How a program signs in to the Shop API, how to check a token, and the request limit.
Where to find itShopWhatsapp Api & Webhooks
Before you start
Signing in works on any plan. The bulk update call needs the "Webhooks & developer API" plan feature.
Needs
You turn this on
Who can use this
Shop owner, Shop Manager
The Shop API accepts a token that belongs to one panel account. A call made with it acts as that person.
Base address: your panel address followed by /api/shop. Send JSON, and send Accept: application/json so errors come back as JSON.
Get a token
There are two ways.
From the panel. The owner opens Shop › Whatsapp Api & Webhooks and selects 1. Generate token, or Regenerate when one exists. 2. Show token reveals it and 3. Copy copies it. The steps are on Whatsapp Api & Webhooks.
It answers with the same auth_token and user_id when the pair is the one stored for an owner or a Shop Manager. Otherwise validation fails with "invalid auth_token or user_id". A token that was replaced by a newer one fails this check.
Limits
Rule
Value
Requests
500 a minute. Beyond that the answer is HTTP 429
Missing or refused token on a protected call
HTTP 403 with the text "Unauthorized."
What the token can call
Under /api/shop there is one data call: bulk update products. To create products, sync stock or read orders, use the incoming API, which has its own token.