Skip to main content
The Customer Dashboard API lets a custom storefront act on behalf of one of your shop’s customers: read their store credit, open and reply to support tickets, manage subscriptions, run the affiliate and reseller panels, place reseller orders from balance, and buy instantly from balance. You only need this if you are building your own customer area. The hosted SellAuth storefront already does all of it.

Base URL

Authentication

Every endpoint requires a customer token, sent as a Bearer token:
Mint the token server-to-server with Create Customer Token, using your seller API key:
Call the minting endpoint from your backend only. Your seller API key grants full access to the shop and must never reach the browser.
Tokens last 30 days by default. Pass expires_in (in seconds, from 60 up to 2592000) to shorten or extend that. It is your job to authenticate the person first. SellAuth does not verify who is behind the request when you mint a token, so only mint one after your own login flow has established which customer it is.
The SellAuth login flow itself (one-time codes, passwords, two-factor authentication, Discord sign-in) is not part of this API. It is served on an internal domain for the hosted storefront.

Token lifecycle

  • A token stays valid until it expires, until the customer logs out of other sessions, or until you delete the customer.
  • Revoke Token deletes only the token that made the call, which is what you want when your storefront signs a customer out.
  • Handle 401 by minting a fresh token rather than treating it as a hard failure.
Reseller API keys are rejected here with a 403. The Reseller API and this API are separate surfaces with separate keys.

Rate limits

Limits are per customer, per minute:

Shop settings apply

Most endpoints depend on how the shop is configured. Tickets need tickets enabled, affiliate endpoints need the affiliate program enabled with a separate affiliate balance, and reseller endpoints need the reseller program enabled and the customer approved. When a feature is off, the endpoint answers 403 with a message you can show as is.