API keys & scopes
Minting scoped credentials for the public API — the scope catalogue, why implication is resolved at grant time rather than at check time, and what a key with no scopes means.
Minting scoped credentials for the public API — the scope catalogue, why implication is resolved at grant time rather than at check time, and what a key with no scopes means.
How the Sumeru Systems APIs are organized — v1 admin API (programmatic), public storefront endpoints (CORS), webhooks (HMAC). Conventions, error model, versioning policy.
Integrate with Sumeru Systems via APIs, webhooks, the v1 admin API, the storefront pixel, and the embed SDK. Production-grade documentation for engineers building on the platform.
Stable, versioned admin endpoints for server-to-server programmatic access — BI tools, data warehouses, agency tooling, custom integrations. Bearer-token authenticated with per-operation scopes.
CORS-allowed storefront APIs that back the Theme App Extension widgets — reviews, referrals, bundles, upsells, quizzes, A/B tests, product feed, cart nudges, and the storefront pixel.