> ## Documentation Index
> Fetch the complete documentation index at: https://docs.anny.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Create or update a connection

> Create a new connection or update an existing one between the authenticated customer and another person. The backend determines whether this is a new connection or an update based on the `connectedPerson` identity.

**Scopes:**
- `permittedScopes` — scopes you grant to the other person. Values: `granted` or `declined`
- `accessibleScopes` — scopes you request from the other person. Values: `requested` or `declined`. These become `granted` once accepted by the other user.

Provide either the `id` (UUID) or `email` of the connected person — or both. If the email is not yet registered, an invitation to create an anny account is sent.



## OpenAPI

````yaml /developers/openapi/customer-internal.openapi.json post /api/connections/save
openapi: 3.1.0
info:
  title: customer-api
  version: '1.0'
  contact:
    name: anny GmbH
    url: anny.co
    email: support@anny.co
  description: >-
    The Customer API is the **public booking surface** for end-user facing
    applications. It covers everything a customer can see and do — searching
    availability, placing bookings, managing their account, and more.


    ---


    ## When to use the Customer API


    Use the Customer API when you are **building something your customers
    interact with directly**:


    - **Custom booking flow** — embed a fully branded booking experience inside
    your own app or website instead of redirecting to anny

    - **Headless checkout** — drive the cart, checkout, and payment steps
    entirely from your own frontend

    - **Custom confirmation pages** — retrieve booking and order details after
    checkout to render a tailored confirmation

    - **Opening hours and availability on public pages** — display live schedule
    data on your website with no authentication required

    - **White-label experiences** — build lobby screens, kiosks, or mobile apps
    on top of the Customer API


    Many endpoints work **without any authentication**. For a custom OAuth2
    client to authenticate your own users, contact
    [support@anny.co](mailto:support@anny.co) with your use case.


    ---


    ## Authentication — Optional Auth


    Most Customer API endpoints work without a token. Providing a customer
    bearer token unlocks personal data and additional actions:


    | Auth state | What's accessible |

    |---|---|

    | Anonymous | Availability, public resource/service info, booking lookup by
    number, checkout |

    | Customer token | Own bookings, account data, communities, passes, queue
    tickets |


    ```

    Authorization: Bearer {customer_access_token}

    ```


    To authenticate your own users, you need a custom OAuth2 client — contact
    [support@anny.co](mailto:support@anny.co). See the [Authentication
    guide](/developers/guides/authentication) for the full token flow.


    ---


    ## Customer API vs Admin API


    | Feature | Customer API | Admin API |

    |---|---|---|

    | **Use case** | End-user apps, booking widgets | Server-side automation,
    backend tooling |

    | **Auth** | Optional — many endpoints work without a token | Required — API
    token or OAuth2 |

    | **Identifiers** | Slugs, booking numbers, order numbers | Immutable UUIDs
    and integer IDs |

    | **Access** | Public and customer-owned data only | Full read/write |


    → [Go to the Admin API](/developers/api-reference/admin)


    ---


    ## Resource Identifiers


    The Customer API uses **human-readable identifiers** that appear in booking
    URLs:


    | Entity | Identifier | Example |

    |---|---|---|

    | Resources | Slug | `conference-room-berlin` |

    | Services | Slug | `hourly-desk-booking` |

    | Organizations | Slug | `acme-gmbh` |

    | Bookings | Booking number | `BB123456789` |

    | Orders | Order number | `BO123456789` |


    Use the Admin API if you need immutable internal IDs for storage in external
    systems.


    ---


    ## Starting Points


    | Guide | What it covers |

    |---|---|

    | [Getting Started](/developers) | First steps and quickstart |

    | [JSON:API Conventions](/developers/guides/json-api-conventions) | Request
    and response format |

    | [Authentication](/developers/guides/authentication) | Customer token flow,
    OAuth2, anonymous access |

    | [Availability & Booking Search](/developers/guides/availability) | Search
    open slots, filter by service and resource |

    | [Customer Booking
    Lifecycle](/developers/guides/customer/booking-lifecycle) | View, modify,
    and cancel bookings |

    | [Order & Checkout Flow](/developers/guides/customer/checkout) | Cart,
    checkout steps, payment |

    | [Plans & Subscriptions](/developers/guides/customer/plans-subscriptions) |
    Membership plans and recurring billing |

    | [Communities & Access Control](/developers/guides/customer/communities) |
    Community membership and access gates |

    | [Waitlist](/developers/guides/customer/waitlist) | Join and manage
    waitlists |


    ---


    ## Base URLs


    | Environment | URL |

    |---|---|

    | Production | `https://b.anny.co` |

    | Gov-Cloud | `https://b.anny.eu` |
  termsOfService: https://anny.co/terms-of-use
  x-logo:
    url: https://cdn.anny.co/cms/anny_logo_main_colour_blue_4865e76654.svg
    altText: anny logo
    href: https://anny.co
servers:
  - url: https://b.anny.co
    description: Production
  - url: https://b.anny.eu
    description: Gov-Cloud
security: []
tags:
  - name: Addresses
  - name: Business Accounts
  - name: Access Control
  - name: Connections
  - name: Notifications
  - name: Payment Setups
paths:
  /api/connections/save:
    post:
      tags:
        - Connections
      summary: Create or update a connection
      description: >-
        Create a new connection or update an existing one between the
        authenticated customer and another person. The backend determines
        whether this is a new connection or an update based on the
        `connectedPerson` identity.


        **Scopes:**

        - `permittedScopes` — scopes you grant to the other person. Values:
        `granted` or `declined`

        - `accessibleScopes` — scopes you request from the other person. Values:
        `requested` or `declined`. These become `granted` once accepted by the
        other user.


        Provide either the `id` (UUID) or `email` of the connected person — or
        both. If the email is not yet registered, an invitation to create an
        anny account is sent.
      operationId: post-connections-save
      parameters:
        - schema:
            type: string
          in: header
          name: Authorization
          description: Bearer Token
          required: true
      requestBody:
        content:
          application/json:
            schema:
              type: object
              required:
                - connectedPerson
                - permittedScopes
                - accessibleScopes
              properties:
                connectedPerson:
                  type: object
                  properties:
                    id:
                      type:
                        - string
                        - 'null'
                      format: uuid
                      description: UUID of the customer account (nullable if email is set)
                    email:
                      type:
                        - string
                        - 'null'
                      format: email
                      description: >-
                        Email of the person to connect with (nullable if id is
                        set)
                permittedScopes:
                  type: object
                  properties:
                    read_bookings:
                      type: string
                      enum:
                        - granted
                        - declined
                    edit_bookings:
                      type: string
                      enum:
                        - granted
                        - declined
                    book_on_behalf:
                      type: string
                      enum:
                        - granted
                        - declined
                    receive_notifications:
                      type: string
                      enum:
                        - granted
                        - declined
                accessibleScopes:
                  type: object
                  properties:
                    read_bookings:
                      type: string
                      enum:
                        - requested
                        - declined
                    edit_bookings:
                      type: string
                      enum:
                        - requested
                        - declined
                    book_on_behalf:
                      type: string
                      enum:
                        - requested
                        - declined
                    receive_notifications:
                      type: string
                      enum:
                        - requested
                        - declined
            examples:
              new-connection:
                value:
                  connectedPerson:
                    id: 93633dd1-1399-40df-8536-9972f41ee71c
                    email: david.bowie@example.com
                  permittedScopes:
                    read_bookings: granted
                    edit_bookings: declined
                    book_on_behalf: declined
                    receive_notifications: declined
                  accessibleScopes:
                    read_bookings: requested
                    edit_bookings: declined
                    book_on_behalf: declined
                    receive_notifications: declined
      responses:
        '200':
          description: OK
        '401':
          description: Unauthorized
      security:
        - Bearer: []
components:
  securitySchemes:
    Bearer:
      type: oauth2
      flows:
        authorizationCode:
          tokenUrl: https://auth.anny.co/oauth/token
          refreshUrl: https://auth.anny.co/oauth/token/refresh
          scopes: {}
          authorizationUrl: https://auth.anny.co/oauth/authorize

````