Commercefull APIs
Everything the admin portal does, the API does — over 1,100 documented endpoints across three surfaces, plus HMAC-signed webhooks and a transactional event bus.
Customer API
/customer
Build custom storefronts, mobile apps, and customer experiences — authentication, catalog, baskets, checkout, orders, and accounts.
- • Catalog browsing & search
- • Guest & authenticated baskets
- • Checkout & payment sessions
- • Orders, returns & loyalty
- • JWT bearer + session auth
Business API
/business
Manage the store programmatically — catalog, inventory, orders, pricing, promotions, fulfillment, and administration.
- • Product & inventory management
- • Order processing & fulfillment
- • Pricing, promotions & B2B
- • Analytics, reports & audit
- • Organization JWT auth
GraphQL
/graphql
A GraphQL endpoint alongside REST — schemas are registered per-module and follow the same feature flags.
- • Per-module schemas via registry
- • Same auth & feature flags as REST
- • Media and catalog operations
Webhooks & Events
Subscribe to platform events with exact, wildcard, or category filters. Every delivery is HMAC-SHA256 signed, retried with backoff, and tracked.
- ✓Transactional outbox — events can't be lost on crash
- ✓Endpoint registration & test deliveries
- ✓Delivery history and failure inspection
Generated Reference
The API reference is generated from the OpenAPI spec in the repo — always in sync with the code, versioned with the release.
- ✓1,150+ operations, fully documented
- ✓Route index by surface and module
- ✓Configuration reference generated from source
Your API, your infrastructure
No rate limits set by a vendor, no per-call pricing, no deprecated versions forced on you. It's your server.