Documented Venue REST APIs (v1 through v3) cover menus, orders, customers, inventory, and sales, with a Vendor API and webhooks. Onboarding runs through the POSaBIT Connect partner program rather than self-serve signup. Auth is uneven: Bearer tokens on v1 and v2, Basic Auth on v3.
POSaBIT scores C on the API Report Card. Documented Venue REST APIs (v1 through v3) cover menus, orders, customers, inventory, and sales, with a Vendor API and webhooks. Onboarding runs through the POSaBIT Connect partner program rather than self-serve signup. Auth is uneven: Bearer tokens on v1 and v2, Basic Auth on v3.
POSaBIT has an official API, but teams routinely hit its limits: gated access, partial coverage, or paid tiers. Most end up supplementing it with exports or an unofficial API layer like Supergood. Site terms may apply to any integration approach, and how they apply is a determination each team makes for itself.
POSaBIT is a cannabis-specific point-of-sale, payments and e-commerce platform from POSaBIT Systems Corporation (CSE: PBIT / OTCQB: POSAF).
Cannabis dispensaries, single-location operators through multi-state operator (MSO) chains in legal US adult-use and medical markets. Budtender rings a sale on a POSaBIT POS terminal or Pocket POS handheld; product, weight, taxes and patient/recreational status are checked against state rules; the transaction is routed through POSaBIT Pay (PIN-debit/ACH-style cashless) and pushed to Metrc/BioTrack for state reporting.
Mid-tier within cannabis, low outside it. POSaBIT consistently appears on 'top 5–10 dispensary POS' lists alongside Dutchie, Flowhub, Treez, Cova, Meadow and Blaze, but trails Dutchie (largest market share) and Flowhub on installed base.
Parent: POSaBIT Systems Corporation (CSE: PBIT, OTCQB: POSAF); HQ 4786 1st Ave South, Seattle, WA. Founded: 2015. Headcount: ~62 employees (2025). Revenue: ~$11.5M TTM as of Sep 30, 2025.
Founded 2015 in Seattle; publicly traded on the CSE since 2019 and on OTCQB as POSAF.
Grades measure one thing: can a customer's engineering team get their own data out programmatically? We check six things (whether a real API exists, how access is gated, data coverage, auth quality, docs and developer experience, and stability) and roll them into a letter grade. Grades get re-verified, and they only move on evidence.
Yes, via a managed API layer. Supergood builds REST APIs and MCP servers for authenticated enterprise web apps, so AI agents and internal tools can read and write data programmatically.