# Rules for your integration

Every integration, and the AI coding assistant building it, must follow these rules.

1. All calls MUST be made from your backend server. Never put your API key in browser
   JavaScript, a mobile app, or a public repository.
2. Never construct the checkout URL yourself. Always use the `buyLink` string from the most
   recent cart response, verbatim. This holds with or without CJ.
3. Money is always an integer in minor units (cents for USD). See [Conventions](/docs/conventions.md).
4. Treat cursor values as opaque. Send them back exactly as received, URL-encoded.
5. Send identical query parameters on every page of one products walk. Only `cursor` changes.
6. Read error codes with one helper. See [Handling errors](/docs/handling-errors.md).
7. Do not blind-retry adding items to a cart. It adds quantity, so a retry can double it. On a
   timeout, read the cart and reconcile.
8. Only US inventory is exposed: every deal the API returns is a US deal. Always send
   `country=US`.
9. Send your own `User-Agent` header on every request, for example
   `MyStore/1.0 (+https://mystore.example)`. A generic client default is rejected.
10. Never share an API key between storefronts. A key acts as the storefront that created it.
11. Revoke a key you no longer use, from the storefront's key list in this portal.
