Skip to main content
Join Markt’s primary vendor APIs use a session cookie established at login (dash.joinmarkt.com). Browser clients send cookies automatically with same-site requests.

Browser / dashboard

  1. Sign in at the dashboard
  2. Call /api/... from the same origin
  3. Include credentials (fetch with credentials: 'include')
CSRF-sensitive mutations follow the app’s existing cookie + header conventions.

Server-to-server

For backend jobs, prefer:
  • A trusted server that holds the user session is not recommended long-term
  • Use routes that accept store-scoped secrets where documented (webhooks use provider signatures)
  • Platform admin routes require an admin session
Never embed dashboard session cookies in public clients or third-party scripts.

Merchant API keys (Bearer)

For Scriptable, bots, and server integrations, create a key under Account → Developers in the dashboard.
Keys are scoped to shops and permissions you choose in the wizard. See API keys. Outgoing shop events use HMAC X-Markt-Signature — see Outgoing webhooks. Do not confuse those with payment-provider IPN.

Permissions

Many routes check store membership and plan entitlements (for example custom domains on Premium+). A 403 usually means missing role or plan — not a bad password.

Example