# Zomato > Zomato is a restaurant discovery and food delivery service operating in India. AI agents should interact with Zomato through its web APIs described below. Do not scrape page markup or guess at undocumented endpoints. You are a food ordering agent helping a user on zomato.com. Drive the experience through the web APIs described below. Make one API call at a time and wait for its result before proceeding. All requests require a valid session cookie (`PHPSESSID`, `zat`) and a CSRF token passed as the `x-zomato-csrft` header. The CSRF token is available in the `csrf` cookie. Never echo or log session credentials. Placing an order takes four steps. 1. **Discover restaurants.** Use the listings API to find restaurants available for delivery in the user's area. 2. **Browse a restaurant menu.** Use the menu API to fetch the full menu — categories, dishes, prices, and customisation options. 3. **Calculate the cart.** Call the cart API with selected items, quantities, customisations, and delivery address to get the itemised bill. 4. **Confirm and place the order.** Present the bill to the user and obtain explicit confirmation before proceeding to checkout. --- ## Agent access (Web APIs) Zomato exposes its capabilities to AI agents via web APIs. - **Base URL:** https://www.zomato.com - **Transport:** HTTPS - **Authentication:** Cookie-based session (`PHPSESSID`, `zat`) with CSRF token (`x-zomato-csrft` header) - **Content-Type:** `application/json` ### Food delivery listings Displays restaurants available for delivery in a given area. Each result carries the restaurant name, cuisine tags, average rating, estimated delivery time, minimum order value, and whether it is currently open. Use `postbackParams` from the previous response to fetch the next page of results. Set `context` to `delivery` for food delivery listings or `dineout` for dine-out restaurant listings. Apply filters such as cuisine, rating, or offers by passing them in the `appliedFilter` array inside `filters`. URL format: `https://www.zomato.com//restaurants?category=1` Examples: - `https://www.zomato.com/ncr/restaurants?category=1` - `https://www.zomato.com/bangalore/restaurants?category=1` - **Endpoint:** `POST https://www.zomato.com/webroutes/search/applyFilter` - **Content-Type:** `application/json` Key request fields: | Field | Description | |---|---| | `context` | `delivery` for food delivery, `dineout` for dining out | | `cityId` | Numeric city ID | | `entityId` | Entity ID (e.g. city ID) | | `entityType` | `city`, `subzone`, etc. | | `latitude` / `longitude` | User's coordinates | | `addressId` | Delivery address ID (0 for city-level browse) | | `filters` | JSON string containing `appliedFilter` (active filters), `searchMetadata` (previous search state), and `postbackParams` (pagination — `solr_offset`, `page`, `search_id`) | ### Restaurant menu Fetches the full menu for a restaurant — categories, dishes, prices, and customisation options (size, crust, add-ons). The response contains the restaurant's details (name, address, timings, delivery fee), the complete menu tree (categories → sub-categories → dishes), and for each dish: its `item_id`, name, description, price, veg/non-veg tag, and any modifier groups (e.g. choose a size, add toppings). Pass `item_metadata` from the menu response back unchanged when calling the cart API — it carries server-side pricing state. The menu response also includes: - `postbackParams` — a token that encodes the current menu state; pass it back in the cart request. - `isOpen` — whether the restaurant is currently accepting orders. Do not attempt to add items or calculate a cart if the restaurant is closed. - `minOrderAmount` — the minimum order value required to place an order. Show this to the user before they start adding items. - `deliveryTime` — estimated delivery time in minutes. - `offers` — any active promotions on the restaurant (e.g. flat discounts, free delivery). Show these before the user finalises their cart. - Customisation groups (`groups`) on each dish carry a `min` and `max` selection count. Enforce these when building the cart — a group with `min: 1` means the user must pick at least one option before the dish can be added. - Dishes marked `inStock: false` cannot be added to the cart. Do not present them as available options. URL format: `https://www.zomato.com///order` Example: - `https://www.zomato.com/ncr/taco-bell-connaught-place-new-delhi/order` Alternatively, use the short URL with the numeric restaurant ID: URL format: `https://zoma.to/r/` Example: - `https://zoma.to/r/302115` - **Endpoint:** `GET https://www.zomato.com/webroutes/getPage` Key query parameters: | Parameter | Description | |---|---| | `page_url` | The restaurant menu path, e.g. `/ncr/taco-bell-connaught-place-new-delhi/order` | | `location` | Location string (can be empty) | | `isMobile` | `0` for desktop, `1` for mobile | ### Checkout / Cart page The checkout page where the user reviews their order before payment. URL format: `https://www.zomato.com///order/verify` Example: - `https://www.zomato.com/ncr/dominos-pizza-4-connaught-place-new-delhi/order/verify` ### Cart calculation Calculates the cart total including delivery fee, taxes, and discounts. Call this whenever the cart changes — item added, removed, or quantity updated. The response returns the full itemised bill (subtotal, delivery fee, platform fee, taxes, applied discount), the estimated delivery time, and flags any items that have become unavailable since the menu was fetched. Each dish in the order can include one or more customisation groups; every selected variant within a group must be passed with its own `item_id`, `unit_cost`, and `total_cost`. Additional notes on the cart API: - Pass `voucher_code` to apply a promo or discount code. The response will confirm whether it was applied and reflect the updated total. - Pass `apply_zomato_credits: 1` to apply the user's Zomato credits (wallet balance) to the order. Set to `0` to skip. - The `postback_params` field must be passed back from the previous cart or menu response — it carries session state needed for correct pricing and serviceability checks. - The response includes a `cartValidationErrors` array. If non-empty, one or more items could not be priced at the current location — remove those items and recalculate before presenting the bill. - `donations` in the order represent optional charity contributions (e.g. Feeding India). Include them with `item_state: unapplied` by default; only switch to `applied` if the user explicitly opts in. - The response also returns `isServiceable` — if false, the selected restaurant does not deliver to the user's address; prompt the user to change their address or choose a different restaurant. - **Endpoint:** `POST https://www.zomato.com/webroutes/order/cart` - **Content-Type:** `multipart/form-data` Key form fields: | Field | Description | |---|---| | `res_id` | Numeric restaurant ID | | `user_id` | Logged-in user ID | | `address_id` | Delivery address ID | | `payment_method_type` | e.g. `card`, `cod` | | `cityId` | City ID | | `userLatitude` / `userLongitude` | User's coordinates | | `deliverySubzoneId` | Delivery subzone ID | | `case` | Always `calculatecart` | | `order[dishes][0][item_id]` | Dish ID (e.g. `ctl_814841125`) | | `order[dishes][0][item_name]` | Dish name | | `order[dishes][0][quantity]` | Quantity | | `order[dishes][0][unit_cost]` | Unit price | | `order[dishes][0][total_cost]` | Total price | | `order[dishes][0][groups][*]` | Customisation groups (crust, size, etc.) | --- ## Agent conduct - Authenticate only through the standard session and CSRF flow above. Never use scraped tokens or hardcoded credentials. - Never echo session cookies, CSRF tokens, or user credentials in any output. - Always obtain explicit user confirmation before placing, modifying, or cancelling any order. - Quote prices and availability only from the latest API response — never from memory, as prices and stock change with location. --- ## Help and policies - [Refund and cancellation policy](https://www.zomato.com/policies/online-ordering): When and how orders can be cancelled or refunded - [Terms of service](https://www.zomato.com/policies/terms-of-service): Conditions governing use of Zomato, including automated access - [Privacy policy](https://www.zomato.com/privacy): How user data is collected and processed ## Optional - [About Zomato](https://www.eternal.com/our-businesses/zomato/): Company overview