Base URL
Authentication
Every endpoint requires a customer token, sent as a Bearer token:expires_in (in seconds, from 60 up to 2592000) to shorten or extend that.
It is your job to authenticate the person first. SellAuth does not verify who is behind the request when you mint a token, so only mint one after your own login flow has established which customer it is.
The SellAuth login flow itself (one-time codes, passwords, two-factor authentication, Discord sign-in) is not part of this API. It is served on an internal domain for the hosted storefront.
Token lifecycle
- A token stays valid until it expires, until the customer logs out of other sessions, or until you delete the customer.
- Revoke Token deletes only the token that made the call, which is what you want when your storefront signs a customer out.
- Handle
401by minting a fresh token rather than treating it as a hard failure.
Rate limits
Limits are per customer, per minute:Shop settings apply
Most endpoints depend on how the shop is configured. Tickets need tickets enabled, affiliate endpoints need the affiliate program enabled with a separate affiliate balance, and reseller endpoints need the reseller program enabled and the customer approved. When a feature is off, the endpoint answers403 with a message you can show as is.