Public catalogue

Products, collections, menus, prices, whether each can be ordered (yes or no, never a count), services, buy prices and the shop’s details, read with no key.

GET your shop's address/_talstok/v1/products

Connect an AI assistant

Any MCP client that can send a key in a header connects to one address.

  1. Make a key

    The shop owner makes one in Settings, under Apps and API keys, and gives it a role: manager, packer or viewer. It is shown once.

  2. Add the server

    Point the assistant at https://api.talstok.com/mcp, as in the settings at the top of this page, and send the key as a Bearer token.

  3. Try a change first

    Every tool that changes something accepts dry_run, which checks the change without making it.

  4. Let it work

    The assistant reads products and orders, records counts and the rest, within the key’s role.

What to know before you build

  • Keys by role

    Each key belongs to one shop and holds one role: manager, packer or viewer. No key can act as the owner.

  • Safe retries

    Every POST must carry an Idempotency-Key. A retry of the same request with the same key is told what the first one did (its status and the id it made) instead of acting twice.

  • Refusals you can act on

    An error names a stable code and the shop’s rule that refused the request, so your code can change the plan instead of retrying.

  • Paging

    Lists page with a cursor, up to 200 rows at a time.

  • The site guide

    How a website turns a shop into menus and pages, in markdown, with no key: the site guide.

  • The contract

    Every path, field and role in one OpenAPI document, read with any API key: openapi.json.

Questions from developers

What is a POS API?

An API for a point-of-sale system: a way for other software to read and change what the till sells from. Talstok’s covers products, stock, orders, customers and settings, and a sale made at the till reads as an order. Ringing up a sale through the API is not built.

Does Talstok have an MCP server?

Yes. Talstok’s MCP endpoint lets an AI assistant work on a shop with the same permissions as an API key: read products and orders, record stock counts, and the other operations the API offers. It has 131 tools.

Do I need a developer to use it?

No. Everything the API does can be done in the dashboard. The API is there for shops and agencies who want their own website, their own tools or an AI assistant on top.

Is there a test environment?

Yes. Build against a test shop at https://api-test.talstok.com with that shop’s key, where no money moves. Then point the same code at https://api.talstok.com with a key from the live shop.

How is each shop’s data kept apart?

Each shop’s records live in a database of their own, and every row is checked against the shop it belongs to. A key names one shop, so a request has no way to reach another.

When is an online card order marked paid?

Only when Stripe sends a signed message for that shop. A request from a browser, or from an API key, cannot mark one paid. A sale at the till is marked paid by the signed-in person who takes the money.

Are orders ever deleted?

No. Orders are never deleted and prices are kept as a history, so the API can always say what an order cost on the day.

Build on a test shop

A test shop is free, and no money moves in it. Build your tools against its API at https://api-test.talstok.com, then point the same code at https://api.talstok.com with a key from the live shop. A website built on the public catalogue reads the test shop’s own address, then the live shop’s.