Skip to main content
The reference includes every merchant-key operation. It also includes the protected key lifecycle that requires a Customer session.

Select a server

The host, key, and merchant must belong to the same environment.

Authenticate the request

Merchant operations use:
/v1/api-keys operations use a Customer session and step-up for credential mutations. An API key cannot manage itself.

Download the contract

The bundle excludes auth, onboarding, backoffice, Customer routes, and Zuplo routing metadata. Each operation declares a unique operationId, scopes, request schemas, responses, security, and owner tag.
Repository checks fail when the bundle, manifest, and gateway contract diverge.
Last modified on August 22, 2026