Skip to main content
All routes require:
Paths are store-scoped. A key must include the matching product scope and access to that shop.

List

Scope: product:read
limit max is 100. Variant stockKeys are never returned here — use the stock endpoint.

Create

Scope: product:create · 201
storeId in the JSON body is ignored. The path store wins. Default delivery is license keys. Add stock before customers can check out, or send deliveryConfig with another method (manual_delivery, download_file, …).

Get / update / delete

Scopes: product:read · product:update · product:delete {productId} may be the cuid id or the numeric productId. PATCH/PUT are partial — omitted fields stay as they are. DELETE removes unused license keys automatically. If keys were already delivered on orders, delete returns 400 — hide the product instead.

Stock (license keys)

Scopes: product:stock:read · product:stock:write Optional query: ?variantName=Pro
  • PUT replaces unused keys for that variant (or the product when variantName is omitted)
  • POST appends keys

Errors