Partner API overview
An API for external apps that connect to Toreca Cloud over OAuth to read buy boosts and stock.
The partner API is for external apps a shop has approved: apps that put buy boosts on a landing page or an X post, and oripa services or business systems that sync stock.
An app calls the API with a token issued when a shop member approves it in the browser. No API keys are shared. The token decides which shop’s data the app reads; a request can’t name another shop.
Basics
| Item | Value |
|---|---|
| Base URL | https://api.toreca-cloud.com/partner/v1 |
| Authorization | OAuth 2.1 authorization code flow (PKCE S256 required) |
| Client | A pre-registered confidential client (client_secret_basic) |
| Format | JSON; every response has Cache-Control: no-store |
What it offers
| Scope | Lets the app |
|---|---|
purchase-boosts:read |
Read the buy boost list. No stock is visible |
inventory:read |
Sync sites, storage locations and stock units |
inventory:write |
Hold and ship units it sold |
inventory:move |
Move between shelves and sites, take out and return |
Give landing page and posting apps purchase-boosts:read only. They get the buy boosts and never see a single unit of stock.
Getting started
The shop registers the app
A shop admin registers the app under Settings › Integrations: display name, redirect URI and what to allow. A client ID and client secret are issued. If the screen isn’t there, ask Toreca Cloud support to enable it.
A shop member approves
The app opens the authorization screen, and a shop member signs in and presses Allow. The app exchanges the authorization code for tokens (authorization).
Create the connection
Call POST /connection first. If the shop revokes it, later calls fail with
connection_revoked.
Call the API
Send the access token as a Bearer token. Store and refresh tokens as described in tokens and expiry.
Every endpoint is described in the API reference.

