openapi: 3.1.0
info:
title: ShopMy Partners Catalog OAuth API
version: '1.0'
description: The ShopMy Partners API lets Brand Partners and developer applications integrate with the ShopMy creator-commerce network. Brand Partners pull detailed affiliate order reports; OAuth developer applications act on behalf of authenticated ShopMy users to read and create product links, manage shelf collections, resolve/rate product URLs, search the catalog, and read public profile information. All requests must be made over HTTPS.
contact:
name: ShopMy Developer Support
email: developers@shopmy.us
url: https://docs.shopmy.us/
x-apievangelist:
method: searched
generated: '2026-07-21'
source: https://docs.shopmy.us/reference/getting-started-with-your-api
note: Derived faithfully from the ShopMy developer documentation at docs.shopmy.us (per-endpoint reference pages + embedded schema examples). Paths, methods, parameters, scopes and status codes are as published; not an official ShopMy-published OpenAPI file.
servers:
- url: https://api.shopmy.us/v1/Partners
description: Production
tags:
- name: OAuth
description: OAuth token exchange for developer applications.
paths:
/oauth-exchange-token:
post:
tags:
- OAuth
operationId: oauthExchangeToken
summary: OAuth Exchange Token
description: Exchange a one-time OAuth authorization code (shopmy_code) for a long-term access token. Token exchange can only be done once per user for security purposes; store the resulting access token securely.
security:
- developerKey: []
requestBody:
required: true
content:
application/json:
schema:
type: object
required:
- shopmy_code
properties:
shopmy_code:
type: string
description: The one-time authorization code from the OAuth redirect.
responses:
'200':
description: Access token issued.
'400':
$ref: '#/components/responses/BadRequest'
'401':
$ref: '#/components/responses/Unauthorized'
components:
responses:
Unauthorized:
description: 'Unauthorized. Example - "Missing required scopes: The user has not authorized you to perform this action."'
BadRequest:
description: Bad request.
securitySchemes:
developerKey:
type: http
scheme: bearer
description: 'Brand/developer key sent as `Authorization: Bearer <developer key>`. Found in Brand Account Settings under Tokens > Developer Key.'
accessToken:
type: apiKey
in: header
name: X-ACCESS-TOKEN
description: 'Per-user long-term OAuth access token sent as `X-ACCESS-TOKEN: Bearer <access token>`, obtained via the OAuth token exchange.'
oauth2:
type: oauth2
description: OAuth 2.0 authorization-code flow for acting on behalf of ShopMy users.
flows:
authorizationCode:
authorizationUrl: https://shopmy.us/oauth
tokenUrl: https://api.shopmy.us/v1/Partners/oauth-exchange-token
scopes:
read_links: View product links.
write_links: View and edit product links.
read_collections: View shelf collections.
write_collections: Create and edit collections.
read_profile: View public profile information.