Surfing Dog Inbox
Message, ask for a quote or book a call with Surfing Dog, through its open-source inbox.
- 0.1.0
- Version
- remote
- Transport
- 19
- Tools
Security review
Review passedReviewed 1d ago.
- tools: 19 tools scanned
- metadata: scanned
No findings.
Tools (19)
get_business_profile
Name, time zone, currency, languages and the item types this business accepts.
list_services
Bookable services with duration and price. A price per person (price.per = person) is for each person in the booking: send partySize, and the total is the price times it.
list_products
Orderable products with prices in minor units.
check_availability
Free start times for a service between two instants (at most 14 days). A time that has started, or that starts within the business's minimum notice, is not offered.
request_quote
Ask for a price on something custom. Creates a quote_request item.
create_booking
Request a service at a time. Check availability first. A fixed-price service costs the business's price from list_services; a different totalPrice you send is only noted for the business. A priced booking binds your person only once they confirmed it: without terms_sha nothing is sent, and you get the summary to show them (confirm.summary, confirm.terms_sha); call again with that terms_sha on their clear yes. Returns the item and, if you have no account, an access_token.
create_order
Order products. Prices are in minor units. A line naming a product (productId or sku) costs the business's price from list_products, and the total follows; a different price you send is only noted for the business. A line naming no product waits for the business to price it. A priced order binds your person only once they confirmed it: without terms_sha nothing is sent, and you get the summary to show them (confirm.summary, confirm.terms_sha); call again with that terms_sha on their clear yes.
get_item_status
The current state of an item you created, in the business's words: what it proposed and waits for your person to answer (offer, with its terms_sha), who it waits on, what they can do next, and the conversation so far (thread: the business's replies and your person's messages).
accept_offer
Accept another time the business proposed for a booking, its quote, its changes to an order, or a change it asks for to a confirmed booking or an accepted order (offer.kind change: the promise moves). This binds your person, so send terms_sha — offer.terms_sha from get_item_status — only after they said yes to offer.human, and offer_id (offer.id) so an answer to an offer since replaced does nothing. Without terms_sha nothing is booked: you get the terms to show them. An accepted quote becomes a confirmed booking or order (linked). A yes to a change that can no longer be made online goes to a person there instead (passed_on), and what was agreed stands.
decline_offer
Say no to another time or to changes the business proposed (the booking request or the order is closed) or to its quote. To a change it asks for to a confirmed booking or an accepted order, no keeps what was agreed; on a change your person asked for (requested_change), it takes that back. Add reason (and reason_code) for anything your person wants the business to know.
suggest_time
Instead of the time the business proposed, ask for another: start_time must be one of the free times check_availability lists (the end follows the service's length). The business confirms it or proposes again. On a confirmed booking it asks the business to move it (the end keeps the booking's length), and the booking stays as agreed until the business says yes. After a few rounds, or past the changes a booking may have, a person there answers it instead (passed_on).
make_offer
Answer what the business proposed with only what your person would change: another start_time (a booking: one of the free times check_availability lists; a quote request: the time it is for), other quantities for the lines of changes it suggested to an order (by index in offer.terms.lines; 0 drops one), another delivery_when, or how many (quantity) for a quote request. It goes back to the business as their request. On a confirmed booking or an accepted order it asks for a change to what was agreed (lines by index in the order's orderedItem), which stands until the business says yes. A price of their own is their answer only where get_business_profile says price_negotiable: total_price for a time it proposed (start_time optional), unit_price on lines of changes to an order; it goes back to the business, which takes it or answers. Otherwise — a price where the business sets its prices, on a quote, on something it does not haggle, or asked too often — it goes to a person there as their me
provide_details
Answer what the business asked about an item (get_item_status says it needs a detail). The item moves on; on any other item your details are kept as a message for the business.
withdraw_from_contract
Your person withdraws from their booking (one they paid for) or order, within the period the business states (withdrawal on get_item_status). Two steps: without confirm_withdrawal nothing is sent and you get the statement to show them (confirm.statement); send confirm_withdrawal: true on their yes. Before the goods went out the order ends and what was paid is refunded; once they reached your person, the goods come back (lines: only some of them) and are refunded. The business emails a copy. Never refused: past the period, or for something that cannot be returned, it goes to a person there instead (passed_on), or becomes a return under the business's own policy.
request_return
Once an order's goods reached your person: ask to send them back. reason faulty, not_as_described or wrong_item (the legal guarantee: it costs them nothing), or changed_mind (a withdrawal while the period runs, agreed at once; after it, a return the business answers under its own policy). lines: which, by index in orderedItem, and how many; all when left out. The return comes back as linked; get_item_status lists it under refunds.
cancel_item
Cancel an item you created. After the business's cancellation window, a confirmed booking is cancelled late where the business records late cancellations (it may count against the customer), and refused where it does not.
send_message
Start a conversation, or reply on an item you own.
acknowledge_receipt
Counter-sign a receipt this item earned, so both sides hold it: a promise, a change both sides agreed to it (kind amended), how it ended, or a refund's. Read the item to find its receipts; then send a compact JWS signed with your own Ed25519 key — header {alg:'EdDSA', typ:'sdi-receipt-ack+jws', jwk:<your public jwk>}, payload {rcp:<receipt id>, sha:<base64url(SHA-256(receipt jws))>, iat:<unix seconds>}. The instance verifies it against the key you carry and keeps it. Acknowledging twice is harmless.
verify_customer
When a result says identity.recognised is weak, the person gave the email of a customer the business knows. Call this with item_id and access_token to email them six digits; ask the person for the code and call it again with code. Then the business recognises them.