Parameters
1 query · JSON body
Query parameters
· 1apiKeystringRequiredYour BizKitHub API key (passed as GET parameter).
Key format: A 32-character string matching: ^(PROD|DEV_|ROOT)[A-Za-z0-9]{28}$
Prefixes: PROD (production key), DEV_ (individual developer), ROOT (system key with no limits). Learn more
PRODPGrFxpGEtrOZfuWhnoJohUYBXuOERequest body
application/jsonorganisationNamestringRequiredDisplay name of the new organisation the vendor is spawning. Must be unique across the platform; if the exact name is already taken, a numeric suffix is appended automatically (e.g. "Acme" → "Acme 2").
Acme ShopemailstringRequiredContact email address.
The system validates the input as a standard email address and automatically applies normalization and canonicalization.
All API responses return the normalized form, and each email address is unique per organisation within the system.
Phone-only contacts: Since 2026-06-10 a contact may exist without an e-mail when it was registered only by phone (e.g. imports of phone-only records). Responses that expose such contacts use API_EMAIL_NULLABLE instead, where this field can be null. Endpoints that accept e-mail as input still require a valid value here — phone-only creation goes through admin-only import / BFF flows.
Vendor spawn: address of the customer who will become the founder + root member of the new organisation. Must NOT already resolve to an existing cas__user — reuse of an existing account is rejected with EMAIL_ALREADY_TAKEN (the customer would have two root accounts otherwise). If your customer already has a BizKitHub account, invite them as a member of an existing org instead of spawning a new one.
jan@barasek.compasswordstringRequiredFounder password (min 8 chars, standard strength check). Collect it from the vendor form; BizKitHub never emails the plaintext back. If you prefer a "reset link" flow, send any placeholder here and immediately call POST /api/v1/customer/request-reset-password for the same e-mail to issue a token the customer can use to set their real password.
firstNamestringRequiredFounder first name — becomes the contact's first name in the new org.
lastNamestringRequiredFounder last name — becomes the contact's last name in the new org.
localestringOptionalCommunication locale code — controls the language of textual data (product names, descriptions, articles, storefront UI, transactional e-mails).
Preferred format: BCP 47 language tag — language[-Script][-REGION]. Use the full tag whenever the script or region matters:
en-GBvs.en-US(British vs. American spelling)pt-PTvs.pt-BR(European vs. Brazilian Portuguese)zh-Hansvs.zh-Hant(Simplified vs. Traditional Chinese)sr-Latnvs.sr-Cyrl(Latin vs. Cyrillic Serbian)
Backwards-compatible fallback: the bare two-letter ISO 639-1 code (cs, en, pl, …) is accepted indefinitely — legacy clients that only send the language subtag continue to work unchanged.
Resolution algorithm (server-side): the input is resolved against the supported locale list via the [RFC 4647 Lookup] progressive-fallback strategy — trailing subtags are stripped one by one until a supported locale is found. Example: en-GB-oxendict → en-GB → en (matched). If no subtag combination is supported, the request is rejected.
Currently supported locales: cs, en, fr, it, pl, de, sk, sv, es, zh, ja, uk, da, hu, ro, nl, pt, fi, nb, hr. Region-specific variants (e.g. en-GB, pt-BR) are accepted and resolved to their base language when the exact variant is not registered separately.
Defaults to cs when omitted. Drives the primary locale of the new org, the founder's UI language, and the language of the platform welcome e-mail.
csenen-GBpt-BRzh-HanstimezonestringOptionalIANA timezone identifier for the new org (e.g. Europe/Prague). When omitted, resolved from the request IP's geo record.
Europe/PraguecountryIdnumberOptionalHQ country FK (core__country.id, from GET /organisation/available-countries). When omitted, resolved via geo lookup with Czech Republic (id=158) as ultimate fallback.
158descriptionstringOptionalOptional short description of the new organisation.
companyRegistrationNumberstringOptionalOptional company registration number (IČO in CZ). When provided, an ARES lookup is attempted to pre-fill legal name, address, and tax data.
taxIdentificationNumberstringOptionalOptional VAT / tax identification number (DIČ in CZ).
checkboxTermsbooleanOptionalWhether the founder has agreed to BizKitHub's terms and conditions. The vendor is responsible for collecting this consent from the end customer before calling the API.
falsecheckboxMarketingbooleanOptionalWhether the founder has opted in to marketing communication.
truecustomerRealIpstringOptionalAccepted formats:
- IPv4 dot-decimal, e.g.
1.1.1.1(4 octets, 0–255, no leading zeros). - IPv6 as defined by RFC 4291 — full
2001:0db8:0000:0000:0000:0000:0000:0001, zero-compressed2001:db8::1, IPv4-mapped::ffff:1.2.3.4, or scoped literals. Both upper- and lower-case hex are accepted.
Server-side canonicalization (ipNormalize in core/src/lib/network/ipNormalize.ts):
- Valid IPv4 is passed through verbatim.
- Valid IPv6 is lowercased (RFC 5952 §4.3).
- IPv4-mapped IPv6
::ffff:X.X.X.Xis unwrapped to plain IPv4 (RFC 4291 §2.5.5.2) so1.2.3.4and::ffff:1.2.3.4share onebrj__geo_iprow. - Loopback aliases (
::1,0.0.0.0,localhost, empty string) collapse to127.0.0.1. - Junk values that fail both IPv4 and IPv6 validation are silently rejected and replaced with
127.0.0.1(loopback).
On the wire: every response returns the canonicalized form — clients can safely rely on lowercase IPv6 and the plain-IPv4 unwrap when de-duping or joining. Server-originated writers (activity log, session log, ban list) resolve the visitor IP via resolveClientIp / resolveClientIpOrNull — always native IPv6 on Vercel Edge (there is no auto-mapping to ::ffff:X.X.X.X).
Enrichment: the system resolves reverse DNS, geolocation, ASN, mobile/proxy/hosting/Tor flags via our VikiTron GEO/IP resolver for both address families. Learn more
1.1.1.12001:4860:4860::8888