Wish OAuth API

The OAuth API from Wish — 3 operation(s) for oauth.

OpenAPI Specification

wish-oauth-api-openapi.yml Raw ↑
openapi: 3.0.0
info:
  contact:
    email: partner-api@wish.com
  x-wish-dev-contact:
    assignee: kwei
    email: marketplace-external-api@contextlogic.com
  description: "\nWish Marketplace V3 API\n\n# General Information\n\n The Wish Marketplace API will be using oAuth to authenticate in order to offer better security for its users\n\n *   Learn about oAuth [here](oauth).\n *   If you are a merchant and want to create an application for yourself, learn about how to create a private app [here](../../private-app)\n *   If you are a ERP and create applications that'll be used by multiple merchants, learn about how to create a public app [here]( ../../public-app). You will need to apply to be a verified public application\n\n ## How to Test\n\n To avoid testing the API on production data, use our sandbox. The sandbox is completely contained and will not affect Wish users or your merchant account. \n \n To reach the sandbox, visit: https://sandbox.merchant.wish.com.\n\n To use the sandbox in testing, use https://sandbox.merchant.wish.com/api/v3/ as your base URL.\n\n How to Generate test data after you have created a sandbox account:\n 1. Navigate to the [unfulfilled orders page](https://sandbox.merchant.wish.com/transactions/action)\n 2. Hover over the dropdown next to the 'fulfill with csv' button and select Generate Orders\n\n ## Date/Time Format\n\n  All dates and times in our API are returned in the same format. It is in the form `YYYY-MM-DDTHH:mm:ss.sss±XX:ZZ` or `YYYY-MM-DDTHH:mm:ss.sssZ`, where 'Z' represents UTC timezone.\n  When sending timestamps in URL parameters or the request body, millisecond is optional and will defaults to 0 if not provided.\n\n  * `YYYY` is the year\n  * `MM` is the month\n  * `DD` is the day\n  * `HH` is the hour (in 24-hour clock format)\n  * `mm` is the minutes\n  * `ss.sss` is the seconds and milliseconds\n  * `±XX:ZZ` is the UTC offset of the form +XX:ZZ or -XX:ZZ where XX is a 2-digit string giving the number of UTC offset hours, and ZZ is a 2-digit string giving the number of UTC offset minutes.\n\n ## Response Schema\n\n  Every response returned from the Wish API will have the same schema. This schema is intended to give you a predictable manner to check the status of your request and know where to get the data. Each response will have the following top level attributes: message, code and data.\n\n  **Attributes**\n\n  <table>\n  <tbody>\n  <tr>\n  <th>Message</th>\n  <td>A message describing the error that happened, example: \"We could not find a product for id: '5d30f60e0a6fc464f4f376b0'\"</td>\n  </tr>\n  <tr>\n  <th>Code</th>\n  <td>A unique number which represents the error that has occurred, example: 1008 or 0 if success.</td>\n  </tr>\n  <tr>\n  <th>Data</th>\n  <td>For errors this will be empty.</td>\n  </tr>\n  </tbody>\n  </table>\n\n ## General Querying Techniques\n\n ### Partial Resources\n All GET endpoints (except OAuth) support a fields parameter which allows for requesting a partial response. Any fields specified in the response schema of an endpoint can be selected. The top level attribute `data` can be ignored when using the fields parameter.\n\n **Syntax**\n * Comma-separated list to select multiple fields\n * Use forward slash `/` to select nested field: `field1/nested_field`\n * Use parentheses `( )` to select multiple nested fields: `field1(nested_field1,nested_field2)`\n * Use `*` for wildcard selection: `field1/nested_field/*`\n\n\n **Example:**\n ```\n https://merchant.wish.com/api/v3/demo/get?fields=title,items(id,info/name)\n ```\n Which would result in the following partial response:\n ```\n {\n   \"title\": \"demo\",\n   \"items\": [\n     {\n       \"id\": \"1\",\n       \"info\": {\n         \"name\": \"demo_item_1\"\n       }\n     }, {\n       \"id\": \"2\",\n       \"info\": {\n         \"name\": \"demo_item_2\"\n       }\n     },\n     ...\n   ]\n }\n ```\n\n ## Locale\n   You can optionally specify locale in order to translate content and error messages into your language.\n   To do this use the [Accept-Language](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Accept-Language) header to specify your preferred locales.\n   If none is provided, your default locale will be used.\n\n   For example, to request content in Chinese use: `Accept-Language: zh`\n\n   In the response, you will receive a [Content-Language](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Language) header that specifies the locale code of the response content.\n\n\n ## Rate-Limiting\n\n  Rate-limiting will be performed on a per-merchant basis for each app. It is your responsibility to ensure you are not making frequent unnecessary calls to the API.\n\n  If the rate limits cannot satisfy your need, we highly recommend integrating webhooks for your app. With webhooks, instead of pulling resources periodically, your app will receive real-time notifications for particular events that occur to a merchant’s store. [Learn more](https://merchant.wish.com/documentation/webhooks)\n\n  **Normal Usage**\n\n  To help you track the rate-limiter status, the following response header(s) will be provided with each response:\n\n   * `Wish-Rate-Limit-Remaining`: The number of calls remaining in the current rate-limiting window.\n\n\n  **Rate-Limit Exceeded**\n\n  After you exceed the number of allowed calls in the current rate-limiting window, you will receive a `429 Too Many Requests` error response and the following additional header(s):\n\n   * `Wish-Rate-Limit-Reset`: The time the rate-limiter will reset.\n\n\n  Once you receive this response there is nothing you can do except wait for the rate-limiter to reset. In order to avoid being rate-limited, you may want to cache your responses.\n\n ## Sorting\n   ### Overview\n   Sorting is available for most endpoints that return a collection (list) of objects. Each collection has a different set of enabled parameters for sorting, so please check specific collection section for detail.\n\n   ### Usage\n   Append `sort_by={parameter_name}.{asc|desc}` in your API request where `parameter_name` is a valid sortable parameter of that endpoint.\n\n   Example:\n   ```\n   /api/v3/penalties?sort_by=created_at.asc\n   ```\n\n ## Pagination\n  All bulk-fetching API methods that return lists of resource support pagination.\n  These methods commonly take at least 3 parameters: `limit`, `{attribute}_min`, `{attribute}_max`. Attribute can be `id`, `create_at`, etc., depending on each specific method.\n  For instance, you make a request to get a list of penalties `/api/v3/penalties?limit=20&created_at_max=2020-04-08T23:59:59Z&sort_by=created_at_max.desc`,\n  which means to fetch 20 penalities sorted by their creation time, with the most recent one being created before `2020-04-08T23:59:59Z`.\n  Assume that the response contains 20 `penalty` objects with the last object being `penalty_foo`,\n  then your subsequent request can be `/api/v3/penalties?limit=20&created_at_max={penalty_foo.create_at}&sort_by=created_at_max.desc` to fetch the next page of list.\n  Note that when fetching next page using `id_min` or `id_max`, you need to perform `+/- 1`(correspondingly) on the last object's ID in the current page, as `id_min` and `id_max` are inclusive. (All V3 API resources' IDs are either integer or BSON object ID - a hex number).\n\n\n ## Request ID\n  Each API request is associated with a unique identifier. You can find this value in response headers, under `Wish-Request-Id`.\n  **When you need to contact us about a specific request, please provide this ID to ensure the fastest possible reply**\n\n# Authentication\nFor all requests that require OAuth2 authentication, the access token must be provided in the `Authorization` request header in the following format: `Authorization: Bearer <token>`\n\nFor example:\n```\nAuthorization: Bearer 3d6e2d71bc464e42bfbdb081afb73c1e\n```\n<!-- ReDoc-Inject: <security-definitions> -->\n"
  version: 3.0.65
  title: Wish Marketplace V3 Brands OAuth API
servers:
- url: https://merchant.wish.com
  description: V3 API endpoint
security:
- OAuth2: []
tags:
- externalDocs:
    url: https://merchant.wish.com/documentation/api/v3/oauth
    description: Learn more about the OAuth process
  name: OAuth
paths:
  /api/v3/oauth/access_token:
    post:
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AccessToken'
          description: successful operation
        '400':
          content:
            application/json:
              examples:
                InvalidAuthCode:
                  value:
                    message: Incorrect authorization code provided
                    code: '10008'
                InvalidParam:
                  value:
                    message: grant_type must be set to 'authorization_code'
                    code: '1001'
                TokenRedeemed:
                  value:
                    message: The authorization code has already been redeemed
                    code: '10002'
                TokenRevoked:
                  value:
                    message: The access token has been revoked
                    code: '1008'
                InvalidCredentials:
                  value:
                    message: Incorrect credentials. One of client_id, client_secret, or redirect_url does not match our records
                    code: '10001'
                AccessTokenExpired:
                  value:
                    message: The access token has expired. Please restart the OAuth process
                    code: '1007'
                OAuthCodeExpired:
                  value:
                    message: The authorization code has expired
                    code: '10004'
              schema:
                $ref: '#/components/schemas/APIError'
          description: failed request
      tags:
      - OAuth
      summary: Retrieve an access token
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RetrieveAccessToken'
      operationId: oauthAccessTokenPost
      externalDocs:
        url: https://merchant.wish.com/documentation/api/v3/oauth
        description: OAuth tutorial
      x-code-samples:
      - lang: php_curl
        source: "<?php\n\n$curl = curl_init();\n\ncurl_setopt_array($curl, array(\n  CURLOPT_URL => \"https://merchant.wish.com/api/v3/oauth/access_token\",\n  CURLOPT_RETURNTRANSFER => true,\n  CURLOPT_ENCODING => \"\",\n  CURLOPT_MAXREDIRS => 10,\n  CURLOPT_TIMEOUT => 30,\n  CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n  CURLOPT_CUSTOMREQUEST => \"POST\",\n  CURLOPT_POSTFIELDS => \"{\\\"client_id\\\":\\\"string\\\",\\\"client_secret\\\":\\\"string\\\",\\\"code\\\":\\\"string\\\",\\\"grant_type\\\":\\\"string\\\",\\\"redirect_uri\\\":\\\"string\\\"}\",\n  CURLOPT_HTTPHEADER => array(\n    \"authorization: Bearer REPLACE_BEARER_TOKEN\",\n    \"content-type: application/json\"\n  ),\n));\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n  echo \"cURL Error #:\" . $err;\n} else {\n  echo $response;\n}"
      - lang: shell_curl
        source: "curl --request POST \\\n  --url 'https://merchant.wish.com/api/v3/oauth/access_token' \\\n  --header 'authorization: Bearer REPLACE_BEARER_TOKEN' \\\n  --header 'content-type: application/json' \\\n  --data '{\"client_id\":\"string\",\"client_secret\":\"string\",\"code\":\"string\",\"grant_type\":\"string\",\"redirect_uri\":\"string\"}'"
      - lang: java_unirest
        source: "HttpResponse<String> response = Unirest.post(\"https://merchant.wish.com/api/v3/oauth/access_token\")\n  .header(\"content-type\", \"application/json\")\n  .header(\"authorization\", \"Bearer REPLACE_BEARER_TOKEN\")\n  .body(\"{\\\"client_id\\\":\\\"string\\\",\\\"client_secret\\\":\\\"string\\\",\\\"code\\\":\\\"string\\\",\\\"grant_type\\\":\\\"string\\\",\\\"redirect_uri\\\":\\\"string\\\"}\")\n  .asString();"
      - lang: javascript_jquery
        source: "var settings = {\n  \"async\": true,\n  \"crossDomain\": true,\n  \"url\": \"https://merchant.wish.com/api/v3/oauth/access_token\",\n  \"method\": \"POST\",\n  \"headers\": {\n    \"content-type\": \"application/json\",\n    \"authorization\": \"Bearer REPLACE_BEARER_TOKEN\"\n  },\n  \"processData\": false,\n  \"data\": \"{\\\"client_id\\\":\\\"string\\\",\\\"client_secret\\\":\\\"string\\\",\\\"code\\\":\\\"string\\\",\\\"grant_type\\\":\\\"string\\\",\\\"redirect_uri\\\":\\\"string\\\"}\"\n}\n\n$.ajax(settings).done(function (response) {\n  console.log(response);\n});"
      - lang: python_requests
        source: "import requests\n\nurl = \"https://merchant.wish.com/api/v3/oauth/access_token\"\n\npayload = \"{\\\"client_id\\\":\\\"string\\\",\\\"client_secret\\\":\\\"string\\\",\\\"code\\\":\\\"string\\\",\\\"grant_type\\\":\\\"string\\\",\\\"redirect_uri\\\":\\\"string\\\"}\"\nheaders = {\n    'content-type': \"application/json\",\n    'authorization': \"Bearer REPLACE_BEARER_TOKEN\"\n    }\n\nresponse = requests.request(\"POST\", url, data=payload, headers=headers)\n\nprint(response.text)"
      description: An access token and a refresh token will be returned through this API. Your application should store both tokens. The access token is used to make authorized requests and the refresh token is used to obtain new access tokens. For security reasons, the access token will expire after 30 days. When the access token expires, please use refresh_token API to get new ones.
    get:
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AccessToken'
          description: successful operation
        '400':
          content:
            application/json:
              examples:
                InvalidAuthCode:
                  value:
                    message: Incorrect authorization code provided
                    code: '10008'
                InvalidParam:
                  value:
                    message: grant_type must be set to 'authorization_code'
                    code: '1001'
                TokenRedeemed:
                  value:
                    message: The authorization code has already been redeemed
                    code: '10002'
                TokenRevoked:
                  value:
                    message: The access token has been revoked
                    code: '1008'
                InvalidCredentials:
                  value:
                    message: Incorrect credentials. One of client_id, client_secret, or redirect_url does not match our records
                    code: '10001'
                AccessTokenExpired:
                  value:
                    message: The access token has expired. Please restart the OAuth process
                    code: '1007'
                OAuthCodeExpired:
                  value:
                    message: The authorization code has expired
                    code: '10004'
              schema:
                $ref: '#/components/schemas/APIError'
          description: failed request
      parameters:
      - required: true
        in: query
        description: Your app's client ID
        name: client_id
        schema:
          type: string
          format: object-id
      - required: true
        in: query
        description: Your app's client secret
        name: client_secret
        schema:
          type: string
      - required: true
        in: query
        description: The authorization code you received
        name: code
        schema:
          type: string
      - required: true
        in: query
        description: The string 'authorization_code'
        name: grant_type
        schema:
          type: string
      - required: true
        in: query
        description: Your app's redirect uri that you specified when you created the app
        name: redirect_uri
        schema:
          type: string
      tags:
      - OAuth
      summary: Retrieve an access token
      operationId: oauthAccessToken
      externalDocs:
        url: https://merchant.wish.com/documentation/api/v3/oauth
        description: OAuth tutorial
      x-code-samples:
      - lang: php_curl
        source: "<?php\n\n$curl = curl_init();\n\ncurl_setopt_array($curl, array(\n  CURLOPT_URL => \"https://merchant.wish.com/api/v3/oauth/access_token?client_id=SOME_STRING_VALUE&client_secret=SOME_STRING_VALUE&code=SOME_STRING_VALUE&grant_type=SOME_STRING_VALUE&redirect_uri=SOME_STRING_VALUE\",\n  CURLOPT_RETURNTRANSFER => true,\n  CURLOPT_ENCODING => \"\",\n  CURLOPT_MAXREDIRS => 10,\n  CURLOPT_TIMEOUT => 30,\n  CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n  CURLOPT_CUSTOMREQUEST => \"GET\",\n  CURLOPT_HTTPHEADER => array(\n    \"authorization: Bearer REPLACE_BEARER_TOKEN\"\n  ),\n));\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n  echo \"cURL Error #:\" . $err;\n} else {\n  echo $response;\n}"
      - lang: shell_curl
        source: "curl --request GET \\\n  --url 'https://merchant.wish.com/api/v3/oauth/access_token?client_id=SOME_STRING_VALUE&client_secret=SOME_STRING_VALUE&code=SOME_STRING_VALUE&grant_type=SOME_STRING_VALUE&redirect_uri=SOME_STRING_VALUE' \\\n  --header 'authorization: Bearer REPLACE_BEARER_TOKEN'"
      - lang: java_unirest
        source: "HttpResponse<String> response = Unirest.get(\"https://merchant.wish.com/api/v3/oauth/access_token?client_id=SOME_STRING_VALUE&client_secret=SOME_STRING_VALUE&code=SOME_STRING_VALUE&grant_type=SOME_STRING_VALUE&redirect_uri=SOME_STRING_VALUE\")\n  .header(\"authorization\", \"Bearer REPLACE_BEARER_TOKEN\")\n  .asString();"
      - lang: javascript_jquery
        source: "var settings = {\n  \"async\": true,\n  \"crossDomain\": true,\n  \"url\": \"https://merchant.wish.com/api/v3/oauth/access_token?client_id=SOME_STRING_VALUE&client_secret=SOME_STRING_VALUE&code=SOME_STRING_VALUE&grant_type=SOME_STRING_VALUE&redirect_uri=SOME_STRING_VALUE\",\n  \"method\": \"GET\",\n  \"headers\": {\n    \"authorization\": \"Bearer REPLACE_BEARER_TOKEN\"\n  }\n}\n\n$.ajax(settings).done(function (response) {\n  console.log(response);\n});"
      - lang: python_requests
        source: 'import requests


          url = "https://merchant.wish.com/api/v3/oauth/access_token"


          querystring = {"client_id":"SOME_STRING_VALUE","client_secret":"SOME_STRING_VALUE","code":"SOME_STRING_VALUE","grant_type":"SOME_STRING_VALUE","redirect_uri":"SOME_STRING_VALUE"}


          headers = {''authorization'': ''Bearer REPLACE_BEARER_TOKEN''}


          response = requests.request("GET", url, headers=headers, params=querystring)


          print(response.text)'
      description: An access token and a refresh token will be returned through this API. Your application should store both tokens. The access token is used to make authorized requests and the refresh token is used to obtain new access tokens. For security reasons, the access token will expire after 30 days. When the access token expires, please use refresh_token API to get new ones.
  /api/v3/oauth/test:
    get:
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TestTokenResponse'
          description: successful operation
        '400':
          content:
            application/json:
              examples:
                TokenExpired:
                  value:
                    message: This access token has expired
                    code: '1007'
                TokenRevoked:
                  value:
                    message: This access token has been revoked
                    code: '1008'
                CantAccessDueToAccountStatus:
                  value:
                    message: Cannot access API due to account is disabled
                    code: '1002'
                UnauthorizedAccess:
                  value:
                    message: No access token found or the app does not existd
                    code: '1006'
              schema:
                $ref: '#/components/schemas/APIError'
          description: failed request
      tags:
      - OAuth
      description: This is a convenient endpoint for users to quickly verify if a given access token can be used.
      summary: Test if an access token is valid
      externalDocs:
        url: https://merchant.wish.com/documentation/api/v3/oauth
        description: OAuth tutorial
      x-code-samples:
      - lang: php_curl
        source: "<?php\n\n$curl = curl_init();\n\ncurl_setopt_array($curl, array(\n  CURLOPT_URL => \"https://merchant.wish.com/api/v3/oauth/test\",\n  CURLOPT_RETURNTRANSFER => true,\n  CURLOPT_ENCODING => \"\",\n  CURLOPT_MAXREDIRS => 10,\n  CURLOPT_TIMEOUT => 30,\n  CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n  CURLOPT_CUSTOMREQUEST => \"GET\",\n  CURLOPT_HTTPHEADER => array(\n    \"authorization: Bearer REPLACE_BEARER_TOKEN\"\n  ),\n));\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n  echo \"cURL Error #:\" . $err;\n} else {\n  echo $response;\n}"
      - lang: shell_curl
        source: "curl --request GET \\\n  --url 'https://merchant.wish.com/api/v3/oauth/test' \\\n  --header 'authorization: Bearer REPLACE_BEARER_TOKEN'"
      - lang: java_unirest
        source: "HttpResponse<String> response = Unirest.get(\"https://merchant.wish.com/api/v3/oauth/test\")\n  .header(\"authorization\", \"Bearer REPLACE_BEARER_TOKEN\")\n  .asString();"
      - lang: javascript_jquery
        source: "var settings = {\n  \"async\": true,\n  \"crossDomain\": true,\n  \"url\": \"https://merchant.wish.com/api/v3/oauth/test\",\n  \"method\": \"GET\",\n  \"headers\": {\n    \"authorization\": \"Bearer REPLACE_BEARER_TOKEN\"\n  }\n}\n\n$.ajax(settings).done(function (response) {\n  console.log(response);\n});"
      - lang: python_requests
        source: 'import requests


          url = "https://merchant.wish.com/api/v3/oauth/test"


          headers = {''authorization'': ''Bearer REPLACE_BEARER_TOKEN''}


          response = requests.request("GET", url, headers=headers)


          print(response.text)'
      operationId: oauthTest
  /api/v3/oauth/refresh_token:
    get:
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AccessToken'
          description: successful operation
        '400':
          content:
            application/json:
              examples:
                InvalidParam:
                  value:
                    message: grant_type must be set to 'authorization_code'
                    code: '1001'
                UnauthorizedAccess:
                  value:
                    message: Unauthorized access on this API
                    code: '1006'
                InvalidCredentials:
                  value:
                    message: Incorrect credentials. client_id or client_secret does not match our records
                    code: '10001'
                CantAccessDueToAccountStatus:
                  value:
                    message: Cannot access API due to account is disabled
                    code: '1002'
              schema:
                $ref: '#/components/schemas/APIError'
          description: failed request
      parameters:
      - required: true
        in: query
        description: Your app's client ID
        name: client_id
        schema:
          type: string
          format: object-id
      - required: true
        in: query
        description: Your app's client secret
        name: client_secret
        schema:
          type: string
      - required: true
        in: query
        description: The refresh token
        name: refresh_token
        schema:
          type: string
      - required: true
        in: query
        description: The string 'refresh_token'
        name: grant_type
        schema:
          type: string
      tags:
      - OAuth
      summary: Obtain a new token when the current token expires
      operationId: oauthRefreshToken
      externalDocs:
        url: https://merchant.wish.com/documentation/api/v3/oauth
        description: OAuth tutorial
      x-code-samples:
      - lang: php_curl
        source: "<?php\n\n$curl = curl_init();\n\ncurl_setopt_array($curl, array(\n  CURLOPT_URL => \"https://merchant.wish.com/api/v3/oauth/refresh_token?client_id=SOME_STRING_VALUE&client_secret=SOME_STRING_VALUE&refresh_token=SOME_STRING_VALUE&grant_type=SOME_STRING_VALUE\",\n  CURLOPT_RETURNTRANSFER => true,\n  CURLOPT_ENCODING => \"\",\n  CURLOPT_MAXREDIRS => 10,\n  CURLOPT_TIMEOUT => 30,\n  CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n  CURLOPT_CUSTOMREQUEST => \"GET\",\n  CURLOPT_HTTPHEADER => array(\n    \"authorization: Bearer REPLACE_BEARER_TOKEN\"\n  ),\n));\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n  echo \"cURL Error #:\" . $err;\n} else {\n  echo $response;\n}"
      - lang: shell_curl
        source: "curl --request GET \\\n  --url 'https://merchant.wish.com/api/v3/oauth/refresh_token?client_id=SOME_STRING_VALUE&client_secret=SOME_STRING_VALUE&refresh_token=SOME_STRING_VALUE&grant_type=SOME_STRING_VALUE' \\\n  --header 'authorization: Bearer REPLACE_BEARER_TOKEN'"
      - lang: java_unirest
        source: "HttpResponse<String> response = Unirest.get(\"https://merchant.wish.com/api/v3/oauth/refresh_token?client_id=SOME_STRING_VALUE&client_secret=SOME_STRING_VALUE&refresh_token=SOME_STRING_VALUE&grant_type=SOME_STRING_VALUE\")\n  .header(\"authorization\", \"Bearer REPLACE_BEARER_TOKEN\")\n  .asString();"
      - lang: javascript_jquery
        source: "var settings = {\n  \"async\": true,\n  \"crossDomain\": true,\n  \"url\": \"https://merchant.wish.com/api/v3/oauth/refresh_token?client_id=SOME_STRING_VALUE&client_secret=SOME_STRING_VALUE&refresh_token=SOME_STRING_VALUE&grant_type=SOME_STRING_VALUE\",\n  \"method\": \"GET\",\n  \"headers\": {\n    \"authorization\": \"Bearer REPLACE_BEARER_TOKEN\"\n  }\n}\n\n$.ajax(settings).done(function (response) {\n  console.log(response);\n});"
      - lang: python_requests
        source: 'import requests


          url = "https://merchant.wish.com/api/v3/oauth/refresh_token"


          querystring = {"client_id":"SOME_STRING_VALUE","client_secret":"SOME_STRING_VALUE","refresh_token":"SOME_STRING_VALUE","grant_type":"SOME_STRING_VALUE"}


          headers = {''authorization'': ''Bearer REPLACE_BEARER_TOKEN''}


          response = requests.request("GET", url, headers=headers, params=querystring)


          print(response.text)'
      description: This API will generate a new token without going through the full OAuth process again. Existing access tokens will be revoked after calling this API
components:
  schemas:
    APIError:
      required:
      - code
      - message
      type: object
      properties:
        message:
          type: string
        code:
          type: integer
          format: int32
    AccessToken:
      required:
      - access_token
      - refresh_token
      - expiry_time
      - merchant_id
      - scopes
      type: object
      properties:
        access_token:
          type: string
          description: The access token needed in order to use all other marketplace APIs
        scopes:
          items:
            type: string
          type: array
          description: A list of scopes granted on this token
        merchant_id:
          type: string
          description: ID of the merchant to whom this token is linked
        expiry_time:
          type: string
          description: 'The timestamp on when this token will expire. '
          format: date-time
        refresh_token:
          type: string
          description: The refresh token used to get a new token when current token expires
    TestTokenResponse:
      required:
      - merchant_id
      type: object
      properties:
        merchant_id:
          type: string
          description: ID of the merchant to whom the access token belongs
    RetrieveAccessToken:
      required:
      - client_id
      - client_secret
      - code
      - grant_type
      - redirect_uri
      type: object
      properties:
        code:
          type: string
          description: The authorization code you received
        client_secret:
          type: string
          description: Your app's client secret
        redirect_uri:
          type: string
          description: Your app's redirect uri that you specified when you created the app
        client_id:
          type: string
          description: Your app's client ID
          format: object-id
        grant_type:
          type: string
          description: The string 'authorization_code'
  securitySchemes:
    OpenID:
      type: openIdConnect
      openIdConnectUrl: https://merchant.wish.com/oidc/.well-known/openid-configuration
    OAuth2:
      type: oauth2
      flows:
        authorizationCode:
          scopes:
            payments:write: Update payments
            tickets:write: Write customer tickets
            epc:read: read EPC info
            returns:write: Write returns
            returns:read: Read returns
            fbw:read: Read FBW
            products:read: Read products
            payments:read: Read payments
            fbw:write: Write FBW
            merchant:write: Write merchant
            products:write: Write products
            ratings:read: Read ratings
            videos:read: Read videos
            compliance:write: Write Compliance
            product_boost:read: Read ProductBoost
            listing_quality:read: Read listing quality
            webhook:write: Write webhook
            orders:read: Read orders
            compliance:read: Read Compliance
            fbs:read: Read FBS
            penalties:read: Read penalties
            penalties:write: Update penalties
            infractions:read: Read infractions
            orders:write: Update orders
            merchant:read: Read merchant
            notifications:write: Write notifications
            announcements:read: Read announcements
            product_boost:write: Write ProductBoost
            notifications:read: Read notifications
            webhook:read: Read webhook
            qoo10:read: Read Qoo10
            wps_parcel:write: Write WishParcel
            wps_parcel:read: Read WishParcel
            tickets:read: Read customer tickets
            infractions:write: Write infractions
            videos:write: Write videos
            epc:write: write EPC info
          tokenUrl: https://merchant.wish.com/api/v3/oauth/access_token
          refreshUrl: https://merchant.wish.com/api/v3/oauth/refresh_token
          authorizationUrl: https://merchant.wish.com/v3/oauth/authorize
externalDocs:
  url: https://merchant.wish.com/documentation/api/v3/explorer
  description: API explorer
x-wish-hidden: false