> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sellauth.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Customer Dashboard API Introduction

> Public API for acting on behalf of a SellAuth shop's customers.

The Customer Dashboard API lets a custom storefront act on behalf of one of your shop's customers: read their store credit, open and reply to support tickets, manage subscriptions, run the affiliate and reseller panels, place reseller orders from balance, and buy instantly from balance.

You only need this if you are building your own customer area. The hosted SellAuth storefront already does all of it.

## Base URL

```
https://api.sellauth.com/v1/customer-dashboard
```

## Authentication

Every endpoint requires a **customer token**, sent as a Bearer token:

```bash theme={null}
curl https://api.sellauth.com/v1/customer-dashboard/balance \
  -H "Authorization: Bearer CUSTOMER_TOKEN"
```

Mint the token server-to-server with [Create Customer Token](/api-reference/customers/create-customer-token), using your seller API key:

```bash theme={null}
curl -X POST https://api.sellauth.com/v1/shops/1/customers/2/token \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"expires_in": 604800}'
```

<Warning>Call the minting endpoint from your backend only. Your seller API key grants full access to the shop and must never reach the browser.</Warning>

Tokens last 30 days by default. Pass `expires_in` (in seconds, from 60 up to 2592000) to shorten or extend that.

It is your job to authenticate the person first. SellAuth does not verify who is behind the request when you mint a token, so only mint one after your own login flow has established which customer it is.

<Note>The SellAuth login flow itself (one-time codes, passwords, two-factor authentication, Discord sign-in) is not part of this API. It is served on an internal domain for the hosted storefront.</Note>

### Token lifecycle

* A token stays valid until it expires, until the customer logs out of other sessions, or until you delete the customer.
* [Revoke Token](/customer-api/balance/revoke-token) deletes only the token that made the call, which is what you want when your storefront signs a customer out.
* Handle `401` by minting a fresh token rather than treating it as a hard failure.

<Warning>Reseller API keys are rejected here with a `403`. The [Reseller API](/reseller-api/introduction) and this API are separate surfaces with separate keys.</Warning>

## Rate limits

Limits are per customer, per minute:

| Endpoints | Limit |
| - | - |
| Get Reseller Order | 60 |
| Get Balance, Get Ticket, List Subscriptions, Quote Balance Purchase, Quote Reseller Order | 20 to 30 |
| Send Ticket Message, Pay from Balance, Pay Reseller Order | 10 |
| Everything else (create ticket, cancel or resume subscription, open billing portal, affiliate, reseller settings) | 5 |

## Shop settings apply

Most endpoints depend on how the shop is configured. Tickets need tickets enabled, affiliate endpoints need the affiliate program enabled with a separate affiliate balance, and reseller endpoints need the reseller program enabled and the customer approved. When a feature is off, the endpoint answers `403` with a message you can show as is.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.