Developers
Connect your store to your own systems
Send orders, products and stock to your accounting, your ERP or your own app with a REST API, scoped API keys and signed webhooks.
- REST API and OpenAPI 3.1
- Standard Webhooks signatures
- Scoped API keys

Everything an integration needs
REST API
The things you do in the panel go through the same API: products, stock, orders, customers, campaigns, pages and more. Responses are JSON, and amounts come as integers in minor units with a currency code.
OpenAPI 3.1 schema
Endpoints, parameters and responses are described by an OpenAPI 3.1 schema that is kept in step with the code. You can generate a client in the language of your choice from it.
Scoped API keys
A key is tied to a single store and only works with the permissions you give it; staff, billing and store-deletion permissions cannot be given to a key. It is shown once when it is created and can be revoked instantly from the panel.
Webhooks
Sends events such as orders, payments, refunds, shipments, products, stock, customers, campaigns and e-invoices as JSON to the address you choose. You subscribe only to the events you care about.
Signed, reliable delivery
Signed in the Standard Webhooks format; during a secret rotation both secrets sign. Failed deliveries are retried at growing intervals for roughly a day, and there is a delivery log, manual retry, replay and test sending.
Module SDK
Payments, shipping, SMS, e-invoicing, product feeds and tracking tools are written against a standard module contract: a manifest, permissions, a settings form, events and scheduled jobs. Modules ship with the platform; store owners cannot upload their own code.
Your first integration
Your first integration in four steps
- Step 1: 1
Create a key
Create an API key in the store panel and choose only the permissions you need. The key is shown once, so store it safely. For a key that can change data you are asked for a confirmation code sent to your e-mail.
- Step 2: 2
Send the first request
Put your key in the Authorization header as a Bearer token and list orders: GET /api/v1/stores/{storeId}/orders. The response comes with data and meta fields; use page and limit for pagination.
- Step 3: 3
Add a webhook
Add a webhook in the panel: choose its address and the events you want. The secret is shown once when it is created. You can try your address with a test sending from the panel.
- Step 4: 4
Verify the signature
Verify the signature of every incoming request, de-duplicate with webhook-id and answer quickly. A verification sample follows below.
Verify the webhook signature
Every webhook request carries three headers: webhook-id, webhook-timestamp and webhook-signature. The signature is an HMAC-SHA256 of the text id.timestamp.body made with your secret. The secret starts with whsec_, is shown once when it is created and is stored encrypted. The sample below verifies a request in Node.js.
import { createHmac, timingSafeEqual } from 'node:crypto';
// rawBody: the request body as raw text, before any JSON parsing
export function verifyWebhook(secret, headers, rawBody) {
const id = headers['webhook-id'];
const timestamp = headers['webhook-timestamp'];
const signatures = headers['webhook-signature'];
if (!id || !timestamp || !signatures) return false;
// Time tolerance against replay attacks (5 minutes)
if (Math.abs(Date.now() / 1000 - Number(timestamp)) > 300) return false;
// The secret starts with "whsec_"; the rest is a base64-encoded key
const key = Buffer.from(secret.replace(/^whsec_/, ''), 'base64');
const expected = createHmac('sha256', key)
.update(`${id}.${timestamp}.${rawBody}`)
.digest();
// The header can hold several space-separated "v1,<signature>" entries
return signatures.split(' ').some((entry) => {
const [version, signature] = entry.split(',');
if (version !== 'v1' || !signature) return false;
const given = Buffer.from(signature, 'base64');
return given.length === expected.length && timingSafeEqual(given, expected);
});
}- Pass the body to the signature check as raw text, without parsing it as JSON first.
- webhook-id stays the same across every retry of the same event; store the ids you have processed and skip repeats.
- Any response outside 2xx counts as a failure and redirects are not followed; move heavy work to the background and answer quickly.
- After a secret rotation the header can carry two signatures; the sample tries all of them.
Limits, plans and the contract in brief
API access, the number of webhooks and request limits depend on your plan; the current values are in the plan comparison on the pricing page. Creating an API key requires the API access feature on your plan. When a limit is reached, the API answers with status 429 and RateLimit headers; wait a moment and retry.
| Topic | How it works |
|---|---|
| Base path | /api/v1 |
| Authentication | An API key in Authorization: Bearer (starts with api_live_) |
| Response | JSON; a data field on success and, for lists, pagination details in a meta field |
| Errors | An error object with code, message, details and requestId; messages follow the Accept-Language header in Turkish or English |
| Money | An integer in minor units plus a currency code (12990 = 129.90) |
| Dates | ISO 8601, UTC |
| Versioning | A breaking change requires a new major version; within v1 only backwards-compatible additions are made |
Frequently asked questions
Which plan do I need to use the API?
API access and webhooks are plan features. You can see which plans include them, together with the request limits and the number of webhooks, in the comparison on the pricing page.
Which permissions can I give an API key?
A key carries a subset of the store's permissions (for example reading products or writing orders). Staff, billing, API key and store-deletion permissions cannot be given to a key. When you create a key that can change data, a confirmation code is sent to your account's e-mail. You can revoke a leaked key from the panel and review its use in the audit log.
Which events are sent as webhooks?
Orders (created, paid, fulfilled, delivered, cancelled, refunded), payment and refund records, shipments and return requests, products and stock, categories, customers, favourites, campaigns, abandoned carts, newsletter subscriptions, domain status changes and e-invoice results. The full list appears in the panel when you add a webhook.
How do I send orders to my accounting or ERP system?
Subscribe a webhook to an order event (for example paid) and read the order's details from the API when the event arrives. Alternatively you can export orders as CSV from the panel. There is also a module that connects your own integrator account for e-invoices; see e-invoicing for details.
Can I upload my own payment or shipping module?
No. Modules are first-party packages compiled with the platform; uploading code as a store owner is deliberately not supported. For custom integrations use the API and webhooks; if you need an extra script on the storefront, you can add it with the custom script feature and choose its cookie consent category.
Ready to try the API?
Open your account, create an API key and send your first request. No credit card is asked during the trial.