openapi: 3.0.0
info:
contact:
email: partner-api@wish.com
x-wish-dev-contact:
assignee: kwei
email: marketplace-external-api@contextlogic.com
description: "\nWish Marketplace V3 API\n\n# General Information\n\n The Wish Marketplace API will be using oAuth to authenticate in order to offer better security for its users\n\n * Learn about oAuth [here](oauth).\n * If you are a merchant and want to create an application for yourself, learn about how to create a private app [here](../../private-app)\n * If you are a ERP and create applications that'll be used by multiple merchants, learn about how to create a public app [here]( ../../public-app). You will need to apply to be a verified public application\n\n ## How to Test\n\n To avoid testing the API on production data, use our sandbox. The sandbox is completely contained and will not affect Wish users or your merchant account. \n \n To reach the sandbox, visit: https://sandbox.merchant.wish.com.\n\n To use the sandbox in testing, use https://sandbox.merchant.wish.com/api/v3/ as your base URL.\n\n How to Generate test data after you have created a sandbox account:\n 1. Navigate to the [unfulfilled orders page](https://sandbox.merchant.wish.com/transactions/action)\n 2. Hover over the dropdown next to the 'fulfill with csv' button and select Generate Orders\n\n ## Date/Time Format\n\n All dates and times in our API are returned in the same format. It is in the form `YYYY-MM-DDTHH:mm:ss.sss±XX:ZZ` or `YYYY-MM-DDTHH:mm:ss.sssZ`, where 'Z' represents UTC timezone.\n When sending timestamps in URL parameters or the request body, millisecond is optional and will defaults to 0 if not provided.\n\n * `YYYY` is the year\n * `MM` is the month\n * `DD` is the day\n * `HH` is the hour (in 24-hour clock format)\n * `mm` is the minutes\n * `ss.sss` is the seconds and milliseconds\n * `±XX:ZZ` is the UTC offset of the form +XX:ZZ or -XX:ZZ where XX is a 2-digit string giving the number of UTC offset hours, and ZZ is a 2-digit string giving the number of UTC offset minutes.\n\n ## Response Schema\n\n Every response returned from the Wish API will have the same schema. This schema is intended to give you a predictable manner to check the status of your request and know where to get the data. Each response will have the following top level attributes: message, code and data.\n\n **Attributes**\n\n <table>\n <tbody>\n <tr>\n <th>Message</th>\n <td>A message describing the error that happened, example: \"We could not find a product for id: '5d30f60e0a6fc464f4f376b0'\"</td>\n </tr>\n <tr>\n <th>Code</th>\n <td>A unique number which represents the error that has occurred, example: 1008 or 0 if success.</td>\n </tr>\n <tr>\n <th>Data</th>\n <td>For errors this will be empty.</td>\n </tr>\n </tbody>\n </table>\n\n ## General Querying Techniques\n\n ### Partial Resources\n All GET endpoints (except OAuth) support a fields parameter which allows for requesting a partial response. Any fields specified in the response schema of an endpoint can be selected. The top level attribute `data` can be ignored when using the fields parameter.\n\n **Syntax**\n * Comma-separated list to select multiple fields\n * Use forward slash `/` to select nested field: `field1/nested_field`\n * Use parentheses `( )` to select multiple nested fields: `field1(nested_field1,nested_field2)`\n * Use `*` for wildcard selection: `field1/nested_field/*`\n\n\n **Example:**\n ```\n https://merchant.wish.com/api/v3/demo/get?fields=title,items(id,info/name)\n ```\n Which would result in the following partial response:\n ```\n {\n \"title\": \"demo\",\n \"items\": [\n {\n \"id\": \"1\",\n \"info\": {\n \"name\": \"demo_item_1\"\n }\n }, {\n \"id\": \"2\",\n \"info\": {\n \"name\": \"demo_item_2\"\n }\n },\n ...\n ]\n }\n ```\n\n ## Locale\n You can optionally specify locale in order to translate content and error messages into your language.\n To do this use the [Accept-Language](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Accept-Language) header to specify your preferred locales.\n If none is provided, your default locale will be used.\n\n For example, to request content in Chinese use: `Accept-Language: zh`\n\n In the response, you will receive a [Content-Language](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Language) header that specifies the locale code of the response content.\n\n\n ## Rate-Limiting\n\n Rate-limiting will be performed on a per-merchant basis for each app. It is your responsibility to ensure you are not making frequent unnecessary calls to the API.\n\n If the rate limits cannot satisfy your need, we highly recommend integrating webhooks for your app. With webhooks, instead of pulling resources periodically, your app will receive real-time notifications for particular events that occur to a merchant’s store. [Learn more](https://merchant.wish.com/documentation/webhooks)\n\n **Normal Usage**\n\n To help you track the rate-limiter status, the following response header(s) will be provided with each response:\n\n * `Wish-Rate-Limit-Remaining`: The number of calls remaining in the current rate-limiting window.\n\n\n **Rate-Limit Exceeded**\n\n After you exceed the number of allowed calls in the current rate-limiting window, you will receive a `429 Too Many Requests` error response and the following additional header(s):\n\n * `Wish-Rate-Limit-Reset`: The time the rate-limiter will reset.\n\n\n Once you receive this response there is nothing you can do except wait for the rate-limiter to reset. In order to avoid being rate-limited, you may want to cache your responses.\n\n ## Sorting\n ### Overview\n Sorting is available for most endpoints that return a collection (list) of objects. Each collection has a different set of enabled parameters for sorting, so please check specific collection section for detail.\n\n ### Usage\n Append `sort_by={parameter_name}.{asc|desc}` in your API request where `parameter_name` is a valid sortable parameter of that endpoint.\n\n Example:\n ```\n /api/v3/penalties?sort_by=created_at.asc\n ```\n\n ## Pagination\n All bulk-fetching API methods that return lists of resource support pagination.\n These methods commonly take at least 3 parameters: `limit`, `{attribute}_min`, `{attribute}_max`. Attribute can be `id`, `create_at`, etc., depending on each specific method.\n For instance, you make a request to get a list of penalties `/api/v3/penalties?limit=20&created_at_max=2020-04-08T23:59:59Z&sort_by=created_at_max.desc`,\n which means to fetch 20 penalities sorted by their creation time, with the most recent one being created before `2020-04-08T23:59:59Z`.\n Assume that the response contains 20 `penalty` objects with the last object being `penalty_foo`,\n then your subsequent request can be `/api/v3/penalties?limit=20&created_at_max={penalty_foo.create_at}&sort_by=created_at_max.desc` to fetch the next page of list.\n Note that when fetching next page using `id_min` or `id_max`, you need to perform `+/- 1`(correspondingly) on the last object's ID in the current page, as `id_min` and `id_max` are inclusive. (All V3 API resources' IDs are either integer or BSON object ID - a hex number).\n\n\n ## Request ID\n Each API request is associated with a unique identifier. You can find this value in response headers, under `Wish-Request-Id`.\n **When you need to contact us about a specific request, please provide this ID to ensure the fastest possible reply**\n\n# Authentication\nFor all requests that require OAuth2 authentication, the access token must be provided in the `Authorization` request header in the following format: `Authorization: Bearer <token>`\n\nFor example:\n```\nAuthorization: Bearer 3d6e2d71bc464e42bfbdb081afb73c1e\n```\n<!-- ReDoc-Inject: <security-definitions> -->\n"
version: 3.0.65
title: Wish Marketplace V3 Brands OAuth API
servers:
- url: https://merchant.wish.com
description: V3 API endpoint
security:
- OAuth2: []
tags:
- externalDocs:
url: https://merchant.wish.com/documentation/api/v3/oauth
description: Learn more about the OAuth process
name: OAuth
paths:
/api/v3/oauth/access_token:
post:
responses:
'200':
content:
application/json:
schema:
$ref: '#/components/schemas/AccessToken'
description: successful operation
'400':
content:
application/json:
examples:
InvalidAuthCode:
value:
message: Incorrect authorization code provided
code: '10008'
InvalidParam:
value:
message: grant_type must be set to 'authorization_code'
code: '1001'
TokenRedeemed:
value:
message: The authorization code has already been redeemed
code: '10002'
TokenRevoked:
value:
message: The access token has been revoked
code: '1008'
InvalidCredentials:
value:
message: Incorrect credentials. One of client_id, client_secret, or redirect_url does not match our records
code: '10001'
AccessTokenExpired:
value:
message: The access token has expired. Please restart the OAuth process
code: '1007'
OAuthCodeExpired:
value:
message: The authorization code has expired
code: '10004'
schema:
$ref: '#/components/schemas/APIError'
description: failed request
tags:
- OAuth
summary: Retrieve an access token
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/RetrieveAccessToken'
operationId: oauthAccessTokenPost
externalDocs:
url: https://merchant.wish.com/documentation/api/v3/oauth
description: OAuth tutorial
x-code-samples:
- lang: php_curl
source: "<?php\n\n$curl = curl_init();\n\ncurl_setopt_array($curl, array(\n CURLOPT_URL => \"https://merchant.wish.com/api/v3/oauth/access_token\",\n CURLOPT_RETURNTRANSFER => true,\n CURLOPT_ENCODING => \"\",\n CURLOPT_MAXREDIRS => 10,\n CURLOPT_TIMEOUT => 30,\n CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n CURLOPT_CUSTOMREQUEST => \"POST\",\n CURLOPT_POSTFIELDS => \"{\\\"client_id\\\":\\\"string\\\",\\\"client_secret\\\":\\\"string\\\",\\\"code\\\":\\\"string\\\",\\\"grant_type\\\":\\\"string\\\",\\\"redirect_uri\\\":\\\"string\\\"}\",\n CURLOPT_HTTPHEADER => array(\n \"authorization: Bearer REPLACE_BEARER_TOKEN\",\n \"content-type: application/json\"\n ),\n));\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n echo \"cURL Error #:\" . $err;\n} else {\n echo $response;\n}"
- lang: shell_curl
source: "curl --request POST \\\n --url 'https://merchant.wish.com/api/v3/oauth/access_token' \\\n --header 'authorization: Bearer REPLACE_BEARER_TOKEN' \\\n --header 'content-type: application/json' \\\n --data '{\"client_id\":\"string\",\"client_secret\":\"string\",\"code\":\"string\",\"grant_type\":\"string\",\"redirect_uri\":\"string\"}'"
- lang: java_unirest
source: "HttpResponse<String> response = Unirest.post(\"https://merchant.wish.com/api/v3/oauth/access_token\")\n .header(\"content-type\", \"application/json\")\n .header(\"authorization\", \"Bearer REPLACE_BEARER_TOKEN\")\n .body(\"{\\\"client_id\\\":\\\"string\\\",\\\"client_secret\\\":\\\"string\\\",\\\"code\\\":\\\"string\\\",\\\"grant_type\\\":\\\"string\\\",\\\"redirect_uri\\\":\\\"string\\\"}\")\n .asString();"
- lang: javascript_jquery
source: "var settings = {\n \"async\": true,\n \"crossDomain\": true,\n \"url\": \"https://merchant.wish.com/api/v3/oauth/access_token\",\n \"method\": \"POST\",\n \"headers\": {\n \"content-type\": \"application/json\",\n \"authorization\": \"Bearer REPLACE_BEARER_TOKEN\"\n },\n \"processData\": false,\n \"data\": \"{\\\"client_id\\\":\\\"string\\\",\\\"client_secret\\\":\\\"string\\\",\\\"code\\\":\\\"string\\\",\\\"grant_type\\\":\\\"string\\\",\\\"redirect_uri\\\":\\\"string\\\"}\"\n}\n\n$.ajax(settings).done(function (response) {\n console.log(response);\n});"
- lang: python_requests
source: "import requests\n\nurl = \"https://merchant.wish.com/api/v3/oauth/access_token\"\n\npayload = \"{\\\"client_id\\\":\\\"string\\\",\\\"client_secret\\\":\\\"string\\\",\\\"code\\\":\\\"string\\\",\\\"grant_type\\\":\\\"string\\\",\\\"redirect_uri\\\":\\\"string\\\"}\"\nheaders = {\n 'content-type': \"application/json\",\n 'authorization': \"Bearer REPLACE_BEARER_TOKEN\"\n }\n\nresponse = requests.request(\"POST\", url, data=payload, headers=headers)\n\nprint(response.text)"
description: An access token and a refresh token will be returned through this API. Your application should store both tokens. The access token is used to make authorized requests and the refresh token is used to obtain new access tokens. For security reasons, the access token will expire after 30 days. When the access token expires, please use refresh_token API to get new ones.
get:
responses:
'200':
content:
application/json:
schema:
$ref: '#/components/schemas/AccessToken'
description: successful operation
'400':
content:
application/json:
examples:
InvalidAuthCode:
value:
message: Incorrect authorization code provided
code: '10008'
InvalidParam:
value:
message: grant_type must be set to 'authorization_code'
code: '1001'
TokenRedeemed:
value:
message: The authorization code has already been redeemed
code: '10002'
TokenRevoked:
value:
message: The access token has been revoked
code: '1008'
InvalidCredentials:
value:
message: Incorrect credentials. One of client_id, client_secret, or redirect_url does not match our records
code: '10001'
AccessTokenExpired:
value:
message: The access token has expired. Please restart the OAuth process
code: '1007'
OAuthCodeExpired:
value:
message: The authorization code has expired
code: '10004'
schema:
$ref: '#/components/schemas/APIError'
description: failed request
parameters:
- required: true
in: query
description: Your app's client ID
name: client_id
schema:
type: string
format: object-id
- required: true
in: query
description: Your app's client secret
name: client_secret
schema:
type: string
- required: true
in: query
description: The authorization code you received
name: code
schema:
type: string
- required: true
in: query
description: The string 'authorization_code'
name: grant_type
schema:
type: string
- required: true
in: query
description: Your app's redirect uri that you specified when you created the app
name: redirect_uri
schema:
type: string
tags:
- OAuth
summary: Retrieve an access token
operationId: oauthAccessToken
externalDocs:
url: https://merchant.wish.com/documentation/api/v3/oauth
description: OAuth tutorial
x-code-samples:
- lang: php_curl
source: "<?php\n\n$curl = curl_init();\n\ncurl_setopt_array($curl, array(\n CURLOPT_URL => \"https://merchant.wish.com/api/v3/oauth/access_token?client_id=SOME_STRING_VALUE&client_secret=SOME_STRING_VALUE&code=SOME_STRING_VALUE&grant_type=SOME_STRING_VALUE&redirect_uri=SOME_STRING_VALUE\",\n CURLOPT_RETURNTRANSFER => true,\n CURLOPT_ENCODING => \"\",\n CURLOPT_MAXREDIRS => 10,\n CURLOPT_TIMEOUT => 30,\n CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n CURLOPT_CUSTOMREQUEST => \"GET\",\n CURLOPT_HTTPHEADER => array(\n \"authorization: Bearer REPLACE_BEARER_TOKEN\"\n ),\n));\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n echo \"cURL Error #:\" . $err;\n} else {\n echo $response;\n}"
- lang: shell_curl
source: "curl --request GET \\\n --url 'https://merchant.wish.com/api/v3/oauth/access_token?client_id=SOME_STRING_VALUE&client_secret=SOME_STRING_VALUE&code=SOME_STRING_VALUE&grant_type=SOME_STRING_VALUE&redirect_uri=SOME_STRING_VALUE' \\\n --header 'authorization: Bearer REPLACE_BEARER_TOKEN'"
- lang: java_unirest
source: "HttpResponse<String> response = Unirest.get(\"https://merchant.wish.com/api/v3/oauth/access_token?client_id=SOME_STRING_VALUE&client_secret=SOME_STRING_VALUE&code=SOME_STRING_VALUE&grant_type=SOME_STRING_VALUE&redirect_uri=SOME_STRING_VALUE\")\n .header(\"authorization\", \"Bearer REPLACE_BEARER_TOKEN\")\n .asString();"
- lang: javascript_jquery
source: "var settings = {\n \"async\": true,\n \"crossDomain\": true,\n \"url\": \"https://merchant.wish.com/api/v3/oauth/access_token?client_id=SOME_STRING_VALUE&client_secret=SOME_STRING_VALUE&code=SOME_STRING_VALUE&grant_type=SOME_STRING_VALUE&redirect_uri=SOME_STRING_VALUE\",\n \"method\": \"GET\",\n \"headers\": {\n \"authorization\": \"Bearer REPLACE_BEARER_TOKEN\"\n }\n}\n\n$.ajax(settings).done(function (response) {\n console.log(response);\n});"
- lang: python_requests
source: 'import requests
url = "https://merchant.wish.com/api/v3/oauth/access_token"
querystring = {"client_id":"SOME_STRING_VALUE","client_secret":"SOME_STRING_VALUE","code":"SOME_STRING_VALUE","grant_type":"SOME_STRING_VALUE","redirect_uri":"SOME_STRING_VALUE"}
headers = {''authorization'': ''Bearer REPLACE_BEARER_TOKEN''}
response = requests.request("GET", url, headers=headers, params=querystring)
print(response.text)'
description: An access token and a refresh token will be returned through this API. Your application should store both tokens. The access token is used to make authorized requests and the refresh token is used to obtain new access tokens. For security reasons, the access token will expire after 30 days. When the access token expires, please use refresh_token API to get new ones.
/api/v3/oauth/test:
get:
responses:
'200':
content:
application/json:
schema:
$ref: '#/components/schemas/TestTokenResponse'
description: successful operation
'400':
content:
application/json:
examples:
TokenExpired:
value:
message: This access token has expired
code: '1007'
TokenRevoked:
value:
message: This access token has been revoked
code: '1008'
CantAccessDueToAccountStatus:
value:
message: Cannot access API due to account is disabled
code: '1002'
UnauthorizedAccess:
value:
message: No access token found or the app does not existd
code: '1006'
schema:
$ref: '#/components/schemas/APIError'
description: failed request
tags:
- OAuth
description: This is a convenient endpoint for users to quickly verify if a given access token can be used.
summary: Test if an access token is valid
externalDocs:
url: https://merchant.wish.com/documentation/api/v3/oauth
description: OAuth tutorial
x-code-samples:
- lang: php_curl
source: "<?php\n\n$curl = curl_init();\n\ncurl_setopt_array($curl, array(\n CURLOPT_URL => \"https://merchant.wish.com/api/v3/oauth/test\",\n CURLOPT_RETURNTRANSFER => true,\n CURLOPT_ENCODING => \"\",\n CURLOPT_MAXREDIRS => 10,\n CURLOPT_TIMEOUT => 30,\n CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n CURLOPT_CUSTOMREQUEST => \"GET\",\n CURLOPT_HTTPHEADER => array(\n \"authorization: Bearer REPLACE_BEARER_TOKEN\"\n ),\n));\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n echo \"cURL Error #:\" . $err;\n} else {\n echo $response;\n}"
- lang: shell_curl
source: "curl --request GET \\\n --url 'https://merchant.wish.com/api/v3/oauth/test' \\\n --header 'authorization: Bearer REPLACE_BEARER_TOKEN'"
- lang: java_unirest
source: "HttpResponse<String> response = Unirest.get(\"https://merchant.wish.com/api/v3/oauth/test\")\n .header(\"authorization\", \"Bearer REPLACE_BEARER_TOKEN\")\n .asString();"
- lang: javascript_jquery
source: "var settings = {\n \"async\": true,\n \"crossDomain\": true,\n \"url\": \"https://merchant.wish.com/api/v3/oauth/test\",\n \"method\": \"GET\",\n \"headers\": {\n \"authorization\": \"Bearer REPLACE_BEARER_TOKEN\"\n }\n}\n\n$.ajax(settings).done(function (response) {\n console.log(response);\n});"
- lang: python_requests
source: 'import requests
url = "https://merchant.wish.com/api/v3/oauth/test"
headers = {''authorization'': ''Bearer REPLACE_BEARER_TOKEN''}
response = requests.request("GET", url, headers=headers)
print(response.text)'
operationId: oauthTest
/api/v3/oauth/refresh_token:
get:
responses:
'200':
content:
application/json:
schema:
$ref: '#/components/schemas/AccessToken'
description: successful operation
'400':
content:
application/json:
examples:
InvalidParam:
value:
message: grant_type must be set to 'authorization_code'
code: '1001'
UnauthorizedAccess:
value:
message: Unauthorized access on this API
code: '1006'
InvalidCredentials:
value:
message: Incorrect credentials. client_id or client_secret does not match our records
code: '10001'
CantAccessDueToAccountStatus:
value:
message: Cannot access API due to account is disabled
code: '1002'
schema:
$ref: '#/components/schemas/APIError'
description: failed request
parameters:
- required: true
in: query
description: Your app's client ID
name: client_id
schema:
type: string
format: object-id
- required: true
in: query
description: Your app's client secret
name: client_secret
schema:
type: string
- required: true
in: query
description: The refresh token
name: refresh_token
schema:
type: string
- required: true
in: query
description: The string 'refresh_token'
name: grant_type
schema:
type: string
tags:
- OAuth
summary: Obtain a new token when the current token expires
operationId: oauthRefreshToken
externalDocs:
url: https://merchant.wish.com/documentation/api/v3/oauth
description: OAuth tutorial
x-code-samples:
- lang: php_curl
source: "<?php\n\n$curl = curl_init();\n\ncurl_setopt_array($curl, array(\n CURLOPT_URL => \"https://merchant.wish.com/api/v3/oauth/refresh_token?client_id=SOME_STRING_VALUE&client_secret=SOME_STRING_VALUE&refresh_token=SOME_STRING_VALUE&grant_type=SOME_STRING_VALUE\",\n CURLOPT_RETURNTRANSFER => true,\n CURLOPT_ENCODING => \"\",\n CURLOPT_MAXREDIRS => 10,\n CURLOPT_TIMEOUT => 30,\n CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n CURLOPT_CUSTOMREQUEST => \"GET\",\n CURLOPT_HTTPHEADER => array(\n \"authorization: Bearer REPLACE_BEARER_TOKEN\"\n ),\n));\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n echo \"cURL Error #:\" . $err;\n} else {\n echo $response;\n}"
- lang: shell_curl
source: "curl --request GET \\\n --url 'https://merchant.wish.com/api/v3/oauth/refresh_token?client_id=SOME_STRING_VALUE&client_secret=SOME_STRING_VALUE&refresh_token=SOME_STRING_VALUE&grant_type=SOME_STRING_VALUE' \\\n --header 'authorization: Bearer REPLACE_BEARER_TOKEN'"
- lang: java_unirest
source: "HttpResponse<String> response = Unirest.get(\"https://merchant.wish.com/api/v3/oauth/refresh_token?client_id=SOME_STRING_VALUE&client_secret=SOME_STRING_VALUE&refresh_token=SOME_STRING_VALUE&grant_type=SOME_STRING_VALUE\")\n .header(\"authorization\", \"Bearer REPLACE_BEARER_TOKEN\")\n .asString();"
- lang: javascript_jquery
source: "var settings = {\n \"async\": true,\n \"crossDomain\": true,\n \"url\": \"https://merchant.wish.com/api/v3/oauth/refresh_token?client_id=SOME_STRING_VALUE&client_secret=SOME_STRING_VALUE&refresh_token=SOME_STRING_VALUE&grant_type=SOME_STRING_VALUE\",\n \"method\": \"GET\",\n \"headers\": {\n \"authorization\": \"Bearer REPLACE_BEARER_TOKEN\"\n }\n}\n\n$.ajax(settings).done(function (response) {\n console.log(response);\n});"
- lang: python_requests
source: 'import requests
url = "https://merchant.wish.com/api/v3/oauth/refresh_token"
querystring = {"client_id":"SOME_STRING_VALUE","client_secret":"SOME_STRING_VALUE","refresh_token":"SOME_STRING_VALUE","grant_type":"SOME_STRING_VALUE"}
headers = {''authorization'': ''Bearer REPLACE_BEARER_TOKEN''}
response = requests.request("GET", url, headers=headers, params=querystring)
print(response.text)'
description: This API will generate a new token without going through the full OAuth process again. Existing access tokens will be revoked after calling this API
components:
schemas:
APIError:
required:
- code
- message
type: object
properties:
message:
type: string
code:
type: integer
format: int32
AccessToken:
required:
- access_token
- refresh_token
- expiry_time
- merchant_id
- scopes
type: object
properties:
access_token:
type: string
description: The access token needed in order to use all other marketplace APIs
scopes:
items:
type: string
type: array
description: A list of scopes granted on this token
merchant_id:
type: string
description: ID of the merchant to whom this token is linked
expiry_time:
type: string
description: 'The timestamp on when this token will expire. '
format: date-time
refresh_token:
type: string
description: The refresh token used to get a new token when current token expires
TestTokenResponse:
required:
- merchant_id
type: object
properties:
merchant_id:
type: string
description: ID of the merchant to whom the access token belongs
RetrieveAccessToken:
required:
- client_id
- client_secret
- code
- grant_type
- redirect_uri
type: object
properties:
code:
type: string
description: The authorization code you received
client_secret:
type: string
description: Your app's client secret
redirect_uri:
type: string
description: Your app's redirect uri that you specified when you created the app
client_id:
type: string
description: Your app's client ID
format: object-id
grant_type:
type: string
description: The string 'authorization_code'
securitySchemes:
OpenID:
type: openIdConnect
openIdConnectUrl: https://merchant.wish.com/oidc/.well-known/openid-configuration
OAuth2:
type: oauth2
flows:
authorizationCode:
scopes:
payments:write: Update payments
tickets:write: Write customer tickets
epc:read: read EPC info
returns:write: Write returns
returns:read: Read returns
fbw:read: Read FBW
products:read: Read products
payments:read: Read payments
fbw:write: Write FBW
merchant:write: Write merchant
products:write: Write products
ratings:read: Read ratings
videos:read: Read videos
compliance:write: Write Compliance
product_boost:read: Read ProductBoost
listing_quality:read: Read listing quality
webhook:write: Write webhook
orders:read: Read orders
compliance:read: Read Compliance
fbs:read: Read FBS
penalties:read: Read penalties
penalties:write: Update penalties
infractions:read: Read infractions
orders:write: Update orders
merchant:read: Read merchant
notifications:write: Write notifications
announcements:read: Read announcements
product_boost:write: Write ProductBoost
notifications:read: Read notifications
webhook:read: Read webhook
qoo10:read: Read Qoo10
wps_parcel:write: Write WishParcel
wps_parcel:read: Read WishParcel
tickets:read: Read customer tickets
infractions:write: Write infractions
videos:write: Write videos
epc:write: write EPC info
tokenUrl: https://merchant.wish.com/api/v3/oauth/access_token
refreshUrl: https://merchant.wish.com/api/v3/oauth/refresh_token
authorizationUrl: https://merchant.wish.com/v3/oauth/authorize
externalDocs:
url: https://merchant.wish.com/documentation/api/v3/explorer
description: API explorer
x-wish-hidden: false