Checked against the product on 10 October 2026

A REST API for your digital goods store

On Pro and Enterprise, Shoplio has a REST API for the parts of a store that are worth automating: syncing a catalogue, pushing stock from a supplier, reading orders, delivering from your own systems, and adjusting customer balances. Every key belongs to one shop and carries only the scopes you grant.

Basics

A key stops working if it expires, if its shop is deactivated, or if the owner's account leaves the Pro and Enterprise plans. The answer is always the same generic 401, so the API never reveals which of those it was.

Endpoints

Scopes

There are ten scopes: read_products, write_products, read_orders, write_orders, fulfill_orders, read_stock, write_stock, edit_stock, delete_stock and read_analytics. You tick them when you create a key and can change them later. The three that destroy stock or hand out goods (edit_stock, delete_stock and fulfill_orders) are never granted unless you tick them.

read_orders returns the exact content each buyer received, decrypted, and read_stock returns unsold stock. Treat a key with either scope as holding your inventory.

Rate limits and retries

Each key can make 60 requests a minute. Editing and deleting stock has a stricter bucket of 20 a minute, and order delivery has its own bucket of 60 a minute. Writes to the same product are serialised: a 409 with Retry-After: 5 means another change to that product was in flight and nothing was written, so retrying is always correct. Delivering an order is idempotent: calling it again for a delivered order returns success with "already_delivered": true and delivers nothing more.

Typical uses

Example: push stock from a supplier feed

POST https://api.shopl.io/api/v1/products/{product_id}/stock with a JSON body of {"items": ["KEY-1", "KEY-2"], "variant_id": "...", "notify": true}. variant_id is required when the product has variants. With notify set, the storefront cache is refreshed and your restock alerts fire; it is off by default. The key needs the write_stock scope.

What the API does not do

Shoplio does not send outgoing webhooks for new orders; poll GET /orders instead. There is no file upload: product images take an already-hosted URL. Withdrawals, payout wallets, API keys and shop deletion are not available through the API.

Frequently asked questions

Does Shoplio have an API?

Yes. Pro and Enterprise include a REST API at https://api.shopl.io/api/v1 for products, variants, stock, orders, delivery, customers and balances, authenticated with shop-scoped Bearer keys.

How do I bulk upload stock through the API?

POST the items as a JSON array to /api/v1/products/{id}/stock with a key that has the write_stock scope. Include variant_id for a product with variants.

What are the API rate limits?

60 requests a minute per key, 20 a minute for stock edits and deletes, and a separate 60 a minute for order delivery.

Does Shoplio send webhooks for new orders?

Not to merchants today. Poll GET /api/v1/orders for new orders.

Can an API key withdraw my money?

No. There is no withdrawal endpoint, and payout wallets and API keys can only be managed by the owner in the dashboard.

Related

More features

Start on the free plan

No card and no subscription. Upgrade only when you need a paid feature.