Developers
Keys, scopesand limits
How authentication works, what the API covers, how it is rate limited, and how to get a key issued for your store.
Authentication
One bearer token, scoped to one store
Keys are issued per store and carry explicit scopes. A key can read products without being able to issue refunds, which is the difference between integrating a stock feed and handing over the business.
- Bearer tokens in the Authorization header
- Scopes per resource, read and write separately
- Keys revocable from the dashboard at any time
- Every call attributed in the store's audit trail
POST /v1/orders/{id}/fulfilments
Authorization: Bearer sk_live_…
Content-Type: application/json
{
"outletId": "out_3f9",
"lines": [{ "orderLineId": "ol_88", "quantity": 2 }],
"deliveryMethod": "RIDER"
}Reference
What you can call
The resource groups available today. Full request and response schemas ship with the public reference.
| Resource | Path | Operations |
|---|---|---|
| Products | /v1/products | list · create · update · delete |
| Variants | /v1/products/{id}/variants | list · create · update |
| Collections | /v1/collections | list · create · update |
| Inventory | /v1/inventory/levels | list · adjust · transfer |
| Orders | /v1/orders | list · create · update · cancel |
| Fulfilments | /v1/orders/{id}/fulfilments | list · create |
| Returns | /v1/returns | list · create · approve |
| Customers | /v1/customers | list · create · update |
| Payments | /v1/payments | list · refund |
| Invoices | /v1/invoices | list · create · send |
| Outlets | /v1/outlets | list |
| Webhooks | /v1/webhooks | list · create · delete |
Limits & behaviour
What to expect from the wire
Rate limiting
Per-key limits with the remaining budget returned on every response. A limited request returns 429 with a retry hint rather than failing silently.
Pagination
List endpoints are cursor-paginated. Page through with the cursor from the previous response rather than fetching records one at a time.
Idempotency
Write requests accept an idempotency key, so a retry after a timeout will not create a second order or a second refund.
Errors
Failures return a stable machine-readable code alongside the human message, so your integration can branch on the code rather than on wording.
Versioning
The version is in the path. Breaking changes ship as a new version; additive changes land in place and are announced before they do.
Webhook delivery
Payloads are signed and retried with backoff. Deliveries and their responses are visible so a failing endpoint is diagnosable.