Skip to main content
All routes require:
Paths are store-scoped. The key must include order:read or order:update and access to that shop. Dashboard permission ceilings still apply (viewOrders / editOrders).

List

Scope: order:read Query:
IP, user-agent, payment-provider secrets, and proof uploads are never returned.

Get

Scope: order:read {orderId} may be the cuid id or the public ORD-… value. An order that belongs to another shop returns 404. Detail adds seller note (human-readable only) and customFieldResponses. License key strings are not included — use dashboard fulfillment for that.

Update

Scope: order:update Only the mutations the dashboard already supports:
  • note — same as dashboard order note (updateOrderNote)
  • markDelivered: true — same as fulfillment “mark delivered” (paid / processing / completed with deliverable content)
Arbitrary status values are rejected (400). Pending orders cannot be marked delivered. markDelivered: false is ignored as a no-op and returns 400.

Errors