API
Authentication
Authenticate Developer API requests with a secret API key.
Create a key in Dashboard → Developers → API keys. Send it as a Bearer token.
curl https://your-vinext-host/api/dev/v1/me \
-H "Authorization: Bearer sk_live_..."Do not put secret keys in browsers, mobile apps, or public repos. Use the embed script or the storefront SDK for client-side checkout.
Scopes
Keys can be limited to scopes such as products:read, orders:write, and webhooks:write. A request without the required scope returns FORBIDDEN.
Idempotency
Mutations accept Idempotency-Key. Replay the same key to retry a create without duplicating the resource.