VTEX OAuth Flow API

The OAuth Flow API from VTEX — 4 operation(s) for oauth flow.

Operations 4

POST /authorization/token VTex 1. Retrieve Token #
GET /redirect VTex 2. Redirect #
GET /authorizationCode 3. Return to VTEX #
GET /authorization/credentials VTex 4. Get Credentials #

Documentation

📖
Documentation
https://developers.vtex.com/docs/guides/how-the-integration-protocol-between-vtex-and-antifraud-companies-works
📖
Documentation
https://developers.vtex.com/docs/guides/bulk-import-buyer-organizations-spreadsheet
📖
Documentation
https://developers.vtex.com/docs/guides/catalog-api-seller-portal-overview
📖
Documentation
https://developers.vtex.com/docs/guides/catalog-overview
📖
Documentation
https://developers.vtex.com/docs/guides/checkout-overview
📖
Documentation
https://help.vtex.com/en/tutorial/customer-credit-overview--1uIqTjWxIIIEW0COMg4uE0
📖
Documentation
https://help.vtex.com/en/tutorial/data-subject-rights--6imchxTx09icupKMbzHVIM
📖
Documentation
https://developers.vtex.com/docs/api-reference/do-api
📖
Documentation
https://developers.vtex.com/docs/guides/managing-vtex-gift-cards
📖
Documentation
https://developers.vtex.com/docs/guides/gift-card-integration-guide
📖
Documentation
https://developers.vtex.com/docs/guides/faststore/headless-cms-overview
📖
Documentation
https://developers.vtex.com/docs/api-reference/vtex-id-api
📖
Documentation
https://help.vtex.com/en/tracks/vtex-intelligent-search--19wrbB7nEQcmwzDPl1l4Cb/3qgT47zY08biLP3d5os3DG
📖
Documentation
https://developers.vtex.com/docs/apps/vtex.search@1.0.8
📖
Documentation
https://help.vtex.com/en/tracks/cms--2YcpgIljVaLVQYMzxQbc3z/1oN446gRGcR2s70RvBCAmj
📖
Documentation
https://developers.vtex.com/docs/guides/search-overview
📖
Documentation
https://help.vtex.com/en/tutorial/license-manager-resources--3q6ztrC8YynQf6rdc6euk3
📖
Documentation
https://developers.vtex.com/docs/guides/fulfillment
📖
Documentation
https://developers.vtex.com/docs/guides/marketplace-overview
📖
Documentation
https://developers.vtex.com/updates/release-notes/marketplace-protocol-documentation-update
📖
Documentation
https://developers.vtex.com/docs/guides/external-marketplace-integration-guide
📖
Documentation
https://developers.vtex.com/docs/guides/external-seller-integration-connector
📖
Documentation
https://developers.vtex.com/docs/guides/external-seller-integration-guide
📖
Documentation
https://help.vtex.com/en/tutorial/master-data--4otjBnR27u4WUIciQsmkAw
📖
Documentation
https://help.vtex.com/en/tutorial/understanding-the-message-center--tutorials_84
📖
Documentation
https://developers.vtex.com/docs/guides/orders-overview
📖
Documentation
https://developers.vtex.com/docs/guides/changes-in-vtex-features-behavior-to-handle-pii-data
📖
Documentation
https://help.vtex.com/en/tutorial/payment-provider-protocol--RdsT2spdq80MMwwOeEq0m
📖
Documentation
https://developers.vtex.com/docs/guides/payments-integration-guide
📖
Documentation
https://help.vtex.com/en/tutorial/vtex-pick-and-pack-last-mile--HN7WKV0xoq2ssVjsJlfzr
📖
Documentation
https://developers.vtex.com/docs/guides/vtex-io-documentation-policies
📖
Documentation
https://developers.vtex.com/docs/guides/pricing-hub
📖
Documentation
https://developers.vtex.com/docs/guides/pricing-overview
📖
Documentation
https://developers.vtex.com/docs/guides/profile-system
📖
Documentation
https://developers.vtex.com/docs/guides/promotions-overview
📖
Documentation
https://developers.vtex.com/docs/apps/vtex.reviews-and-ratings
📖
Documentation
https://developers.vtex.com/docs/guides/sent-offers-integration-guide-connectors
📖
Documentation
https://developers.vtex.com/docs/guides/sessions-system-overview
📖
Documentation
https://developers.vtex.com/docs/guides/vtex-shipping-network
📖
Documentation
https://help.vtex.com/en/tutorial/sku-bindings--1SmrVgNwjJX17hdqwLa0TX
📖
Documentation
https://developers.vtex.com/docs/guides/subscriptions
📖
Documentation
https://developers.vtex.com/docs/apps/vtex.search/suggestions
📖
Documentation
https://developers.vtex.com/docs/guides/vtex-tracking

Specifications

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/vtex-oauth-flow-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

vtex-oauth-flow-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: VTex Anti-fraud Provider OAuth Flow API
  description: '>ℹ️ Onboarding guide

    >

    > Check the new Payments onboarding guide.'
  version: '1.0'
servers:
- url: https://{providerApiEndpoint}
  description: Anti-fraud provider endpoint URL.
  variables:
    providerApiEndpoint:
      description: Anti-fraud provider endpoint URL.
      default: '{providerApiEndpoint}'
tags:
- name: OAuth Flow
paths:
  /authorization/token:
    post:
      tags:
      - OAuth Flow
      summary: VTex 1. Retrieve Token
      description: 'This endpoint is used to retrieve a payment provider token.


        ## Permissions


        This endpoint does not require permissions.'
      operationId: 1.RetrieveToken
      parameters:
      - $ref: '#/components/parameters/X-PROVIDER-API-AppKey'
      - $ref: '#/components/parameters/X-PROVIDER-API-AppToken'
      - $ref: '#/components/parameters/Content-Type'
      - $ref: '#/components/parameters/Accept'
      security:
      - VtexIdclientAutCookie: []
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/1.RetrieveTokenRequest'
        required: true
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/1.RetrieveToken'
              example:
                applicationId: vtex
                token: 358a5bea-07d0-4122-888a-54ab70b5f02f
      deprecated: false
  /redirect:
    get:
      tags:
      - OAuth Flow
      summary: VTex 2. Redirect
      description: 'Through this endpoint, VTEX will redirect the store administrator to the Payment provider website using the `token` retrieved in the previous request.


        At this point in the flow, the provider shows the login site to the store admin and authorizes VTEX to use its integration as a valid Payment Provider Processor. After that, your server generates an `authorizationCode`.


        ## Permissions


        This endpoint does not require permissions.'
      operationId: 2.Redirect
      parameters:
      - name: token
        in: query
        description: Token information.
        required: true
        style: form
        schema:
          type: string
          example: '{token}'
      - name: applicationId
        in: query
        description: VTEX application identifier.
        required: true
        style: form
        schema:
          type: string
          example: vtex
      - $ref: '#/components/parameters/X-PROVIDER-API-AppKey'
      - $ref: '#/components/parameters/X-PROVIDER-API-AppToken'
      - $ref: '#/components/parameters/Content-Type'
      - $ref: '#/components/parameters/Accept'
      security:
      - VtexIdclientAutCookie: []
      responses:
        '200':
          description: OK. This endpoint does not return any data in the response body.
      deprecated: false
  /authorizationCode:
    get:
      tags:
      - OAuth Flow
      summary: 3. Return to VTEX
      description: 'Through this endpoint, the provider will redirect the store administrator to the VTEX website using the `returnUrl` passed from VTEX to create token.


        The `returnUrl` must be filled with your query string **authorizationCode**.


        Example:


        If you receive the following URL:


        `https://store.vtex.com/return?authorizationCode=&otherparams...`


        and your **authorizationCode** is `pro2018`. Then, you redirect the store administrator to: `https://store.vtex.com/return?authorizationCode=pro2018&otherparams...`.


        ## Permissions


        This endpoint does not require permissions.'
      operationId: 3.ReturntoVTEX
      parameters:
      - name: providerAuthorizationCode
        in: query
        description: Provider authorization code information.
        required: true
        style: form
        explode: true
        schema:
          type: string
          example: '{providerAuthorizationCode}'
      - $ref: '#/components/parameters/X-PROVIDER-API-AppKey'
      - $ref: '#/components/parameters/X-PROVIDER-API-AppToken'
      security:
      - VtexIdclientAutCookie: []
      responses:
        '200':
          description: OK. This endpoint does not return any data in the response body.
      deprecated: false
  /authorization/credentials:
    get:
      tags:
      - OAuth Flow
      summary: VTex 4. Get Credentials
      description: 'Retrieves merchant credentials.


        ## Permissions


        This endpoint does not require permissions.'
      operationId: 4.GetCredentials
      parameters:
      - name: authorizationCode
        in: query
        description: Code generate by affiliation that will be used to identify the merchant authorization.
        required: true
        style: form
        explode: true
        schema:
          type: string
          example: '{authorizationCode}'
      - name: applicationId
        in: query
        description: VTEX application identifier.
        required: true
        style: form
        explode: true
        schema:
          type: string
          example: vtex
      - $ref: '#/components/parameters/X-PROVIDER-API-AppKey'
      - $ref: '#/components/parameters/X-PROVIDER-API-AppToken'
      security:
      - VtexIdclientAutCookie: []
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/3.GetCredentials'
              example:
                applicationId: vtex
                appKey: c5a5e3f1-4a77-4a00-8b53-0d1adb3e9628
                appToken: 57ea254d-f3d3-488d-88d7-129766037ed1
      deprecated: false
components:
  schemas:
    1.RetrieveToken:
      required:
      - applicationId
      - token
      type: object
      properties:
        applicationId:
          type: string
          description: This value is always identified as `vtex`.
        token:
          type: string
          description: Payment Provider Token. Used to identify the context after you receive the redirected user to your site.
      example:
        applicationId: vtex
        token: 358a5bea-07d0-4122-888a-54ab70b5f02f
    1.RetrieveTokenRequest:
      required:
      - applicationId
      - returnUrl
      type: object
      properties:
        applicationId:
          type: string
          description: This value is always identified as `vtex`.
        returnUrl:
          type: string
          description: VTEX website URL. You will redirect the user after they complete login on the payment provider's website. The URL should contain a query string parameter called `authorizationCode` which will be passed empty and which you must fill in before returning the user.
      example:
        applicationId: vtex
        returnUrl: https://storevtex.vtexpayments.com/?authorizationCode=
    3.GetCredentials:
      required:
      - applicationId
      - appKey
      - appToken
      type: object
      properties:
        applicationId:
          type: string
          description: This value is always identified as `vtex`.
        appKey:
          type: string
          description: It will be used in all API requests as X-VTEX-API-AppKey.
        appToken:
          type: string
          description: It will be used in all API requests as X-VTEX-API-AppToken.
      example:
        applicationId: vtex
        appKey: c5a5e3f1-4a77-4a00-8b53-0d1adb3e9628
        appToken: 57ea254d-f3d3-488d-88d7-129766037ed1
  parameters:
    Content-Type:
      name: Content-Type
      in: header
      description: Type of the content being sent.
      required: true
      style: simple
      schema:
        type: string
        example: application/json
    X-PROVIDER-API-AppKey:
      name: X-PROVIDER-API-AppKey
      in: header
      description: Unique identifier created by the provider and configured on the provider configuration page (Admin VTEX).
      required: true
      style: simple
      schema:
        type: string
        example: '{{X-PROVIDER-API-AppKey}}'
    Accept:
      name: Accept
      in: header
      description: HTTP Client Negotiation _Accept_ Header. Indicates the types of responses the client can understand.
      required: true
      style: simple
      schema:
        type: string
        example: application/json
    X-PROVIDER-API-AppToken:
      name: X-PROVIDER-API-AppToken
      in: header
      description: Unique token created by the provider and configured on the provider configuration page (Admin VTEX).
      required: true
      style: simple
      schema:
        type: string
        example: '{{X-PROVIDER-API-AppToken}}'
  securitySchemes:
    VtexIdclientAutCookie:
      type: apiKey
      in: header
      name: VtexIdclientAutCookie
      description: '[User token](https://developers.vtex.com/docs/guides/api-authentication-using-user-tokens), valid for 24 hours.'