Skip to content

Developers

Connect your store to your own systems

Send orders, products and stock to your accounting, your ERP or your own app with a REST API, scoped API keys and signed webhooks.

  • REST API and OpenAPI 3.1
  • Standard Webhooks signatures
  • Scoped API keys
JavaScript code on a laptop screen

Everything an integration needs

  • REST API

    The things you do in the panel go through the same API: products, stock, orders, customers, campaigns, pages and more. Responses are JSON, and amounts come as integers in minor units with a currency code.

  • OpenAPI 3.1 schema

    Endpoints, parameters and responses are described by an OpenAPI 3.1 schema that is kept in step with the code. You can generate a client in the language of your choice from it.

  • Scoped API keys

    A key is tied to a single store and only works with the permissions you give it; staff, billing and store-deletion permissions cannot be given to a key. It is shown once when it is created and can be revoked instantly from the panel.

  • Webhooks

    Sends events such as orders, payments, refunds, shipments, products, stock, customers, campaigns and e-invoices as JSON to the address you choose. You subscribe only to the events you care about.

  • Signed, reliable delivery

    Signed in the Standard Webhooks format; during a secret rotation both secrets sign. Failed deliveries are retried at growing intervals for roughly a day, and there is a delivery log, manual retry, replay and test sending.

  • Module SDK

    Payments, shipping, SMS, e-invoicing, product feeds and tracking tools are written against a standard module contract: a manifest, permissions, a settings form, events and scheduled jobs. Modules ship with the platform; store owners cannot upload their own code.

Your first integration

Your first integration in four steps

  1. Step 1: 1

    Create a key

    Create an API key in the store panel and choose only the permissions you need. The key is shown once, so store it safely. For a key that can change data you are asked for a confirmation code sent to your e-mail.

  2. Step 2: 2

    Send the first request

    Put your key in the Authorization header as a Bearer token and list orders: GET /api/v1/stores/{storeId}/orders. The response comes with data and meta fields; use page and limit for pagination.

  3. Step 3: 3

    Add a webhook

    Add a webhook in the panel: choose its address and the events you want. The secret is shown once when it is created. You can try your address with a test sending from the panel.

  4. Step 4: 4

    Verify the signature

    Verify the signature of every incoming request, de-duplicate with webhook-id and answer quickly. A verification sample follows below.

Verify the webhook signature

Every webhook request carries three headers: webhook-id, webhook-timestamp and webhook-signature. The signature is an HMAC-SHA256 of the text id.timestamp.body made with your secret. The secret starts with whsec_, is shown once when it is created and is stored encrypted. The sample below verifies a request in Node.js.

import { createHmac, timingSafeEqual } from 'node:crypto';

// rawBody: the request body as raw text, before any JSON parsing
export function verifyWebhook(secret, headers, rawBody) {
  const id = headers['webhook-id'];
  const timestamp = headers['webhook-timestamp'];
  const signatures = headers['webhook-signature'];
  if (!id || !timestamp || !signatures) return false;

  // Time tolerance against replay attacks (5 minutes)
  if (Math.abs(Date.now() / 1000 - Number(timestamp)) > 300) return false;

  // The secret starts with "whsec_"; the rest is a base64-encoded key
  const key = Buffer.from(secret.replace(/^whsec_/, ''), 'base64');
  const expected = createHmac('sha256', key)
    .update(`${id}.${timestamp}.${rawBody}`)
    .digest();

  // The header can hold several space-separated "v1,<signature>" entries
  return signatures.split(' ').some((entry) => {
    const [version, signature] = entry.split(',');
    if (version !== 'v1' || !signature) return false;
    const given = Buffer.from(signature, 'base64');
    return given.length === expected.length && timingSafeEqual(given, expected);
  });
}
  • Pass the body to the signature check as raw text, without parsing it as JSON first.
  • webhook-id stays the same across every retry of the same event; store the ids you have processed and skip repeats.
  • Any response outside 2xx counts as a failure and redirects are not followed; move heavy work to the background and answer quickly.
  • After a secret rotation the header can carry two signatures; the sample tries all of them.

Limits, plans and the contract in brief

API access, the number of webhooks and request limits depend on your plan; the current values are in the plan comparison on the pricing page. Creating an API key requires the API access feature on your plan. When a limit is reached, the API answers with status 429 and RateLimit headers; wait a moment and retry.

TopicHow it works
Base path/api/v1
AuthenticationAn API key in Authorization: Bearer (starts with api_live_)
ResponseJSON; a data field on success and, for lists, pagination details in a meta field
ErrorsAn error object with code, message, details and requestId; messages follow the Accept-Language header in Turkish or English
MoneyAn integer in minor units plus a currency code (12990 = 129.90)
DatesISO 8601, UTC
VersioningA breaking change requires a new major version; within v1 only backwards-compatible additions are made

Frequently asked questions

Which plan do I need to use the API?

API access and webhooks are plan features. You can see which plans include them, together with the request limits and the number of webhooks, in the comparison on the pricing page.

Which permissions can I give an API key?

A key carries a subset of the store's permissions (for example reading products or writing orders). Staff, billing, API key and store-deletion permissions cannot be given to a key. When you create a key that can change data, a confirmation code is sent to your account's e-mail. You can revoke a leaked key from the panel and review its use in the audit log.

Which events are sent as webhooks?

Orders (created, paid, fulfilled, delivered, cancelled, refunded), payment and refund records, shipments and return requests, products and stock, categories, customers, favourites, campaigns, abandoned carts, newsletter subscriptions, domain status changes and e-invoice results. The full list appears in the panel when you add a webhook.

How do I send orders to my accounting or ERP system?

Subscribe a webhook to an order event (for example paid) and read the order's details from the API when the event arrives. Alternatively you can export orders as CSV from the panel. There is also a module that connects your own integrator account for e-invoices; see e-invoicing for details.

Can I upload my own payment or shipping module?

No. Modules are first-party packages compiled with the platform; uploading code as a store owner is deliberately not supported. For custom integrations use the API and webhooks; if you need an extra script on the storefront, you can add it with the custom script feature and choose its cookie consent category.

Ready to try the API?

Open your account, create an API key and send your first request. No credit card is asked during the trial.

Choose how we use cookies

We use cookies that the site needs to work. Analytics cookies are enabled only if you allow them; you can change your choice at any time from the link at the bottom of the page.