Wish O Auth API

The OAuth API from Wish — 3 operation(s) for oauth.

Operations 4

POST /api/v3/oauth/access_token Retrieve an access token #
GET /api/v3/oauth/access_token Retrieve an access token #
GET /api/v3/oauth/test Test if an access token is valid #
GET /api/v3/oauth/refresh_token Obtain a new token when the current token expires #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/wish-oauth-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

wish-oauth-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  contact:
    email: partner-api@wish.com
  x-wish-dev-contact:
    assignee: kwei
    email: marketplace-external-api@contextlogic.com
  description: 'Wish Marketplace V3 API


    # General Information


    The Wish Marketplace API will be using oAuth to authenticate in order to offer better security for its users


    * Learn about oAuth here.'
  version: 3.0.65
  title: Wish Marketplace V3 OAuth API
servers:
- url: https://merchant.wish.com
  description: V3 API endpoint
security:
- OAuth2: []
tags:
- externalDocs:
    url: https://merchant.wish.com/documentation/api/v3/oauth
    description: Learn more about the OAuth process
  name: OAuth
paths:
  /api/v3/oauth/access_token:
    post:
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AccessToken'
          description: successful operation
        '400':
          content:
            application/json:
              examples:
                InvalidAuthCode:
                  value:
                    message: Incorrect authorization code provided
                    code: '10008'
                InvalidParam:
                  value:
                    message: grant_type must be set to 'authorization_code'
                    code: '1001'
                TokenRedeemed:
                  value:
                    message: The authorization code has already been redeemed
                    code: '10002'
                TokenRevoked:
                  value:
                    message: The access token has been revoked
                    code: '1008'
                InvalidCredentials:
                  value:
                    message: Incorrect credentials. One of client_id, client_secret, or redirect_url does not match our records
                    code: '10001'
                AccessTokenExpired:
                  value:
                    message: The access token has expired. Please restart the OAuth process
                    code: '1007'
                OAuthCodeExpired:
                  value:
                    message: The authorization code has expired
                    code: '10004'
              schema:
                $ref: '#/components/schemas/APIError'
          description: failed request
      tags:
      - OAuth
      summary: Retrieve an access token
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RetrieveAccessToken'
      operationId: oauthAccessTokenPost
      externalDocs:
        url: https://merchant.wish.com/documentation/api/v3/oauth
        description: OAuth tutorial
      x-code-samples:
      - lang: php_curl
        source: "<?php\n\n$curl = curl_init();\n\ncurl_setopt_array($curl, array(\n  CURLOPT_URL => \"https://merchant.wish.com/api/v3/oauth/access_token\",\n  CURLOPT_RETURNTRANSFER => true,\n  CURLOPT_ENCODING => \"\",\n  CURLOPT_MAXREDIRS => 10,\n  CURLOPT_TIMEOUT => 30,\n  CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n  CURLOPT_CUSTOMREQUEST => \"POST\",\n  CURLOPT_POSTFIELDS => \"{\\\"client_id\\\":\\\"string\\\",\\\"client_secret\\\":\\\"string\\\",\\\"code\\\":\\\"string\\\",\\\"grant_type\\\":\\\"string\\\",\\\"redirect_uri\\\":\\\"string\\\"}\",\n  CURLOPT_HTTPHEADER => array(\n    \"authorization: Bearer REPLACE_BEARER_TOKEN\",\n    \"content-type: application/json\"\n  ),\n));\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n  echo \"cURL Error #:\" . $err;\n} else {\n  echo $response;\n}"
      - lang: shell_curl
        source: "curl --request POST \\\n  --url 'https://merchant.wish.com/api/v3/oauth/access_token' \\\n  --header 'authorization: Bearer REPLACE_BEARER_TOKEN' \\\n  --header 'content-type: application/json' \\\n  --data '{\"client_id\":\"string\",\"client_secret\":\"string\",\"code\":\"string\",\"grant_type\":\"string\",\"redirect_uri\":\"string\"}'"
      - lang: java_unirest
        source: "HttpResponse<String> response = Unirest.post(\"https://merchant.wish.com/api/v3/oauth/access_token\")\n  .header(\"content-type\", \"application/json\")\n  .header(\"authorization\", \"Bearer REPLACE_BEARER_TOKEN\")\n  .body(\"{\\\"client_id\\\":\\\"string\\\",\\\"client_secret\\\":\\\"string\\\",\\\"code\\\":\\\"string\\\",\\\"grant_type\\\":\\\"string\\\",\\\"redirect_uri\\\":\\\"string\\\"}\")\n  .asString();"
      - lang: javascript_jquery
        source: "var settings = {\n  \"async\": true,\n  \"crossDomain\": true,\n  \"url\": \"https://merchant.wish.com/api/v3/oauth/access_token\",\n  \"method\": \"POST\",\n  \"headers\": {\n    \"content-type\": \"application/json\",\n    \"authorization\": \"Bearer REPLACE_BEARER_TOKEN\"\n  },\n  \"processData\": false,\n  \"data\": \"{\\\"client_id\\\":\\\"string\\\",\\\"client_secret\\\":\\\"string\\\",\\\"code\\\":\\\"string\\\",\\\"grant_type\\\":\\\"string\\\",\\\"redirect_uri\\\":\\\"string\\\"}\"\n}\n\n$.ajax(settings).done(function (response) {\n  console.log(response);\n});"
      - lang: python_requests
        source: "import requests\n\nurl = \"https://merchant.wish.com/api/v3/oauth/access_token\"\n\npayload = \"{\\\"client_id\\\":\\\"string\\\",\\\"client_secret\\\":\\\"string\\\",\\\"code\\\":\\\"string\\\",\\\"grant_type\\\":\\\"string\\\",\\\"redirect_uri\\\":\\\"string\\\"}\"\nheaders = {\n    'content-type': \"application/json\",\n    'authorization': \"Bearer REPLACE_BEARER_TOKEN\"\n    }\n\nresponse = requests.request(\"POST\", url, data=payload, headers=headers)\n\nprint(response.text)"
      description: An access token and a refresh token will be returned through this API. Your application should store both tokens. The access token is used to make authorized requests and the refresh token is used to obtain new access tokens. For security reasons, the access token will expire after 30 days. When the access token expires, please use refresh_token API to get new ones.
    get:
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AccessToken'
          description: successful operation
        '400':
          content:
            application/json:
              examples:
                InvalidAuthCode:
                  value:
                    message: Incorrect authorization code provided
                    code: '10008'
                InvalidParam:
                  value:
                    message: grant_type must be set to 'authorization_code'
                    code: '1001'
                TokenRedeemed:
                  value:
                    message: The authorization code has already been redeemed
                    code: '10002'
                TokenRevoked:
                  value:
                    message: The access token has been revoked
                    code: '1008'
                InvalidCredentials:
                  value:
                    message: Incorrect credentials. One of client_id, client_secret, or redirect_url does not match our records
                    code: '10001'
                AccessTokenExpired:
                  value:
                    message: The access token has expired. Please restart the OAuth process
                    code: '1007'
                OAuthCodeExpired:
                  value:
                    message: The authorization code has expired
                    code: '10004'
              schema:
                $ref: '#/components/schemas/APIError'
          description: failed request
      parameters:
      - required: true
        in: query
        description: Your app's client ID
        name: client_id
        schema:
          type: string
          format: object-id
      - required: true
        in: query
        description: Your app's client secret
        name: client_secret
        schema:
          type: string
      - required: true
        in: query
        description: The authorization code you received
        name: code
        schema:
          type: string
      - required: true
        in: query
        description: The string 'authorization_code'
        name: grant_type
        schema:
          type: string
      - required: true
        in: query
        description: Your app's redirect uri that you specified when you created the app
        name: redirect_uri
        schema:
          type: string
      tags:
      - OAuth
      summary: Retrieve an access token
      operationId: oauthAccessToken
      externalDocs:
        url: https://merchant.wish.com/documentation/api/v3/oauth
        description: OAuth tutorial
      x-code-samples:
      - lang: php_curl
        source: "<?php\n\n$curl = curl_init();\n\ncurl_setopt_array($curl, array(\n  CURLOPT_URL => \"https://merchant.wish.com/api/v3/oauth/access_token?client_id=SOME_STRING_VALUE&client_secret=SOME_STRING_VALUE&code=SOME_STRING_VALUE&grant_type=SOME_STRING_VALUE&redirect_uri=SOME_STRING_VALUE\",\n  CURLOPT_RETURNTRANSFER => true,\n  CURLOPT_ENCODING => \"\",\n  CURLOPT_MAXREDIRS => 10,\n  CURLOPT_TIMEOUT => 30,\n  CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n  CURLOPT_CUSTOMREQUEST => \"GET\",\n  CURLOPT_HTTPHEADER => array(\n    \"authorization: Bearer REPLACE_BEARER_TOKEN\"\n  ),\n));\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n  echo \"cURL Error #:\" . $err;\n} else {\n  echo $response;\n}"
      - lang: shell_curl
        source: "curl --request GET \\\n  --url 'https://merchant.wish.com/api/v3/oauth/access_token?client_id=SOME_STRING_VALUE&client_secret=SOME_STRING_VALUE&code=SOME_STRING_VALUE&grant_type=SOME_STRING_VALUE&redirect_uri=SOME_STRING_VALUE' \\\n  --header 'authorization: Bearer REPLACE_BEARER_TOKEN'"
      - lang: java_unirest
        source: "HttpResponse<String> response = Unirest.get(\"https://merchant.wish.com/api/v3/oauth/access_token?client_id=SOME_STRING_VALUE&client_secret=SOME_STRING_VALUE&code=SOME_STRING_VALUE&grant_type=SOME_STRING_VALUE&redirect_uri=SOME_STRING_VALUE\")\n  .header(\"authorization\", \"Bearer REPLACE_BEARER_TOKEN\")\n  .asString();"
      - lang: javascript_jquery
        source: "var settings = {\n  \"async\": true,\n  \"crossDomain\": true,\n  \"url\": \"https://merchant.wish.com/api/v3/oauth/access_token?client_id=SOME_STRING_VALUE&client_secret=SOME_STRING_VALUE&code=SOME_STRING_VALUE&grant_type=SOME_STRING_VALUE&redirect_uri=SOME_STRING_VALUE\",\n  \"method\": \"GET\",\n  \"headers\": {\n    \"authorization\": \"Bearer REPLACE_BEARER_TOKEN\"\n  }\n}\n\n$.ajax(settings).done(function (response) {\n  console.log(response);\n});"
      - lang: python_requests
        source: 'import requests


          url = "https://merchant.wish.com/api/v3/oauth/access_token"


          querystring = {"client_id":"SOME_STRING_VALUE","client_secret":"SOME_STRING_VALUE","code":"SOME_STRING_VALUE","grant_type":"SOME_STRING_VALUE","redirect_uri":"SOME_STRING_VALUE"}


          headers = {''authorization'': ''Bearer REPLACE_BEARER_TOKEN''}


          response = requests.request("GET", url, headers=headers, params=querystring)


          print(response.text)'
      description: An access token and a refresh token will be returned through this API. Your application should store both tokens. The access token is used to make authorized requests and the refresh token is used to obtain new access tokens. For security reasons, the access token will expire after 30 days. When the access token expires, please use refresh_token API to get new ones.
  /api/v3/oauth/test:
    get:
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/TestTokenResponse'
          description: successful operation
        '400':
          content:
            application/json:
              examples:
                TokenExpired:
                  value:
                    message: This access token has expired
                    code: '1007'
                TokenRevoked:
                  value:
                    message: This access token has been revoked
                    code: '1008'
                CantAccessDueToAccountStatus:
                  value:
                    message: Cannot access API due to account is disabled
                    code: '1002'
                UnauthorizedAccess:
                  value:
                    message: No access token found or the app does not existd
                    code: '1006'
              schema:
                $ref: '#/components/schemas/APIError'
          description: failed request
      tags:
      - OAuth
      description: This is a convenient endpoint for users to quickly verify if a given access token can be used.
      summary: Test if an access token is valid
      externalDocs:
        url: https://merchant.wish.com/documentation/api/v3/oauth
        description: OAuth tutorial
      x-code-samples:
      - lang: php_curl
        source: "<?php\n\n$curl = curl_init();\n\ncurl_setopt_array($curl, array(\n  CURLOPT_URL => \"https://merchant.wish.com/api/v3/oauth/test\",\n  CURLOPT_RETURNTRANSFER => true,\n  CURLOPT_ENCODING => \"\",\n  CURLOPT_MAXREDIRS => 10,\n  CURLOPT_TIMEOUT => 30,\n  CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n  CURLOPT_CUSTOMREQUEST => \"GET\",\n  CURLOPT_HTTPHEADER => array(\n    \"authorization: Bearer REPLACE_BEARER_TOKEN\"\n  ),\n));\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n  echo \"cURL Error #:\" . $err;\n} else {\n  echo $response;\n}"
      - lang: shell_curl
        source: "curl --request GET \\\n  --url 'https://merchant.wish.com/api/v3/oauth/test' \\\n  --header 'authorization: Bearer REPLACE_BEARER_TOKEN'"
      - lang: java_unirest
        source: "HttpResponse<String> response = Unirest.get(\"https://merchant.wish.com/api/v3/oauth/test\")\n  .header(\"authorization\", \"Bearer REPLACE_BEARER_TOKEN\")\n  .asString();"
      - lang: javascript_jquery
        source: "var settings = {\n  \"async\": true,\n  \"crossDomain\": true,\n  \"url\": \"https://merchant.wish.com/api/v3/oauth/test\",\n  \"method\": \"GET\",\n  \"headers\": {\n    \"authorization\": \"Bearer REPLACE_BEARER_TOKEN\"\n  }\n}\n\n$.ajax(settings).done(function (response) {\n  console.log(response);\n});"
      - lang: python_requests
        source: 'import requests


          url = "https://merchant.wish.com/api/v3/oauth/test"


          headers = {''authorization'': ''Bearer REPLACE_BEARER_TOKEN''}


          response = requests.request("GET", url, headers=headers)


          print(response.text)'
      operationId: oauthTest
  /api/v3/oauth/refresh_token:
    get:
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AccessToken'
          description: successful operation
        '400':
          content:
            application/json:
              examples:
                InvalidParam:
                  value:
                    message: grant_type must be set to 'authorization_code'
                    code: '1001'
                UnauthorizedAccess:
                  value:
                    message: Unauthorized access on this API
                    code: '1006'
                InvalidCredentials:
                  value:
                    message: Incorrect credentials. client_id or client_secret does not match our records
                    code: '10001'
                CantAccessDueToAccountStatus:
                  value:
                    message: Cannot access API due to account is disabled
                    code: '1002'
              schema:
                $ref: '#/components/schemas/APIError'
          description: failed request
      parameters:
      - required: true
        in: query
        description: Your app's client ID
        name: client_id
        schema:
          type: string
          format: object-id
      - required: true
        in: query
        description: Your app's client secret
        name: client_secret
        schema:
          type: string
      - required: true
        in: query
        description: The refresh token
        name: refresh_token
        schema:
          type: string
      - required: true
        in: query
        description: The string 'refresh_token'
        name: grant_type
        schema:
          type: string
      tags:
      - OAuth
      summary: Obtain a new token when the current token expires
      operationId: oauthRefreshToken
      externalDocs:
        url: https://merchant.wish.com/documentation/api/v3/oauth
        description: OAuth tutorial
      x-code-samples:
      - lang: php_curl
        source: "<?php\n\n$curl = curl_init();\n\ncurl_setopt_array($curl, array(\n  CURLOPT_URL => \"https://merchant.wish.com/api/v3/oauth/refresh_token?client_id=SOME_STRING_VALUE&client_secret=SOME_STRING_VALUE&refresh_token=SOME_STRING_VALUE&grant_type=SOME_STRING_VALUE\",\n  CURLOPT_RETURNTRANSFER => true,\n  CURLOPT_ENCODING => \"\",\n  CURLOPT_MAXREDIRS => 10,\n  CURLOPT_TIMEOUT => 30,\n  CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n  CURLOPT_CUSTOMREQUEST => \"GET\",\n  CURLOPT_HTTPHEADER => array(\n    \"authorization: Bearer REPLACE_BEARER_TOKEN\"\n  ),\n));\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n  echo \"cURL Error #:\" . $err;\n} else {\n  echo $response;\n}"
      - lang: shell_curl
        source: "curl --request GET \\\n  --url 'https://merchant.wish.com/api/v3/oauth/refresh_token?client_id=SOME_STRING_VALUE&client_secret=SOME_STRING_VALUE&refresh_token=SOME_STRING_VALUE&grant_type=SOME_STRING_VALUE' \\\n  --header 'authorization: Bearer REPLACE_BEARER_TOKEN'"
      - lang: java_unirest
        source: "HttpResponse<String> response = Unirest.get(\"https://merchant.wish.com/api/v3/oauth/refresh_token?client_id=SOME_STRING_VALUE&client_secret=SOME_STRING_VALUE&refresh_token=SOME_STRING_VALUE&grant_type=SOME_STRING_VALUE\")\n  .header(\"authorization\", \"Bearer REPLACE_BEARER_TOKEN\")\n  .asString();"
      - lang: javascript_jquery
        source: "var settings = {\n  \"async\": true,\n  \"crossDomain\": true,\n  \"url\": \"https://merchant.wish.com/api/v3/oauth/refresh_token?client_id=SOME_STRING_VALUE&client_secret=SOME_STRING_VALUE&refresh_token=SOME_STRING_VALUE&grant_type=SOME_STRING_VALUE\",\n  \"method\": \"GET\",\n  \"headers\": {\n    \"authorization\": \"Bearer REPLACE_BEARER_TOKEN\"\n  }\n}\n\n$.ajax(settings).done(function (response) {\n  console.log(response);\n});"
      - lang: python_requests
        source: 'import requests


          url = "https://merchant.wish.com/api/v3/oauth/refresh_token"


          querystring = {"client_id":"SOME_STRING_VALUE","client_secret":"SOME_STRING_VALUE","refresh_token":"SOME_STRING_VALUE","grant_type":"SOME_STRING_VALUE"}


          headers = {''authorization'': ''Bearer REPLACE_BEARER_TOKEN''}


          response = requests.request("GET", url, headers=headers, params=querystring)


          print(response.text)'
      description: This API will generate a new token without going through the full OAuth process again. Existing access tokens will be revoked after calling this API
components:
  schemas:
    RetrieveAccessToken:
      required:
      - client_id
      - client_secret
      - code
      - grant_type
      - redirect_uri
      type: object
      properties:
        code:
          type: string
          description: The authorization code you received
        client_secret:
          type: string
          description: Your app's client secret
        redirect_uri:
          type: string
          description: Your app's redirect uri that you specified when you created the app
        client_id:
          type: string
          description: Your app's client ID
          format: object-id
        grant_type:
          type: string
          description: The string 'authorization_code'
    APIError:
      required:
      - code
      - message
      type: object
      properties:
        message:
          type: string
        code:
          type: integer
          format: int32
    TestTokenResponse:
      required:
      - merchant_id
      type: object
      properties:
        merchant_id:
          type: string
          description: ID of the merchant to whom the access token belongs
    AccessToken:
      required:
      - access_token
      - refresh_token
      - expiry_time
      - merchant_id
      - scopes
      type: object
      properties:
        access_token:
          type: string
          description: The access token needed in order to use all other marketplace APIs
        scopes:
          items:
            type: string
          type: array
          description: A list of scopes granted on this token
        merchant_id:
          type: string
          description: ID of the merchant to whom this token is linked
        expiry_time:
          type: string
          description: 'The timestamp on when this token will expire. '
          format: date-time
        refresh_token:
          type: string
          description: The refresh token used to get a new token when current token expires
  securitySchemes:
    OpenID:
      type: openIdConnect
      openIdConnectUrl: https://merchant.wish.com/oidc/.well-known/openid-configuration
    OAuth2:
      type: oauth2
      flows:
        authorizationCode:
          scopes:
            payments:write: Update payments
            tickets:write: Write customer tickets
            epc:read: read EPC info
            returns:write: Write returns
            returns:read: Read returns
            fbw:read: Read FBW
            products:read: Read products
            payments:read: Read payments
            fbw:write: Write FBW
            merchant:write: Write merchant
            products:write: Write products
            ratings:read: Read ratings
            videos:read: Read videos
            compliance:write: Write Compliance
            product_boost:read: Read ProductBoost
            listing_quality:read: Read listing quality
            webhook:write: Write webhook
            orders:read: Read orders
            compliance:read: Read Compliance
            fbs:read: Read FBS
            penalties:read: Read penalties
            penalties:write: Update penalties
            infractions:read: Read infractions
            orders:write: Update orders
            merchant:read: Read merchant
            notifications:write: Write notifications
            announcements:read: Read announcements
            product_boost:write: Write ProductBoost
            notifications:read: Read notifications
            webhook:read: Read webhook
            qoo10:read: Read Qoo10
            wps_parcel:write: Write WishParcel
            wps_parcel:read: Read WishParcel
            tickets:read: Read customer tickets
            infractions:write: Write infractions
            videos:write: Write videos
            epc:write: write EPC info
          tokenUrl: https://merchant.wish.com/api/v3/oauth/access_token
          refreshUrl: https://merchant.wish.com/api/v3/oauth/refresh_token
          authorizationUrl: https://merchant.wish.com/v3/oauth/authorize
externalDocs:
  url: https://merchant.wish.com/documentation/api/v3/explorer
  description: API explorer
x-wish-hidden: false