Guides
View as MarkdownRules for your integration
Every integration, and the AI coding assistant building it, must follow these rules.
- All calls MUST be made from your backend server. Never put your API key in browser JavaScript, a mobile app, or a public repository.
- Never construct the checkout URL yourself. Always use the
buyLinkstring from the most recent cart response, verbatim. This holds with or without CJ. - Money is always an integer in minor units (cents for USD). See Conventions.
- Treat cursor values as opaque. Send them back exactly as received, URL-encoded.
- Send identical query parameters on every page of one products walk. Only
cursorchanges. - Read error codes with one helper. See Handling errors.
- Do not blind-retry adding items to a cart. It adds quantity, so a retry can double it. On a timeout, read the cart and reconcile.
- Only US inventory is exposed: every deal the API returns is a US deal. Always send
country=US. - Send your own
User-Agentheader on every request, for exampleMyStore/1.0 (+https://mystore.example). A generic client default is rejected. - Never share an API key between storefronts. A key acts as the storefront that created it.
- Revoke a key you no longer use, from the storefront's key list in this portal.