Tenant from the token
The store you act on comes from your signed token, never from a header you set.
Developers
Our admin, website builder and checkout are clients of the same documented APIs you get. Take the whole platform or just the parts you need, and keep your own frontend.
# Read: instant
GET /api/2026-10/storefront/recommendations?productId=…
Authorization: Bearer <storefront token>
# Write: safe to retry
POST /api/2026-10/payments
Authorization: Bearer <integration token>
Idempotency-Key: 6f1c…e9
# Or let an agent do it, with a preview first
> confirm_action { action_id: "act_8Qm2…" }Principles
The store you act on comes from your signed token, never from a header you set.
Send an Idempotency-Key on anything that could double-apply: payments, bulk jobs, webhooks.
Every error is the same structured body with a correlation ID, across every service.
Every list returns the same page envelope — no per-endpoint surprises.
Per-store secrets shown once, rotation, pause, and a delivery log.
Each endpoint says what it does in words a new engineer — or an agent — can act on.
Auth
Tell us what you’re building and we’ll set up a sandbox store and walk through the contracts.