On Pro and Enterprise, Shoplio has a REST API for the parts of a store that are worth automating: syncing a catalogue, pushing stock from a supplier, reading orders, delivering from your own systems, and adjusting customer balances. Every key belongs to one shop and carries only the scopes you grant.
A key stops working if it expires, if its shop is deactivated, or if the owner's account leaves the Pro and Enterprise plans. The answer is always the same generic 401, so the API never reveals which of those it was.
There are ten scopes: read_products, write_products, read_orders, write_orders, fulfill_orders, read_stock, write_stock, edit_stock, delete_stock and read_analytics. You tick them when you create a key and can change them later. The three that destroy stock or hand out goods (edit_stock, delete_stock and fulfill_orders) are never granted unless you tick them.
read_orders returns the exact content each buyer received, decrypted, and read_stock returns unsold stock. Treat a key with either scope as holding your inventory.
Each key can make 60 requests a minute. Editing and deleting stock has a stricter bucket of 20 a minute, and order delivery has its own bucket of 60 a minute. Writes to the same product are serialised: a 409 with Retry-After: 5 means another change to that product was in flight and nothing was written, so retrying is always correct. Delivering an order is idempotent: calling it again for a delivered order returns success with "already_delivered": true and delivers nothing more.
POST https://api.shopl.io/api/v1/products/{product_id}/stock with a JSON body of {"items": ["KEY-1", "KEY-2"], "variant_id": "...", "notify": true}. variant_id is required when the product has variants. With notify set, the storefront cache is refreshed and your restock alerts fire; it is off by default. The key needs the write_stock scope.
Shoplio does not send outgoing webhooks for new orders; poll GET /orders instead. There is no file upload: product images take an already-hosted URL. Withdrawals, payout wallets, API keys and shop deletion are not available through the API.
Yes. Pro and Enterprise include a REST API at https://api.shopl.io/api/v1 for products, variants, stock, orders, delivery, customers and balances, authenticated with shop-scoped Bearer keys.
POST the items as a JSON array to /api/v1/products/{id}/stock with a key that has the write_stock scope. Include variant_id for a product with variants.
60 requests a minute per key, 20 a minute for stock edits and deletes, and a separate 60 a minute for order delivery.
Not to merchants today. Poll GET /api/v1/orders for new orders.
No. There is no withdrawal endpoint, and payout wallets and API keys can only be managed by the owner in the dashboard.
Open a hosted store for keys, accounts and files, take crypto through Cryptomus or OxaPay, and deliver automatically. Free plan; fees stated plainly.
Shoplio delivers keys, accounts and download links the moment a crypto payment confirms: encrypted stock, pre-orders, refunds to balance and an API.
Five Telegram bots for sales alerts, restock posts, store management, tickets and a customer shop bot, plus how Shoplio uses Discord. Pro feature.
Put your Shoplio store on your own domain with one CNAME record. SSL is issued for you. How to connect it, what each status means, and the limits.
No card and no subscription. Upgrade only when you need a paid feature.