Authentication

Access to the Merchant API is by bearer token. A token is issued against the email and password of the shop account and passed in the header of every protected request.

Getting a token

POST /api/merchant-service/auth/token

The method is open: it needs no token itself. The body carries the email and password:

BASH
curl -X POST https://admin.mobiusapp.io/api/merchant-service/auth/token \ -H "Content-Type: application/json" \ -d '{"email":"shop@example.com","password":"••••••"}'

The response:

JSON
{ "token": "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx", "token_type": "bearer", "expires_in": null }
Field Type Description
token string The bearer token for subsequent requests.
token_type string Always bearer.
expires_in integer | null Lifetime in seconds; null means the token does not expire.

Store the token on your side. If it is compromised, revoke it (see Signing out) and get a new one.

Using the token

Add the token to the Authorization header of every protected request:

BASH
curl https://admin.mobiusapp.io/api/merchant-service/orders/list \ -H "Authorization: Bearer xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"

A request to a protected method without a valid token returns 403.

Signing out

POST /api/merchant-service/auth/logout

Revokes the current token. After signing out the token becomes invalid.

BASH
curl -X POST https://admin.mobiusapp.io/api/merchant-service/auth/logout \ -H "Authorization: Bearer xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"
JSON
{ "message": "Logged out" }

Shop context

The shop is determined automatically from the token: there is no need to pass its identifier. Every request runs in the context of the shop attached to the account. If no active shop is attached, protected methods return a business error (422).

Sign-in rate limit

The token method is protected against brute force: no more than 10 requests per minute from one IP. Beyond that a 429 is returned with a Retry-After header saying how many seconds to wait. See Errors, limits and pagination.

Authentication errors

Status When Body
401 Wrong email or password { "error", "errorCode", "message" }
403 No valid token on a protected method { "error", "errorCode", "message" }
429 The sign-in rate limit was exceeded see Errors, limits and pagination

Related pages

Updated 04.09.2026 18:04
Was this page helpful?