v1REST, JSON, OpenAPI 3.1
Build on
anyshop.
Products, stock, orders, licenses and webhooks of your store, over one API at api.anyshop.io. Payments go to your own rails; anyshop delivers what was bought, exactly once, and tells your servers.
$ curl https://api.anyshop.io/v1{ "object": "api", "version": "v1", "openapi": "https://api.anyshop.io/v1/openapi.json", "documentation": "https://docs.anyshop.io" }
Start here
Every guide runs in test mode first: no money moves.
Sell your first key with the API and a webhook
Create a product, add test keys, publish it, and hear about the order on your server.
POST/v1/productsPOST/stock_itemsPOST/v1/webhook_endpointsLicensesCheck licenses in your app
Activate a license on a device within its limit, validate it on launch, and work offline with a signed file.
POST/licenses/activatePOST/licenses/validateWebhooksReact to orders on your servers
Standard Webhooks signatures, retries for 3 days, and replays of anything your server missed.
GET/v1/eventsPOST/rotate_secretImportImport your catalog
Bring products, unsold keys, coupons, customers and licenses into your store with CSV files, and check every row before anything is written.
CheckoutSell from your own site
Your server starts a checkout, the buyer pays on anyshop's payment step, and comes back to your pages. The amount always comes from your prices.
POST/checkout_sessionsGET/checkout_sessions/{id}POST/checkout_sessions/{id}/cancelPaymentsGet paid in many coins
Connect your own NOWPayments account, and buyers pay in the coin they choose. NOWPayments is custodial: it holds the coins until it pays you out, for its 1% service fee.
The rules every call follows
Read these once. Every endpoint in the reference behaves the same way, so its page only lists what is its own.
Authentication
A Bearer API key from Developers, API keys. A test key sees only test mode and cannot change the catalog.
Authorization: Bearer as_test_...Errors
Every error has the same body and a 4xx or 5xx status; param names the field at fault.
{ "error": { "type", "code", "message", "param" } }Pagination
Lists are newest first. Pass the last ID you got as starting_after for the next page.
?limit=100&starting_after=ord_...Idempotency
Send an Idempotency-Key with a write: a retry within 24 hours gets the first answer and runs once.
Idempotency-Key: 9b1c...Money and time
Amounts are integers in minor units of the store currency. Times are ISO 8601, UTC.
"price": 1999
Authentication
A Bearer API key from Developers, API keys. A test key sees only test mode and cannot change the catalog.
Authorization: Bearer as_test_...More on authenticationErrors
Every error has the same body and a 4xx or 5xx status; param names the field at fault.
{ "error": { "type", "code", "message", "param" } }More on errorsPagination
Lists are newest first. Pass the last ID you got as starting_after for the next page.
?limit=100&starting_after=ord_...More on paginationIdempotency
Send an Idempotency-Key with a write: a retry within 24 hours gets the first answer and runs once.
Idempotency-Key: 9b1c...More on idempotencyRate limits
1,000 requests a minute per key. Over it, 429 with Retry-After.
Retry-After: 12More on rate limitsMoney and time
Amounts are integers in minor units of the store currency. Times are ISO 8601, UTC.
"price": 1999More on money and timeAPI reference
GET /v1/openapi.json
Products6 endpoints
6 endpointsYour catalog, shared by live and test mode.
GETPOSTPATCHStock5 endpoints
5 endpointsSerial keys to sell, per mode. Full keys only through an audited reveal.
GETPOSTDELOrders5 endpoints
5 endpointsWhat sold, refunds, taking back delivered items, the delivery email.
GETPOSTCheckout sessions3 endpoints
3 endpointsHeadless checkout: your server starts the checkout, your site's buyer pays on the step it names and comes back to your success_url.
POSTGETLicenses4 endpoints
4 endpointsLicenses, their devices and revocation.
GETPOSTDELWebhooks and events8 endpoints
8 endpointsWhere events go, how they are signed, and the events of the last 30 days.
GETPOSTPATCHDELExports2 endpoints
2 endpointsThe store's data as a zip of JSON and CSV. Unsold keys are exported only from the dashboard.
POSTGETPublic license checksLicense checks
Validate, activate and deactivate from your app. The license key is the credential: no API key ships with your software.
POST /v1/licenses/validateNo API key