Authentication
Access to the Merchant API is by bearer token. A token is issued against the email and password of the shop account and passed in the header of every protected request.
Getting a token
POST /api/merchant-service/auth/token
The method is open: it needs no token itself. The body carries the email and password:
curl -X POST https://admin.mobiusapp.io/api/merchant-service/auth/token \
-H "Content-Type: application/json" \
-d '{"email":"shop@example.com","password":"••••••"}'
The response:
{
"token": "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx",
"token_type": "bearer",
"expires_in": null
}
| Field | Type | Description |
|---|---|---|
token |
string | The bearer token for subsequent requests. |
token_type |
string |
Always bearer. |
expires_in |
integer | null |
Lifetime in seconds; null means the token does not expire. |
Store the token on your side. If it is compromised, revoke it (see Signing out) and get a new one.
Using the token
Add the token to the Authorization header of every protected request:
curl https://admin.mobiusapp.io/api/merchant-service/orders/list \
-H "Authorization: Bearer xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"
A request to a protected method without a valid token returns 403.
Signing out
POST /api/merchant-service/auth/logout
Revokes the current token. After signing out the token becomes invalid.
curl -X POST https://admin.mobiusapp.io/api/merchant-service/auth/logout \
-H "Authorization: Bearer xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"
{ "message": "Logged out" }
Shop context
The shop is determined automatically from the token: there is no need to pass its identifier. Every request runs in the context of the shop attached to the account. If no active shop is attached, protected methods return a business error (422).
Sign-in rate limit
The token method is protected against brute force: no more than 10 requests per
minute from one IP. Beyond that a 429 is returned with a Retry-After header
saying how many seconds to wait. See
Errors, limits and pagination.
Authentication errors
| Status | When | Body |
|---|---|---|
401 |
Wrong email or password |
{ "error", "errorCode", "message" } |
403 |
No valid token on a protected method |
{ "error", "errorCode", "message" } |
429 |
The sign-in rate limit was exceeded | see Errors, limits and pagination |