Every API here is available over the APIs.io API and to AI agents over MCP.
openapi: 3.2.0
info:
contact:
email: partner-api@wish.com
x-wish-dev-contact:
assignee: kwei
email: marketplace-external-api@contextlogic.com
description: 'Wish Marketplace V3 API
# General Information
The Wish Marketplace API will be using oAuth to authenticate in order to offer better security for its users
* Learn about oAuth here.'
version: 3.0.65
title: Wish Marketplace V3 OAuth API
servers:
- url: https://merchant.wish.com
description: V3 API endpoint
security:
- OAuth2: []
tags:
- externalDocs:
url: https://merchant.wish.com/documentation/api/v3/oauth
description: Learn more about the OAuth process
name: OAuth
paths:
/api/v3/oauth/access_token:
post:
responses:
'200':
content:
application/json:
schema:
$ref: '#/components/schemas/AccessToken'
description: successful operation
'400':
content:
application/json:
examples:
InvalidAuthCode:
value:
message: Incorrect authorization code provided
code: '10008'
InvalidParam:
value:
message: grant_type must be set to 'authorization_code'
code: '1001'
TokenRedeemed:
value:
message: The authorization code has already been redeemed
code: '10002'
TokenRevoked:
value:
message: The access token has been revoked
code: '1008'
InvalidCredentials:
value:
message: Incorrect credentials. One of client_id, client_secret, or redirect_url does not match our records
code: '10001'
AccessTokenExpired:
value:
message: The access token has expired. Please restart the OAuth process
code: '1007'
OAuthCodeExpired:
value:
message: The authorization code has expired
code: '10004'
schema:
$ref: '#/components/schemas/APIError'
description: failed request
tags:
- OAuth
summary: Retrieve an access token
requestBody:
content:
application/json:
schema:
$ref: '#/components/schemas/RetrieveAccessToken'
operationId: oauthAccessTokenPost
externalDocs:
url: https://merchant.wish.com/documentation/api/v3/oauth
description: OAuth tutorial
x-code-samples:
- lang: php_curl
source: "<?php\n\n$curl = curl_init();\n\ncurl_setopt_array($curl, array(\n CURLOPT_URL => \"https://merchant.wish.com/api/v3/oauth/access_token\",\n CURLOPT_RETURNTRANSFER => true,\n CURLOPT_ENCODING => \"\",\n CURLOPT_MAXREDIRS => 10,\n CURLOPT_TIMEOUT => 30,\n CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n CURLOPT_CUSTOMREQUEST => \"POST\",\n CURLOPT_POSTFIELDS => \"{\\\"client_id\\\":\\\"string\\\",\\\"client_secret\\\":\\\"string\\\",\\\"code\\\":\\\"string\\\",\\\"grant_type\\\":\\\"string\\\",\\\"redirect_uri\\\":\\\"string\\\"}\",\n CURLOPT_HTTPHEADER => array(\n \"authorization: Bearer REPLACE_BEARER_TOKEN\",\n \"content-type: application/json\"\n ),\n));\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n echo \"cURL Error #:\" . $err;\n} else {\n echo $response;\n}"
- lang: shell_curl
source: "curl --request POST \\\n --url 'https://merchant.wish.com/api/v3/oauth/access_token' \\\n --header 'authorization: Bearer REPLACE_BEARER_TOKEN' \\\n --header 'content-type: application/json' \\\n --data '{\"client_id\":\"string\",\"client_secret\":\"string\",\"code\":\"string\",\"grant_type\":\"string\",\"redirect_uri\":\"string\"}'"
- lang: java_unirest
source: "HttpResponse<String> response = Unirest.post(\"https://merchant.wish.com/api/v3/oauth/access_token\")\n .header(\"content-type\", \"application/json\")\n .header(\"authorization\", \"Bearer REPLACE_BEARER_TOKEN\")\n .body(\"{\\\"client_id\\\":\\\"string\\\",\\\"client_secret\\\":\\\"string\\\",\\\"code\\\":\\\"string\\\",\\\"grant_type\\\":\\\"string\\\",\\\"redirect_uri\\\":\\\"string\\\"}\")\n .asString();"
- lang: javascript_jquery
source: "var settings = {\n \"async\": true,\n \"crossDomain\": true,\n \"url\": \"https://merchant.wish.com/api/v3/oauth/access_token\",\n \"method\": \"POST\",\n \"headers\": {\n \"content-type\": \"application/json\",\n \"authorization\": \"Bearer REPLACE_BEARER_TOKEN\"\n },\n \"processData\": false,\n \"data\": \"{\\\"client_id\\\":\\\"string\\\",\\\"client_secret\\\":\\\"string\\\",\\\"code\\\":\\\"string\\\",\\\"grant_type\\\":\\\"string\\\",\\\"redirect_uri\\\":\\\"string\\\"}\"\n}\n\n$.ajax(settings).done(function (response) {\n console.log(response);\n});"
- lang: python_requests
source: "import requests\n\nurl = \"https://merchant.wish.com/api/v3/oauth/access_token\"\n\npayload = \"{\\\"client_id\\\":\\\"string\\\",\\\"client_secret\\\":\\\"string\\\",\\\"code\\\":\\\"string\\\",\\\"grant_type\\\":\\\"string\\\",\\\"redirect_uri\\\":\\\"string\\\"}\"\nheaders = {\n 'content-type': \"application/json\",\n 'authorization': \"Bearer REPLACE_BEARER_TOKEN\"\n }\n\nresponse = requests.request(\"POST\", url, data=payload, headers=headers)\n\nprint(response.text)"
description: An access token and a refresh token will be returned through this API. Your application should store both tokens. The access token is used to make authorized requests and the refresh token is used to obtain new access tokens. For security reasons, the access token will expire after 30 days. When the access token expires, please use refresh_token API to get new ones.
get:
responses:
'200':
content:
application/json:
schema:
$ref: '#/components/schemas/AccessToken'
description: successful operation
'400':
content:
application/json:
examples:
InvalidAuthCode:
value:
message: Incorrect authorization code provided
code: '10008'
InvalidParam:
value:
message: grant_type must be set to 'authorization_code'
code: '1001'
TokenRedeemed:
value:
message: The authorization code has already been redeemed
code: '10002'
TokenRevoked:
value:
message: The access token has been revoked
code: '1008'
InvalidCredentials:
value:
message: Incorrect credentials. One of client_id, client_secret, or redirect_url does not match our records
code: '10001'
AccessTokenExpired:
value:
message: The access token has expired. Please restart the OAuth process
code: '1007'
OAuthCodeExpired:
value:
message: The authorization code has expired
code: '10004'
schema:
$ref: '#/components/schemas/APIError'
description: failed request
parameters:
- required: true
in: query
description: Your app's client ID
name: client_id
schema:
type: string
format: object-id
- required: true
in: query
description: Your app's client secret
name: client_secret
schema:
type: string
- required: true
in: query
description: The authorization code you received
name: code
schema:
type: string
- required: true
in: query
description: The string 'authorization_code'
name: grant_type
schema:
type: string
- required: true
in: query
description: Your app's redirect uri that you specified when you created the app
name: redirect_uri
schema:
type: string
tags:
- OAuth
summary: Retrieve an access token
operationId: oauthAccessToken
externalDocs:
url: https://merchant.wish.com/documentation/api/v3/oauth
description: OAuth tutorial
x-code-samples:
- lang: php_curl
source: "<?php\n\n$curl = curl_init();\n\ncurl_setopt_array($curl, array(\n CURLOPT_URL => \"https://merchant.wish.com/api/v3/oauth/access_token?client_id=SOME_STRING_VALUE&client_secret=SOME_STRING_VALUE&code=SOME_STRING_VALUE&grant_type=SOME_STRING_VALUE&redirect_uri=SOME_STRING_VALUE\",\n CURLOPT_RETURNTRANSFER => true,\n CURLOPT_ENCODING => \"\",\n CURLOPT_MAXREDIRS => 10,\n CURLOPT_TIMEOUT => 30,\n CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n CURLOPT_CUSTOMREQUEST => \"GET\",\n CURLOPT_HTTPHEADER => array(\n \"authorization: Bearer REPLACE_BEARER_TOKEN\"\n ),\n));\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n echo \"cURL Error #:\" . $err;\n} else {\n echo $response;\n}"
- lang: shell_curl
source: "curl --request GET \\\n --url 'https://merchant.wish.com/api/v3/oauth/access_token?client_id=SOME_STRING_VALUE&client_secret=SOME_STRING_VALUE&code=SOME_STRING_VALUE&grant_type=SOME_STRING_VALUE&redirect_uri=SOME_STRING_VALUE' \\\n --header 'authorization: Bearer REPLACE_BEARER_TOKEN'"
- lang: java_unirest
source: "HttpResponse<String> response = Unirest.get(\"https://merchant.wish.com/api/v3/oauth/access_token?client_id=SOME_STRING_VALUE&client_secret=SOME_STRING_VALUE&code=SOME_STRING_VALUE&grant_type=SOME_STRING_VALUE&redirect_uri=SOME_STRING_VALUE\")\n .header(\"authorization\", \"Bearer REPLACE_BEARER_TOKEN\")\n .asString();"
- lang: javascript_jquery
source: "var settings = {\n \"async\": true,\n \"crossDomain\": true,\n \"url\": \"https://merchant.wish.com/api/v3/oauth/access_token?client_id=SOME_STRING_VALUE&client_secret=SOME_STRING_VALUE&code=SOME_STRING_VALUE&grant_type=SOME_STRING_VALUE&redirect_uri=SOME_STRING_VALUE\",\n \"method\": \"GET\",\n \"headers\": {\n \"authorization\": \"Bearer REPLACE_BEARER_TOKEN\"\n }\n}\n\n$.ajax(settings).done(function (response) {\n console.log(response);\n});"
- lang: python_requests
source: 'import requests
url = "https://merchant.wish.com/api/v3/oauth/access_token"
querystring = {"client_id":"SOME_STRING_VALUE","client_secret":"SOME_STRING_VALUE","code":"SOME_STRING_VALUE","grant_type":"SOME_STRING_VALUE","redirect_uri":"SOME_STRING_VALUE"}
headers = {''authorization'': ''Bearer REPLACE_BEARER_TOKEN''}
response = requests.request("GET", url, headers=headers, params=querystring)
print(response.text)'
description: An access token and a refresh token will be returned through this API. Your application should store both tokens. The access token is used to make authorized requests and the refresh token is used to obtain new access tokens. For security reasons, the access token will expire after 30 days. When the access token expires, please use refresh_token API to get new ones.
/api/v3/oauth/test:
get:
responses:
'200':
content:
application/json:
schema:
$ref: '#/components/schemas/TestTokenResponse'
description: successful operation
'400':
content:
application/json:
examples:
TokenExpired:
value:
message: This access token has expired
code: '1007'
TokenRevoked:
value:
message: This access token has been revoked
code: '1008'
CantAccessDueToAccountStatus:
value:
message: Cannot access API due to account is disabled
code: '1002'
UnauthorizedAccess:
value:
message: No access token found or the app does not existd
code: '1006'
schema:
$ref: '#/components/schemas/APIError'
description: failed request
tags:
- OAuth
description: This is a convenient endpoint for users to quickly verify if a given access token can be used.
summary: Test if an access token is valid
externalDocs:
url: https://merchant.wish.com/documentation/api/v3/oauth
description: OAuth tutorial
x-code-samples:
- lang: php_curl
source: "<?php\n\n$curl = curl_init();\n\ncurl_setopt_array($curl, array(\n CURLOPT_URL => \"https://merchant.wish.com/api/v3/oauth/test\",\n CURLOPT_RETURNTRANSFER => true,\n CURLOPT_ENCODING => \"\",\n CURLOPT_MAXREDIRS => 10,\n CURLOPT_TIMEOUT => 30,\n CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n CURLOPT_CUSTOMREQUEST => \"GET\",\n CURLOPT_HTTPHEADER => array(\n \"authorization: Bearer REPLACE_BEARER_TOKEN\"\n ),\n));\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n echo \"cURL Error #:\" . $err;\n} else {\n echo $response;\n}"
- lang: shell_curl
source: "curl --request GET \\\n --url 'https://merchant.wish.com/api/v3/oauth/test' \\\n --header 'authorization: Bearer REPLACE_BEARER_TOKEN'"
- lang: java_unirest
source: "HttpResponse<String> response = Unirest.get(\"https://merchant.wish.com/api/v3/oauth/test\")\n .header(\"authorization\", \"Bearer REPLACE_BEARER_TOKEN\")\n .asString();"
- lang: javascript_jquery
source: "var settings = {\n \"async\": true,\n \"crossDomain\": true,\n \"url\": \"https://merchant.wish.com/api/v3/oauth/test\",\n \"method\": \"GET\",\n \"headers\": {\n \"authorization\": \"Bearer REPLACE_BEARER_TOKEN\"\n }\n}\n\n$.ajax(settings).done(function (response) {\n console.log(response);\n});"
- lang: python_requests
source: 'import requests
url = "https://merchant.wish.com/api/v3/oauth/test"
headers = {''authorization'': ''Bearer REPLACE_BEARER_TOKEN''}
response = requests.request("GET", url, headers=headers)
print(response.text)'
operationId: oauthTest
/api/v3/oauth/refresh_token:
get:
responses:
'200':
content:
application/json:
schema:
$ref: '#/components/schemas/AccessToken'
description: successful operation
'400':
content:
application/json:
examples:
InvalidParam:
value:
message: grant_type must be set to 'authorization_code'
code: '1001'
UnauthorizedAccess:
value:
message: Unauthorized access on this API
code: '1006'
InvalidCredentials:
value:
message: Incorrect credentials. client_id or client_secret does not match our records
code: '10001'
CantAccessDueToAccountStatus:
value:
message: Cannot access API due to account is disabled
code: '1002'
schema:
$ref: '#/components/schemas/APIError'
description: failed request
parameters:
- required: true
in: query
description: Your app's client ID
name: client_id
schema:
type: string
format: object-id
- required: true
in: query
description: Your app's client secret
name: client_secret
schema:
type: string
- required: true
in: query
description: The refresh token
name: refresh_token
schema:
type: string
- required: true
in: query
description: The string 'refresh_token'
name: grant_type
schema:
type: string
tags:
- OAuth
summary: Obtain a new token when the current token expires
operationId: oauthRefreshToken
externalDocs:
url: https://merchant.wish.com/documentation/api/v3/oauth
description: OAuth tutorial
x-code-samples:
- lang: php_curl
source: "<?php\n\n$curl = curl_init();\n\ncurl_setopt_array($curl, array(\n CURLOPT_URL => \"https://merchant.wish.com/api/v3/oauth/refresh_token?client_id=SOME_STRING_VALUE&client_secret=SOME_STRING_VALUE&refresh_token=SOME_STRING_VALUE&grant_type=SOME_STRING_VALUE\",\n CURLOPT_RETURNTRANSFER => true,\n CURLOPT_ENCODING => \"\",\n CURLOPT_MAXREDIRS => 10,\n CURLOPT_TIMEOUT => 30,\n CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,\n CURLOPT_CUSTOMREQUEST => \"GET\",\n CURLOPT_HTTPHEADER => array(\n \"authorization: Bearer REPLACE_BEARER_TOKEN\"\n ),\n));\n\n$response = curl_exec($curl);\n$err = curl_error($curl);\n\ncurl_close($curl);\n\nif ($err) {\n echo \"cURL Error #:\" . $err;\n} else {\n echo $response;\n}"
- lang: shell_curl
source: "curl --request GET \\\n --url 'https://merchant.wish.com/api/v3/oauth/refresh_token?client_id=SOME_STRING_VALUE&client_secret=SOME_STRING_VALUE&refresh_token=SOME_STRING_VALUE&grant_type=SOME_STRING_VALUE' \\\n --header 'authorization: Bearer REPLACE_BEARER_TOKEN'"
- lang: java_unirest
source: "HttpResponse<String> response = Unirest.get(\"https://merchant.wish.com/api/v3/oauth/refresh_token?client_id=SOME_STRING_VALUE&client_secret=SOME_STRING_VALUE&refresh_token=SOME_STRING_VALUE&grant_type=SOME_STRING_VALUE\")\n .header(\"authorization\", \"Bearer REPLACE_BEARER_TOKEN\")\n .asString();"
- lang: javascript_jquery
source: "var settings = {\n \"async\": true,\n \"crossDomain\": true,\n \"url\": \"https://merchant.wish.com/api/v3/oauth/refresh_token?client_id=SOME_STRING_VALUE&client_secret=SOME_STRING_VALUE&refresh_token=SOME_STRING_VALUE&grant_type=SOME_STRING_VALUE\",\n \"method\": \"GET\",\n \"headers\": {\n \"authorization\": \"Bearer REPLACE_BEARER_TOKEN\"\n }\n}\n\n$.ajax(settings).done(function (response) {\n console.log(response);\n});"
- lang: python_requests
source: 'import requests
url = "https://merchant.wish.com/api/v3/oauth/refresh_token"
querystring = {"client_id":"SOME_STRING_VALUE","client_secret":"SOME_STRING_VALUE","refresh_token":"SOME_STRING_VALUE","grant_type":"SOME_STRING_VALUE"}
headers = {''authorization'': ''Bearer REPLACE_BEARER_TOKEN''}
response = requests.request("GET", url, headers=headers, params=querystring)
print(response.text)'
description: This API will generate a new token without going through the full OAuth process again. Existing access tokens will be revoked after calling this API
components:
schemas:
RetrieveAccessToken:
required:
- client_id
- client_secret
- code
- grant_type
- redirect_uri
type: object
properties:
code:
type: string
description: The authorization code you received
client_secret:
type: string
description: Your app's client secret
redirect_uri:
type: string
description: Your app's redirect uri that you specified when you created the app
client_id:
type: string
description: Your app's client ID
format: object-id
grant_type:
type: string
description: The string 'authorization_code'
APIError:
required:
- code
- message
type: object
properties:
message:
type: string
code:
type: integer
format: int32
TestTokenResponse:
required:
- merchant_id
type: object
properties:
merchant_id:
type: string
description: ID of the merchant to whom the access token belongs
AccessToken:
required:
- access_token
- refresh_token
- expiry_time
- merchant_id
- scopes
type: object
properties:
access_token:
type: string
description: The access token needed in order to use all other marketplace APIs
scopes:
items:
type: string
type: array
description: A list of scopes granted on this token
merchant_id:
type: string
description: ID of the merchant to whom this token is linked
expiry_time:
type: string
description: 'The timestamp on when this token will expire. '
format: date-time
refresh_token:
type: string
description: The refresh token used to get a new token when current token expires
securitySchemes:
OpenID:
type: openIdConnect
openIdConnectUrl: https://merchant.wish.com/oidc/.well-known/openid-configuration
OAuth2:
type: oauth2
flows:
authorizationCode:
scopes:
payments:write: Update payments
tickets:write: Write customer tickets
epc:read: read EPC info
returns:write: Write returns
returns:read: Read returns
fbw:read: Read FBW
products:read: Read products
payments:read: Read payments
fbw:write: Write FBW
merchant:write: Write merchant
products:write: Write products
ratings:read: Read ratings
videos:read: Read videos
compliance:write: Write Compliance
product_boost:read: Read ProductBoost
listing_quality:read: Read listing quality
webhook:write: Write webhook
orders:read: Read orders
compliance:read: Read Compliance
fbs:read: Read FBS
penalties:read: Read penalties
penalties:write: Update penalties
infractions:read: Read infractions
orders:write: Update orders
merchant:read: Read merchant
notifications:write: Write notifications
announcements:read: Read announcements
product_boost:write: Write ProductBoost
notifications:read: Read notifications
webhook:read: Read webhook
qoo10:read: Read Qoo10
wps_parcel:write: Write WishParcel
wps_parcel:read: Read WishParcel
tickets:read: Read customer tickets
infractions:write: Write infractions
videos:write: Write videos
epc:write: write EPC info
tokenUrl: https://merchant.wish.com/api/v3/oauth/access_token
refreshUrl: https://merchant.wish.com/api/v3/oauth/refresh_token
authorizationUrl: https://merchant.wish.com/v3/oauth/authorize
externalDocs:
url: https://merchant.wish.com/documentation/api/v3/explorer
description: API explorer
x-wish-hidden: false