[{"data":1,"prerenderedAt":639},["ShallowReactive",2],{"navigation_docs_en":3,"-en-getting-started-enterprise-integration":210,"-en-getting-started-enterprise-integration-surround":634},[4,23,41,51,65,83,182,196],{"title":5,"icon":6,"path":7,"stem":8,"children":9,"page":22},"Getting started","i-lucide-rocket","\u002Fen\u002Fgetting-started","en\u002F1.getting-started",[10,14,18],{"title":11,"path":12,"stem":13},"Quick start","\u002Fen\u002Fgetting-started\u002Fquick-start","en\u002F1.getting-started\u002F1.quick-start",{"title":15,"path":16,"stem":17},"Trust model","\u002Fen\u002Fgetting-started\u002Ftrust-model","en\u002F1.getting-started\u002F2.trust-model",{"title":19,"path":20,"stem":21},"Enterprise integration journey","\u002Fen\u002Fgetting-started\u002Fenterprise-integration","en\u002F1.getting-started\u002F3.enterprise-integration",false,{"title":24,"icon":25,"path":26,"stem":27,"children":28,"page":22},"Storefront","i-lucide-store","\u002Fen\u002Fstorefront","en\u002F2.storefront",[29,33,37],{"title":30,"path":31,"stem":32},"Third-party Storefront","\u002Fen\u002Fstorefront\u002Fthird-party-storefront","en\u002F2.storefront\u002F1.third-party-storefront",{"title":34,"path":35,"stem":36},"Turnstile trust boundary","\u002Fen\u002Fstorefront\u002Fchallenge-and-turnstile","en\u002F2.storefront\u002F2.challenge-and-turnstile",{"title":38,"path":39,"stem":40},"Third-party Storefront public API","\u002Fen\u002Fstorefront\u002Fpublic-api","en\u002F2.storefront\u002F3.public-api",{"title":42,"icon":43,"path":44,"stem":45,"children":46,"page":22},"OAuth and identity","i-lucide-key-round","\u002Fen\u002Foauth","en\u002F3.oauth",[47],{"title":48,"path":49,"stem":50},"Third-party account authorization boundary","\u002Fen\u002Foauth\u002Fauthorization-code-pkce","en\u002F3.oauth\u002F1.authorization-code-pkce",{"title":52,"icon":53,"path":54,"stem":55,"children":56,"page":22},"Developer platform","i-lucide-blocks","\u002Fen\u002Fplatform","en\u002F4.platform",[57,61],{"title":58,"path":59,"stem":60},"Apps, versions, installations, and scopes","\u002Fen\u002Fplatform\u002Fapps-installations-scopes","en\u002F4.platform\u002F1.apps-installations-scopes",{"title":62,"path":63,"stem":64},"Origins, redirects, proxies, and environments","\u002Fen\u002Fplatform\u002Fsecurity-and-environments","en\u002F4.platform\u002F2.security-and-environments",{"title":66,"icon":67,"path":68,"stem":69,"children":70,"page":22},"Runtime extensions","i-lucide-workflow","\u002Fen\u002Fruntime","en\u002F5.runtime",[71,75,79],{"title":72,"path":73,"stem":74},"Installation Webhooks","\u002Fen\u002Fruntime\u002Fwebhooks","en\u002F5.runtime\u002F1.webhooks",{"title":76,"path":77,"stem":78},"Inventory synchronization","\u002Fen\u002Fruntime\u002Finventory-sync","en\u002F5.runtime\u002F2.inventory-sync",{"title":80,"path":81,"stem":82},"Automatic fulfillment providers","\u002Fen\u002Fruntime\u002Fauto-fulfillment","en\u002F5.runtime\u002F3.auto-fulfillment",{"title":84,"icon":85,"path":86,"stem":87,"children":88,"page":22},"API reference","i-lucide-braces","\u002Fen\u002Freference","en\u002F6.reference",[89,93,97],{"title":90,"path":91,"stem":92},"API Reference","\u002Fen\u002Freference\u002Fapi","en\u002F6.reference\u002F1.api",{"title":94,"path":95,"stem":96},"Errors, idempotency, and rate limits","\u002Fen\u002Freference\u002Ferrors-and-limits","en\u002F6.reference\u002F2.errors-and-limits",{"title":98,"path":99,"stem":100,"children":101,"page":22},"Endpoint catalog","\u002Fen\u002Freference\u002Foperations","en\u002F6.reference\u002F3.operations",[102,106,110,114,118,122,126,130,134,138,142,146,150,154,158,162,166,170,174,178],{"title":103,"path":104,"stem":105},"Get the public runtime configuration","\u002Fen\u002Freference\u002Foperations\u002Fget-public-runtime-config","en\u002F6.reference\u002F3.operations\u002F01.get-public-runtime-config",{"title":107,"path":108,"stem":109},"Get the public site bootstrap configuration","\u002Fen\u002Freference\u002Foperations\u002Fget-public-bootstrap","en\u002F6.reference\u002F3.operations\u002F02.get-public-bootstrap",{"title":111,"path":112,"stem":113},"Get public contact channels","\u002Fen\u002Freference\u002Foperations\u002Fget-public-contact","en\u002F6.reference\u002F3.operations\u002F03.get-public-contact",{"title":115,"path":116,"stem":117},"List current published legal documents by locale","\u002Fen\u002Freference\u002Foperations\u002Flist-public-legal-documents","en\u002F6.reference\u002F3.operations\u002F04.list-public-legal-documents",{"title":119,"path":120,"stem":121},"Get the published Storefront decoration","\u002Fen\u002Freference\u002Foperations\u002Fget-public-storefront-decoration","en\u002F6.reference\u002F3.operations\u002F05.get-public-storefront-decoration",{"title":123,"path":124,"stem":125},"Get the public store security configuration","\u002Fen\u002Freference\u002Foperations\u002Fget-public-store-security-config","en\u002F6.reference\u002F3.operations\u002F06.get-public-store-security-config",{"title":127,"path":128,"stem":129},"Search public products","\u002Fen\u002Freference\u002Foperations\u002Fsearch-public-products","en\u002F6.reference\u002F3.operations\u002F07.search-public-products",{"title":131,"path":132,"stem":133},"List public categories","\u002Fen\u002Freference\u002Foperations\u002Flist-public-categories","en\u002F6.reference\u002F3.operations\u002F08.list-public-categories",{"title":135,"path":136,"stem":137},"Get the installation credential identity","\u002Fen\u002Freference\u002Foperations\u002Fget-installation-credential-identity","en\u002F6.reference\u002F3.operations\u002F09.get-installation-credential-identity",{"title":139,"path":140,"stem":141},"Get the installation credential readiness","\u002Fen\u002Freference\u002Foperations\u002Fget-installation-credential-readiness","en\u002F6.reference\u002F3.operations\u002F10.get-installation-credential-readiness",{"title":143,"path":144,"stem":145},"List the public product catalog","\u002Fen\u002Freference\u002Foperations\u002Flist-public-products","en\u002F6.reference\u002F3.operations\u002F11.list-public-products",{"title":147,"path":148,"stem":149},"Get a public product by slug","\u002Fen\u002Freference\u002Foperations\u002Fget-public-product","en\u002F6.reference\u002F3.operations\u002F12.get-public-product",{"title":151,"path":152,"stem":153},"Get a public store profile","\u002Fen\u002Freference\u002Foperations\u002Fget-public-merchant","en\u002F6.reference\u002F3.operations\u002F13.get-public-merchant",{"title":155,"path":156,"stem":157},"List public products for a store","\u002Fen\u002Freference\u002Foperations\u002Flist-public-merchant-products","en\u002F6.reference\u002F3.operations\u002F14.list-public-merchant-products",{"title":159,"path":160,"stem":161},"List public categories for a store","\u002Fen\u002Freference\u002Foperations\u002Flist-public-merchant-categories","en\u002F6.reference\u002F3.operations\u002F15.list-public-merchant-categories",{"title":163,"path":164,"stem":165},"Get a public product for a store","\u002Fen\u002Freference\u002Foperations\u002Fget-public-merchant-product","en\u002F6.reference\u002F3.operations\u002F16.get-public-merchant-product",{"title":167,"path":168,"stem":169},"Get the current API Key identity and scopes","\u002Fen\u002Freference\u002Foperations\u002Fget-api-key-identity","en\u002F6.reference\u002F3.operations\u002F17.get-api-key-identity",{"title":171,"path":172,"stem":173},"List public categories with an API Key","\u002Fen\u002Freference\u002Foperations\u002Flist-api-key-catalog-categories","en\u002F6.reference\u002F3.operations\u002F18.list-api-key-catalog-categories",{"title":175,"path":176,"stem":177},"List public products with an API Key","\u002Fen\u002Freference\u002Foperations\u002Flist-api-key-catalog-products","en\u002F6.reference\u002F3.operations\u002F19.list-api-key-catalog-products",{"title":179,"path":180,"stem":181},"Get a public product with an API Key","\u002Fen\u002Freference\u002Foperations\u002Fget-api-key-catalog-product","en\u002F6.reference\u002F3.operations\u002F20.get-api-key-catalog-product",{"title":183,"icon":184,"path":185,"stem":186,"children":187,"page":22},"Examples","i-lucide-code-xml","\u002Fen\u002Fexamples","en\u002F7.examples",[188,192],{"title":189,"path":190,"stem":191},"Minimal Nuxt Storefront","\u002Fen\u002Fexamples\u002Fnuxt-storefront","en\u002F7.examples\u002F1.nuxt-storefront",{"title":193,"path":194,"stem":195},"Webhook verification","\u002Fen\u002Fexamples\u002Fwebhook-verification","en\u002F7.examples\u002F2.webhook-verification",{"title":197,"icon":198,"path":199,"stem":200,"children":201,"page":22},"Versions and support","i-lucide-life-buoy","\u002Fen\u002Foperations","en\u002F8.operations",[202,206],{"title":203,"path":204,"stem":205},"Versions, migrations, and changelog","\u002Fen\u002Foperations\u002Fversions-and-migrations","en\u002F8.operations\u002F1.versions-and-migrations",{"title":207,"path":208,"stem":209},"Support and security disclosure","\u002Fen\u002Foperations\u002Fsupport-and-security","en\u002F8.operations\u002F2.support-and-security",{"id":211,"title":19,"body":212,"description":627,"extension":628,"links":629,"meta":630,"navigation":631,"path":20,"seo":632,"stem":21,"__hash__":633},"docs_en\u002Fen\u002F1.getting-started\u002F3.enterprise-integration.md",{"type":213,"value":214,"toc":610},"minimark",[215,236,241,244,304,308,313,333,339,343,348,351,356,360,365,377,383,389,393,398,412,415,419,424,427,440,445,449,454,471,506,510,515,518,522,527,530,542,546,551,554,559,563,568,588,592,597,600,603,607],[216,217,218,219,223,224,227,228,231,232,235],"p",{},"This is a go-live decision path, not an endpoint catalog. Every stage distinguishes ",[220,221,222],"strong",{},"Available",", ",[220,225,226],{},"Platform enablement required",", and ",[220,229,230],{},"Not yet available",". Only operations sourced from the public-only artifact in the ",[233,234,84],"a",{"href":91}," are available.",[237,238,240],"h2",{"id":239},"current-authoritative-blocker-snapshot","Current authoritative blocker snapshot",[216,242,243],{},"The API public-only artifact declares five blockers. They explain why capabilities remain unavailable; they do not imply that an endpoint exists:",[245,246,247,260],"table",{},[248,249,250],"thead",{},[251,252,253,257],"tr",{},[254,255,256],"th",{},"Capability",[254,258,259],{},"Current blocker",[261,262,263,272,280,288,296],"tbody",{},[251,264,265,269],{},[266,267,268],"td",{},"OAuth Authorization Code",[266,270,271],{},"DPoP and resource\u002Finstallation binding are still required",[251,273,274,277],{},[266,275,276],{},"Installation write API",[266,278,279],{},"A sender-constrained installation credential is still required",[251,281,282,285],{},[266,283,284],{},"Orders API",[266,286,287],{},"A tenant-isolated public order contract is still required",[251,289,290,293],{},[266,291,292],{},"Webhook subscription API",[266,294,295],{},"An installation-bound credential is still required",[251,297,298,301],{},[266,299,300],{},"Production activation",[266,302,303],{},"External readiness has not been proven",[237,305,307],{"id":306},"_1-pre-integration-checks","1. Pre-integration checks",[216,309,310],{},[220,311,312],{},"Status: Available (assessment guidance); Platform enablement required (commercial and production eligibility).",[314,315,316,320,323,326],"ul",{},[317,318,319],"li",{},"Decide whether the use case needs anonymous catalog reads, server-side API Key reads, or user authorization\u002Fwrite capabilities that are not yet available.",[317,321,322],{},"Identify the data controller, end users, store\u002Fresource boundary, markets, and retention obligations.",[317,324,325],{},"Assign technical, security, and incident contacts; define responses for credential exposure, rate limiting, and unknown write outcomes.",[317,327,328,329,332],{},"Keep the current implementation scope to the ",[233,330,331],{"href":91},"20 available operations",".",[216,334,335,338],{},[220,336,337],{},"Proceed when:"," every required capability has a public Reference or a written enablement path from the platform. Otherwise stop; do not infer APIs from console traffic or the mixed OpenAPI candidate.",[237,340,342],{"id":341},"_2-request-an-app-and-environment","2. Request an app and environment",[216,344,345],{},[220,346,347],{},"Status: Platform enablement required.",[216,349,350],{},"Apps, environments, API Keys, installations, production eligibility, and associated capabilities are configured or approved by Ayalink. There is no public application-management endpoint. Provide the app name, use case, required markets, callback domains, technical\u002Fsecurity contacts, and a least-privilege justification. Receive secrets only through the approved secure delivery path.",[216,352,353,355],{},[220,354,337],{}," the target environment, allowed capabilities, credential delivery, and rotation instructions are explicit. A documentation page, client ID, or successful CORS request is not production authorization.",[237,357,359],{"id":358},"_3-official-authorization-domain-and-pkce","3. Official authorization domain and PKCE",[216,361,362],{},[220,363,364],{},"Status: Not yet available (OAuth endpoints); security model is published.",[216,366,367,368,372,373,376],{},"When user authorization is required, send users only to the official Ayalink authorization domain confirmed in platform enablement materials. Use Authorization Code with PKCE S256, exact redirect URIs, and fresh validated ",[369,370,371],"code",{},"state"," and ",[369,374,375],{},"nonce"," values. A third party must never proxy or imitate sign-in or collect passwords\u002FMFA.",[216,378,379,380,332],{},"The current public-only artifact contains no authorization, token exchange, revocation, or grant-management endpoint and explicitly blocks release on DPoP plus resource\u002Finstallation binding. This site therefore publishes no URL, scope, curl command, or successful response. See the ",[233,381,382],{"href":49},"OAuth and account security boundary",[216,384,385,388],{},[220,386,387],{},"Stop when:"," the official domain, client configuration, or exact redirect URI has not been confirmed by the platform. Do not implement an OAuth redirect or token exchange.",[237,390,392],{"id":391},"_4-token-security-and-bff","4. Token security and BFF",[216,394,395],{},[220,396,397],{},"Status: Available (security architecture guidance); Platform enablement required (real grants); Not yet available (unconfirmed capabilities such as DPoP and rotation).",[216,399,400,401,223,404,407,408,411],{},"Browsers must not hold a client secret or place access\u002Frefresh tokens in URLs, persistent browser storage, logs, analytics, or error reports. For browser sessions, use a same-origin BFF. It stores only its own app grant and issues its own ",[369,402,403],{},"HttpOnly",[369,405,406],{},"Secure",", appropriately ",[369,409,410],{},"SameSite"," session Cookie. It never accepts or forwards the global Ayalink Cookie.",[216,413,414],{},"Confirm token audience, resource boundaries, lifetime, rotation, and revocation from enablement materials. Do not assume DPoP, refresh-token rotation, or replay detection is available.",[237,416,418],{"id":417},"_5-call-an-available-api","5. Call an available API",[216,420,421],{},[220,422,423],{},"Status: Available (11 read-only operations).",[216,425,426],{},"The Reference currently contains seven anonymous catalog reads and four API Key identity\u002Fcatalog reads. Use the real method, path, authentication, parameters, and response schema on each operation page. Do not copy or guess a Base URL from this guide; obtain the runtime address from platform enablement materials.",[314,428,429,434,437],{},[317,430,431,332],{},[233,432,433],{"href":91},"Browse the available API catalog",[317,435,436],{},"Keep API Keys in an approved server-side header, never in a browser bundle or URL.",[317,438,439],{},"Send only parameters declared by the Reference; do not invent examples for missing schemas.",[216,441,442,444],{},[220,443,337],{}," the target operation is in the current catalog and its authentication has been enabled. Installation identity\u002Freadiness reads are available; writes, OAuth, installation writes, and Webhook management are not among these 20 operations.",[237,446,448],{"id":447},"_6-pagination-errors-requestid-and-429","6. Pagination, errors, requestId, and 429",[216,450,451],{},[220,452,453],{},"Status: Available (subject to each operation's public contract).",[216,455,456,457,223,460,223,463,466,467,470],{},"Implement pagination parameters, cursors, and response shapes only when the operation page declares them. If the spec is silent, do not assume ",[369,458,459],{},"page",[369,461,462],{},"limit",[369,464,465],{},"cursor",", or a total count. Branch on HTTP status and stable machine codes, not human-readable text. Preserve any ",[369,468,469],{},"requestId"," or correlation identifier actually returned for support and reconciliation. If its field\u002Fheader is not declared, follow platform materials rather than inventing one.",[216,472,473,474,477,478,481,482,223,485,223,488,223,491,223,494,223,497,227,499,502,503,332],{},"For ",[369,475,476],{},"429",", honor ",[369,479,480],{},"Retry-After"," only when the response actually provides it; otherwise use bounded exponential backoff with jitter and a retry budget. Recovery boundaries for ",[369,483,484],{},"401",[369,486,487],{},"403",[369,489,490],{},"404",[369,492,493],{},"409\u002F412",[369,495,496],{},"422",[369,498,476],{},[369,500,501],{},"5xx"," are in ",[233,504,505],{"href":95},"errors, idempotency, and rate limits",[237,507,509],{"id":508},"_7-idempotency-and-unknown-outcomes","7. Idempotency and unknown outcomes",[216,511,512],{},[220,513,514],{},"Status: Available operations are GET and require no write idempotency key; installation writes and the Orders API are not yet available.",[216,516,517],{},"The current 20 reads may use bounded safe retries while respecting rate limits. A future write operation can be integrated only after a new public-only artifact defines its idempotency requirement, key location, conflict, and lookup semantics. Treat a timed-out or disconnected write as unknown: query or reconcile before choosing the next action; never replay blindly.",[237,519,521],{"id":520},"_8-webhook-signing-replay-protection-and-retries","8. Webhook signing, replay protection, and retries",[216,523,524],{},[220,525,526],{},"Status: Platform enablement required (subscription and secret); Not yet available (the subscription-management endpoint still requires an installation-bound credential); verification and recovery guidance is published.",[216,528,529],{},"The receiver verifies HMAC over the raw body with the timestamp and signature material declared by the platform, uses constant-time comparison, enforces the accepted time window, and atomically deduplicates the event ID. Do not parse JSON before the signature passes. During rotation, accept a current\u002Fprevious key window only when the platform explicitly allows it.",[216,531,532,533,535,536,372,539,332],{},"Delivery retry counts, time windows, header names, and dead-letter behavior come from enablement materials. Local processing uses bounded backoff, honors an actually received ",[369,534,480],{},", retains the original event ID, and keeps business effects idempotent. See the ",[233,537,538],{"href":73},"Webhook guide",[233,540,541],{"href":194},"verification example",[237,543,545],{"id":544},"_9-test-and-accept","9. Test and accept",[216,547,548],{},[220,549,550],{},"Status: Available (static contract tests); Platform enablement required (real environment integration).",[216,552,553],{},"Cover successful reads, empty results, invalid\u002Frevoked credentials, authorization denial, missing resources, validation errors, 429, 5xx\u002Fdisconnects, pagination boundaries, and log redaction. For Webhooks, also cover invalid signatures, expired timestamps, duplicate and out-of-order events, retries, and secret rotation. Never use production secrets or real personal data in tests.",[216,555,556,558],{},[220,557,337],{}," contract tests use the current artifact; environment tests record requestId, time, operationId, and redacted results; every unknown outcome can be reconciled or stopped safely.",[237,560,562],{"id":561},"_10-production-go-live-checks","10. Production go-live checks",[216,564,565],{},[220,566,567],{},"Status: Platform enablement required; external readiness has not been proven.",[314,569,570,573,576,579,585],{},[317,571,572],{},"The platform has confirmed the production app\u002Fenvironment, allowed capabilities, markets, and credential status.",[317,574,575],{},"Base URL, authorization domain, redirect URIs, audience, scopes, and Webhook parameters come from platform materials, not documentation guesses.",[317,577,578],{},"Credentials are in a secret manager; logging, monitoring, alerting, rotation, rate-limit budgets, and incident contacts are ready.",[317,580,581,582,584],{},"Recheck the current ",[233,583,90],{"href":91}," source version and change notes before production.",[317,586,587],{},"Canary, rollback, and stop conditions have owners. Test success does not equal production approval.",[237,589,591],{"id":590},"_11-revocation-and-incident-response","11. Revocation and incident response",[216,593,594],{},[220,595,596],{},"Status: Platform enablement required (revocation entry point and support); security response guidance is published.",[216,598,599],{},"For an exposed token\u002FAPI Key\u002FWebhook secret, abnormal traffic, a phishing authorization page, or suspected cross-boundary access: stop affected traffic, isolate the leak, revoke or rotate credentials through the approved platform entry point, preserve requestId, operationId, time range, and redacted logs, and contact the official security channel. Never paste tokens, Cookies, or full payloads into a ticket.",[216,601,602],{},"Before resuming, prove old credentials are invalid, consumers are updated, duplicate events\u002Funknown writes are reconciled, the root cause is fixed, and the production checklist has been repeated. No self-service revocation endpoint is public today; do not guess a URL or treat deleting a local Cookie as revoking a grant.",[237,604,606],{"id":605},"automatic-reference-expansion","Automatic Reference expansion",[216,608,609],{},"When a later API public-only artifact arrives, the importer verifies its source commit, hash, operationId, security schemes, and internal boundaries before generating additional bilingual endpoint pages. This guide updates availability only from real artifacts; it does not wait for a full catalog or hand-write endpoints, scopes, or responses.",{"title":611,"searchDepth":612,"depth":612,"links":613},"",2,[614,615,616,617,618,619,620,621,622,623,624,625,626],{"id":239,"depth":612,"text":240},{"id":306,"depth":612,"text":307},{"id":341,"depth":612,"text":342},{"id":358,"depth":612,"text":359},{"id":391,"depth":612,"text":392},{"id":417,"depth":612,"text":418},{"id":447,"depth":612,"text":448},{"id":508,"depth":612,"text":509},{"id":520,"depth":612,"text":521},{"id":544,"depth":612,"text":545},{"id":561,"depth":612,"text":562},{"id":590,"depth":612,"text":591},{"id":605,"depth":612,"text":606},"An end-to-end path from readiness and platform enablement through authorization, API use, Webhooks, testing, production, and emergency revocation.","md",null,{},true,{"title":19,"description":627},"pCs1CKGZYJ2GNqQw4nOHmnELb9-Rf0OuA6kj4LvV8dk",[635,637],{"title":15,"path":16,"stem":17,"description":636,"children":-1},"Understand the public documentation, platform, store, installation, user, and provider trust boundaries.",{"title":30,"path":31,"stem":32,"description":638,"children":-1},"Build an independent storefront while preserving Ayalink identity, access policy, cache, and challenge boundaries.",1785955320476]