OAuth 2.0 + scoped tokens
Standard authorization code flow with refresh tokens. Granular scopes for read/write per resource.
OAuth 2.0 authorization, scoped tokens, webhook subscriptions, and a public marketplace at /apps. Build first-class apps for restaurants, retail, ecom, services, and dispensaries.
Standard authorization code flow with refresh tokens. Granular scopes for read/write per resource.
Inject UI blocks into storefronts. Customers install your block via the visual builder.
Subscribe to order events, customer events, inventory events. Signed payloads with retries.
Public /apps directory. Approved apps get visibility across every tenant's admin.
Get client_id + client_secret in the developer portal.
Redirect users to /api/oauth/authorize; exchange code for token.
Use Bearer token. Scopes enforce what each token can read/write.
Submit for review. Approved apps appear in the public /apps directory.
Read/write per resource: orders, products, customers, inventory, locations, marketing, settings. Apps request scopes; merchants approve at install.
Yes — per-token rate limits scale with the merchant's plan. Generous defaults; contact us for higher quotas.
Free plan, 14-day trial on paid plans, no credit card required.