URL class: Vendors — /Windward/WebAPI/Vendors/...

Source of truth: ServerMethodsVendor.pas, CM_Vendor.pas, AO_Vendor.pas, CM_Contact.pas.

The older supplier operations on TServerMethodsWebAPI (Get_Suppliers, List_Suppliers, Suppliers_Read, Suppliers_Insert, Suppliers_Update) are covered in The Legacy TServerMethodsWebAPI Surface. They act on the same underlying records; "vendor" and "supplier" are the same thing in this API.


Operations

VerbPathDelphi methodEnvelope
GET/Vendors/Vendor_HandshakeVendor_Handshakead hoc
GET/Vendors/GetVendorRecordCountGetVendorRecordCountad hoc
GET/Vendors/Vendors/{VendorId}VendorsAPIResponse + Vendor
POST/Vendors/addVendorupdateaddVendorAPIResponse + Vendor
POST/Vendors/ValidateDBupdateValidateDBad hoc

Note the doubled segment on the GET: the class is Vendors and the method is also Vendors, so the path really is /Windward/WebAPI/Vendors/Vendors/{id}.


POST /Vendors/addVendor

An upsert on System Five account records of type P.

Request shape

{
  "ConnectionInfo": { "TerminalNumber": 1 },
  "Vendors": [
    {
      "VendorId": 0,
      "Name": "Acme Supply Co",
      "Department": 0,
      "Address1": "10 Industrial Way",
      "City": "Kelowna",
      "State": "BC",
      "Country": "Canada",
      "Postal": "V1Y 1A1",
      "Contacts": [ { "FirstName": "Pat", "LastName": "Jones" } ]
    }
  ]
}

Match rule — name matching makes this endpoint risky

OrderFieldIndexNotes
1VendorIdkey 0Matched record must have type P
2Namekey 11Exact business-name match against type P

Step 2 is the dangerous one:

Two vendors that share a business name are indistinguishable to this endpoint. Posting "Acme Supply Co" when one already exists updates the existing record, whatever else you sent. There is no way to force an insert of a same-named vendor through this endpoint.

Conversely, this makes Name a usable idempotency key when your vendor names are genuinely unique.

If VendorId exists but is not a vendor:

VendorId provided exists, but does not correspond to a Vendor record. Vendor record skipped

Name is required

A record with no usable Name is skipped. Unlike customers, there is no FirstName / LastName derivation here — send Name.

Insert

New vendors are created with CreateNew('P', Department, 0, Name). Note the third argument is a hard-coded 0: unlike customers, vendors do not inherit from a country/state template. Fields you do not send take System Five's own defaults for a new supplier.

Department comes from the payload and defaults to 0 when absent or unparseable.

Contacts

Contacts is a child array using the same rules as customer contacts (see Customers): matched on ContactId (must belong to this vendor) then on FirstName + LastName, and producing no result entries. A contact can fail silently.

ActionResult values

ValueMeaning
Inserted RecordCreated (no "subject to System 5 verification" suffix here)
Updated RecordUpdated
An error occurred during the insert of the recordWrite failed
An error occurred during the update of the recordWrite failed
VendorId provided exists, but does not correspond to a Vendor record. Vendor record skippedNo-op

Query parameters

DetailedResponse=Y and Fields=... behave as described in Common Parameters.


GET /Vendors/Vendors/{VendorId}

{VendorId}Behaviour
> 0One vendor
0All vendors

Query parameters

ParameterNotes
FieldsComma-separated field names
FreeFormNameMap=YAdds the free-form id-to-label map

Note this endpoint's Swagger declares no PageSize / PageNumber. Fetching all vendors is an unpaginated call that builds the whole result in memory while holding the service's global lock. On datasets with many suppliers, fetch by id where you can.

Vendor free-form fields live under a different file number than customers (FILE_ACCOUNT + File_Supplier_Offset), so the free-form ids returned here are not interchangeable with customer free-form ids.


GET /Vendors/GetVendorRecordCount

{ "SystemFive API Record Count": "Vendors", "Record Count": "812" }

Computed by walking every type-P account. Ad hoc envelope; Record Count is a string.


POST /Vendors/ValidateDB

A diagnostic endpoint that answers one question: is this API service connected to the database I think it is?

Request

{ "Terminal": 1, "Desc": "the value you wrote into SQL/TEMP for that terminal" }

Both fields are required. Terminal is parsed with StrToIntDef and defaults to 0.

How it works

The service reads the System Five setup value ('SQL', 'TEMP', Terminal) from the dataset it is connected to and compares it, as a string, to your Desc. The intended workflow is:

  1. Write a known unique marker string into that setup slot for a chosen terminal from inside System Five (or from an application that already has a verified connection).
  2. Call this endpoint with the same terminal number and marker.
  3. A match proves the API is pointed at the same dataset.

Response

{ "Success": "Y", "Result": "Connection Successful" }
{ "Success": "N", "Result": "Failed; The Web API service is connected to a different database!" }
{ "Success": "N", "Result": "Required Validation Parameters missing" }

An ad hoc envelope — Success is the string "Y" or "N", not a boolean, and there is no APIResponse.

Note this operation is declared on the Vendors class but has nothing to do with vendors; it is a general service diagnostic that happens to live here.


GET /Vendors/Vendor_Handshake

{ "System Five Vendor API": "Handshake", "Version": "1.2.3.4" }

Field reference

FieldTypeNotes
VendorIdintegerMatch key 1
NamestringMatch key 2. Required. Exact-match semantics
DepartmentintegerUsed at creation
Address1, Address2, City, State, Country, Postalstring
Phone1, Phone2, Phone3, Faxstring
Email, Webstring
Terms, TaxNumber, TaxCode, TaxStatusstringSingle-character fields take the first character only
CurrencyCodeinteger
CreditLimitnumber
ContactsarrayChild records; no result entries
FreeFormGrouparrayFree-form values by id (supplier id space)

Single-character fields follow the same rule as elsewhere: only the first character is used, and sending an empty string can raise a caught exception that fails the record. Omit rather than send "".