How Idovio Commerce authenticates, which endpoints it exposes, how it connects to sales channels and suppliers, and what data each connection handles. The endpoint tables are generated from the source code of the product.
Connection broker at connect.idovio.com: OAuth callbacks and the privacy notifications that Shopify and eBay require.
Web application at idovio.app.
Account and workspace API: built and covered by automated tests, but not yet published at a public address. The reference below describes the version in the source code.
API keys for third-party applications are not issued yet. Scopes and limits will be documented here when they are.
Providers send the merchant back to these addresses after consent, and deliver their mandatory privacy notifications here. The broker stores nothing: it exchanges the authorization for tokens and hands them to the merchant's own workspace.
| Method | Path | |
|---|---|---|
GET | https://connect.idovio.com/health | Service status and configured providers |
GET | https://connect.idovio.com/oauth/callback/{provider} | Redirect address to register in the provider's developer console |
POST | https://connect.idovio.com/webhooks/shopify/customers-data-request | Shopify mandatory privacy webhook, HMAC verified |
POST | https://connect.idovio.com/webhooks/shopify/customers-redact | Shopify mandatory privacy webhook, HMAC verified |
POST | https://connect.idovio.com/webhooks/shopify/shop-redact | Shopify mandatory privacy webhook, HMAC verified |
GET | https://connect.idovio.com/webhooks/ebay/account-deletion | eBay endpoint ownership challenge |
POST | https://connect.idovio.com/webhooks/ebay/account-deletion | eBay marketplace account deletion notification |
All paths are relative to the API origin. Requests and responses are JSON.
| Method | Path | Access |
|---|---|---|
GET | /api/v1/auth/auth0/callback | Public |
GET | /api/v1/auth/auth0/logout | Public |
GET | /api/v1/auth/auth0/start | Public |
GET | /api/v1/auth/google/callback | Public |
GET | /api/v1/auth/google/start | Public |
POST | /api/v1/auth/handoff | Public |
POST | /api/v1/auth/login | Public |
POST | /api/v1/auth/logout | Signed-in user |
GET | /api/v1/auth/mfa | Signed-in user |
POST | /api/v1/auth/mfa/disable | Signed-in user |
POST | /api/v1/auth/mfa/enroll | Signed-in user |
POST | /api/v1/auth/mfa/enroll/confirm | Signed-in user |
POST | /api/v1/auth/mfa/login | Public |
POST | /api/v1/auth/mfa/recovery-codes | Signed-in user |
POST | /api/v1/auth/mfa/verify | Signed-in user |
POST | /api/v1/auth/password/change | Signed-in user |
POST | /api/v1/auth/password/forgot | Public |
POST | /api/v1/auth/password/reset | Public |
GET | /api/v1/auth/providers | Public |
GET | /api/v1/auth/session | Signed-in user |
POST | /api/v1/auth/signup | Public |
POST | /api/v1/auth/verify-email | Public |
POST | /api/v1/auth/verify-email/resend | Signed-in user |
| Method | Path | Access |
|---|---|---|
GET | /api/v1/account | Signed-in user |
PATCH | /api/v1/account | Signed-in user |
GET | /api/v1/devices | Signed-in user |
DELETE | /api/v1/devices/:id | Signed-in user |
POST | /api/v1/devices/revoke-others | Signed-in user |
POST | /api/v1/invitations/accept | Signed-in user |
| Method | Path | Access |
|---|---|---|
GET | /api/v1/audit | Workspace member |
GET | /api/v1/members | Workspace member |
PATCH | /api/v1/members/:userId | Workspace member |
DELETE | /api/v1/members/:userId | Workspace member |
POST | /api/v1/members/invitations | Workspace member |
DELETE | /api/v1/members/invitations/:id | Workspace member |
GET | /api/v1/usage | Workspace member |
GET | /api/v1/workspace | Workspace member |
PATCH | /api/v1/workspace | Workspace member |
GET | /api/v1/workspace/data | Workspace member |
POST | /api/v1/workspace/data | Workspace member |
GET | /api/v1/workspace/layout | Workspace member |
PATCH | /api/v1/workspace/layout | Workspace member |
POST | /api/v1/workspace/members/:userId/mfa/reset | Workspace member |
GET | /api/v1/workspaces | Signed-in user |
POST | /api/v1/workspaces | Signed-in user |
POST | /api/v1/workspaces/:id/select | Signed-in user |
| Method | Path | Access |
|---|---|---|
GET | /api/v1/commerce/orders | Workspace member |
GET | /api/v1/commerce/products | Workspace member |
GET | /api/v1/jobs | Workspace member |
POST | /api/v1/jobs/:id/cancel | Workspace member |
POST | /api/v1/jobs/:id/retry | Workspace member |
| Method | Path | Access |
|---|---|---|
POST | /api/v1/amazon/connect | Workspace member |
GET | /api/v1/amazon/connections | Workspace member |
DELETE | /api/v1/amazon/connections/:id | Workspace member |
POST | /api/v1/amazon/connections/:id/call | Workspace member |
GET | /api/v1/amazon/connections/:id/finances | Workspace member |
GET | /api/v1/amazon/connections/:id/inventory | Workspace member |
GET | /api/v1/amazon/connections/:id/orders | Workspace member |
GET | /api/v1/amazon/oauth/callback | Workspace member |
GET | /api/v1/amazon/oauth/login | Public |
GET | /api/v1/amazon/oauth/start | Workspace member |
POST | /api/v1/connectors/oauth/:provider/start | Workspace member |
GET | /api/v1/connectors/oauth/callback/:provider | Workspace member |
GET | /api/v1/connectors/oauth/connections | Workspace member |
DELETE | /api/v1/connectors/oauth/connections/:id | Workspace member |
POST | /api/v1/connectors/oauth/connections/:id/read | Workspace member |
GET | /api/v1/connectors/oauth/providers | Workspace member |
GET | /api/v1/connectors/vault/:name | Workspace member |
PUT | /api/v1/connectors/vault/:name | Workspace member |
DELETE | /api/v1/connectors/vault/:name | Workspace member |
POST | /api/v1/connectors/vault/call | Workspace member |
GET | /api/v1/secrets | Workspace member |
PUT | /api/v1/secrets/:name | Workspace member |
DELETE | /api/v1/secrets/:name | Workspace member |
POST | /api/v1/secrets/rotate-key | Workspace member |
| Method | Path | Access |
|---|---|---|
GET | /api/v1/automation/approvals | Workspace member |
POST | /api/v1/automation/approvals/:id/approve | Workspace member |
POST | /api/v1/automation/approvals/:id/reject | Workspace member |
GET | /api/v1/automation/executions/:id | Workspace member |
POST | /api/v1/automation/executions/:id/cancel | Workspace member |
GET | /api/v1/automation/executions/:id/events | Workspace member |
POST | /api/v1/automation/executions/:id/retry | Workspace member |
GET | /api/v1/automation/skills | Workspace member |
POST | /api/v1/automation/skills/:skill/execute | Workspace member |
| Method | Path | Access |
|---|---|---|
GET | /api/v1/billing | Workspace member |
POST | /api/v1/billing/cancel | Workspace member |
POST | /api/v1/billing/change-plan | Workspace member |
POST | /api/v1/billing/checkout | Workspace member |
POST | /api/v1/billing/portal | Workspace member |
POST | /api/v1/billing/resume | Workspace member |
POST | /api/v1/billing/webhooks/stripe | Public |
POST | /api/v1/entitlement/certificate | Workspace member |
GET | /api/v1/plans | Public |
| Method | Path | Access |
|---|---|---|
GET | /api/v1/client/release | Public |
GET | /health | Public |
GET | /ready | Public |
GET | /runtime/health | Public |
GET | /runtime/version | Public |
GET | /version | Public |
An external assistant acts through the same control plane as a person. A credential identifies it, but every call still passes workspace binding, scope, policy, limits and, where required, human approval, and is recorded.
commerce.get_overviewcatalog.searchsupplier.rank_routesorders.searchui.navigatesupplier.rerouteprice.updateautomation.runFor each connection: how the merchant authorizes it, what Idovio Commerce can do through it, which classes of data it handles and how changes arrive. Current availability is on the Connections page. Connections
| Provider | Authorization | Capabilities | Data handled | Updates |
|---|---|---|---|---|
| AliExpress | OAuth through the Idovio application | catalog.importcatalog.readcatalog.searchorder.createprice.readshipping.quotestock.readtracking.read | CredentialConfidentialPersonal Data | On request |
| Amazon | OAuth through the Idovio application | account.discovercatalog.publishcatalog.readcatalog.searchcatalog.updatefulfillment.writelisting.pauseorder.readprice.readprice.writestock.readstock.writetracking.write | CredentialSensitive Platform DataRestricted Platform Data | Scheduled polling |
| BigBuy | Merchant's own API key | catalog.readcatalog.searchorder.createprice.readstock.read | CredentialConfidentialPersonal Data | On request |
| Bookvault | Merchant's own API key | catalog.readcatalog.searchprice.readshipping.quotetracking.read | CredentialConfidential | Scheduled polling |
| CJ Dropshipping | Merchant's own API key | catalog.readcatalog.searchorder.createprice.readstock.readtracking.read | CredentialConfidentialPersonal Data | Webhook endpoint |
| Cloudprinter | Merchant's own API key | catalog.readcatalog.searchorder.createprice.readshipping.quotetracking.read | CredentialConfidentialPersonal Data | Scheduled polling |
| EasyPost | Merchant's own API key | shipping.label.createshipping.quotetracking.read | CredentialConfidentialPersonal Data | Scheduled polling |
| eBay | OAuth through the Idovio application | account.discovercatalog.publishcatalog.readcatalog.updatefulfillment.writelisting.pauseorder.readprice.readprice.writerefund.writereturn.readstock.readstock.writetracking.write | CredentialPersonal DataSensitive Platform Data | Scheduled polling |
| Etsy | OAuth with PKCE | account.discovercatalog.publishcatalog.readcatalog.updatefulfillment.writelisting.pauseorder.readprice.readprice.writestock.readstock.writetracking.write | CredentialPersonal DataSensitive Platform Data | On request |
| Gelato | Merchant's own API key | catalog.readcatalog.searchorder.cancelorder.createprice.readshipping.quotetracking.read | CredentialConfidentialPersonal Data | Scheduled polling |
| Gmail | OAuth through the Idovio application | account.discovermail.read | CredentialPersonal DataRestricted Platform Data | Scheduled polling |
| Google Ads | OAuth through the Idovio application | ads.budgetads.pauseads.read | CredentialSensitive Platform Data | On request |
| Gooten | Merchant's own API key | catalog.readcatalog.searchorder.createprice.readshipping.quotetracking.read | CredentialConfidentialPersonal Data | Scheduled polling |
| Lemon Squeezy | Merchant's own application credentials | order.read | CredentialPersonal DataSensitive Platform Data | Scheduled polling |
| Lulu Direct | Merchant's own API key | catalog.readcatalog.searchorder.createprice.readshipping.quotetracking.read | CredentialConfidentialPersonal Data | Scheduled polling |
| Meta Ads | OAuth through the Idovio application | ads.budgetads.pauseads.read | CredentialSensitive Platform Data | On request |
| Microsoft Outlook | OAuth through the Idovio application | account.discovermail.read | CredentialPersonal Data | Scheduled polling |
| Ollama | Local, no external account | model.managemodel.run | InternalConfidential | On request |
| Own Warehouse | Local, no external account | catalog.readcatalog.searchorder.createprice.readreturn.requeststock.read | InternalConfidential | On request |
| Paddle | Merchant's own application credentials | order.read | CredentialPersonal DataSensitive Platform Data | Scheduled polling |
| Printful | OAuth through the Idovio application | catalog.importcatalog.readcatalog.searchorder.cancelorder.createprice.readshipping.quotestock.readtracking.read | CredentialConfidentialPersonal Data | Scheduled polling |
| Printify | OAuth through the Idovio application | catalog.importcatalog.readcatalog.searchorder.cancelorder.createprice.readrefund.requestreturn.requestshipping.quotestock.readtracking.read | CredentialConfidentialPersonal Data | Scheduled polling |
| Prodigi | Merchant's own API key | catalog.readcatalog.searchorder.cancelorder.createprice.readshipping.quotetracking.read | CredentialConfidentialPersonal Data | Scheduled polling |
| Shirtigo | Merchant's own API key | catalog.readcatalog.searchorder.createprice.readshipping.quotetracking.read | CredentialConfidentialPersonal Data | Scheduled polling |
| Shopify | Merchant's own application credentials | catalog.publishcatalog.readcatalog.updatelisting.pauseorder.readprice.readprice.writestock.readstock.write | CredentialPersonal DataSensitive Platform Data | Scheduled polling |
| Stripe | Merchant's own application credentials | order.readrefund.write | CredentialPersonal DataSensitive Platform Data | Scheduled polling |
| TikTok Ads | OAuth through the Idovio application | ads.budgetads.pauseads.read | CredentialSensitive Platform Data | On request |
| TikTok Shop | OAuth through the Idovio application | account.discovercatalog.publishcatalog.readcatalog.updatefulfillment.writelisting.pauseorder.readprice.readprice.writereturn.readstock.readstock.writetracking.writewebhook.verify | CredentialPersonal DataSensitive Platform Data | Webhook endpoint |
| Universal IMAP | Merchant's own application credentials | mail.read | CredentialPersonal Data | Scheduled polling |
| Wix | Merchant's own application credentials | catalog.publishcatalog.readcatalog.updatefulfillment.writelisting.pauseorder.readprice.readprice.writestock.readstock.writetracking.write | CredentialPersonal DataSensitive Platform Data | Scheduled polling |
| WooCommerce | Merchant's own application credentials | catalog.publishcatalog.readcatalog.updatelisting.pauseorder.readprice.readprice.writerefund.writestock.readstock.write | CredentialPersonal DataSensitive Platform Data | Scheduled polling |
Privacy policyTermsSecurityTechnical contact: idev@idovio.com