API referenceIntroduction
API reference
v1.
Products, stock, orders, licenses, webhooks and data exports of your store, as JSON over HTTPS at api.anyshop.io. Every endpoint follows the rules on this page; its own page lists only what is its own. The same reference, as an OpenAPI 3.1 document, is at /v1/openapi.json.
Authentication
Send an API key from the dashboard's Developers, API keys as a Bearer token. A key belongs to one store and one mode: as_live_... sees live mode and as_test_... sees test mode, and nothing in a request can reach another store or the other mode. Keep keys on your servers, never in a browser or an app.
curl https://api.anyshop.io/v1/orders?limit=10 \
-H "Authorization: Bearer $ANYSHOP_API_KEY"Each key has scopes, such as orders:read or products:write; a write scope includes reading. The catalog is shared by both modes, so creating, changing, publishing and unpublishing products needs a live key. Full stock keys come back only from POST /v1/stock_items/{id}/reveal, which needs stock:reveal and is recorded in your security log. The license checks, the index and the OpenAPI document need no key.
Errors
Every error answers with a 4xx or 5xx status and the same body. Branch on type and code; message is for a person, and param names the field at fault when there is one.
{
"error": {
"type": "invalid_request",
"code": "too_long",
"message": "name is at most 120 characters",
"param": "name"
}
}| Status | type | When |
|---|---|---|
| 400 | invalid_request | A parameter or the body is wrong; param says which |
| 401 | authentication | No API key, or not a valid one |
| 403 | permission | The key lacks the scope (missing_scope), or the store is suspended (store_suspended) |
| 404 | not_found | Nothing with that ID in this store and mode |
| 409 | conflict | The object's state does not allow it, such as refunding a refunded order |
| 409 | idempotency | An Idempotency-Key reused for another request, or still running |
| 429 | rate_limited | Too many requests; wait for Retry-After |
| 500 | api_error | Our fault. Try again; with an Idempotency-Key, a retry is safe |
Pagination
Lists answer { "object": "list", "data": [...], "has_more": true }, newest first. Ask for up to 100 with limit (20 by default), and for the next page pass the last ID you got as starting_after.
curl "https://api.anyshop.io/v1/orders?limit=100&starting_after=ord_01m3rt5x2c7q9f0a4d6k8h1n3p" \
-H "Authorization: Bearer $ANYSHOP_API_KEY"Idempotency
Send an Idempotency-Key header with any write, 1 to 255 visible characters such as a UUID. For 24 hours, a retry with the same key and the same request gets the first answer again, with an idempotent-replayed: true header, and the work runs once. The same key with a different request is refused with idempotency_key_reused, and a retry while the first request is still running with idempotency_in_progress: try again in a moment.
Rate limits
1,000 requests a minute per API key. Over it, the answer is 429 with a Retry-After header in seconds. Failed authentication is limited per network, and the public license checks have their own limits, in the licenses guide.
Money and time
Amounts are integers in minor units of the store's currency: 1999 is $19.99, and 1999 in JPY is ¥1,999. Times are ISO 8601 strings in UTC, such as 2026-10-02T14:21:07.000Z. IDs start with their object's prefix, like prod_, ord_ and lic_.
Suspended stores
While a store is suspended its keys can still read everything, and still serve what it already sold: refunds, taking back items, resending the delivery email, revealing a stock key, revoking a license and freeing its devices, managing webhook endpoints, and starting a data export. Its webhooks keep delivering. Anything that sells or changes the catalog answers 403 with store_suspended; each endpoint's page says which it is.