dash.joinmarkt.com). Browser clients send cookies automatically with same-site requests.
Browser / dashboard
- Sign in at the dashboard
- Call
/api/...from the same origin - Include credentials (
fetchwithcredentials: 'include')
Server-to-server
For backend jobs, prefer:- A trusted server that holds the user session is not recommended long-term
- Use routes that accept store-scoped secrets where documented (webhooks use provider signatures)
- Platform admin routes require an admin session
Merchant API keys (Bearer)
For Scriptable, bots, and server integrations, create a key under Account → Developers in the dashboard.X-Markt-Signature — see Outgoing webhooks. Do not confuse those with payment-provider IPN.
Permissions
Many routes check store membership and plan entitlements (for example custom domains on Premium+). A403 usually means missing role or plan — not a bad password.