A customer answers a sent form (public, unauthenticated)
/api/form-sends/{token}The guest side of the standalone Forms feature. The token is the entire credential, same posture the manage-token routes take (0018): every write is scoped to the company_id resolved FROM the token, never from the request body. Replace semantics: a customer reopening the link edits their answers rather than stacking a second submission. No GET: src/app/forms/[token]/page.tsx loads the send directly on the server with its own service-role read.
Path Parameters
book_form_sends.token.
uuidRequest Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
curl -X PUT "https://example.com/api/form-sends/497f6eca-6276-4993-bfeb-53cbbbba6f08" \ -H "Content-Type: application/json" \ -d '{ "answers": {} }'{ "ok": true}Send a catalog form to a customer POST
Snapshots title/description/fields off the CURRENT book_forms row onto a new book_form_sends row, mints its token, and best-effort emails the customer a link (notifyFormSent): the row exists and the link is returned either way, so a failed send never loses the credential. Service-role, not the RLS-scoped client: book_form_sends has no INSERT grant for `authenticated` at all. Same permission bar as the catalog routes above (admin, `intake_forms`): sending an existing form is still deciding what a business asks a customer.
Record a sale POST
The shared "Add item" cart BeNotely uses for both a standalone walk-in "New sale" (no `bookingTable`/`bookingId`) and a booking's close-out (both set, as a pair: CloseOutDialog's own POST). No `hasPermission` gate: recording a sale is ordinary front-of-house work, the same posture PATCH /api/appointments/{id} and /api/reservations/{id} already take for closing out a booking. Calls `book_record_sale()` (service_role), which atomically inserts the sale and its line items and, for each product line, decrements stock via `book_product_stock_adjust()`: either the whole sale and every stock delta commit, or none do.