# ShopBack

**Canonical:** https://apis.io/providers/shopback/  
**Website:** https://www.shopback.com/  
**APIs profiled:** 5

ShopBack is a Singapore-headquartered shopping, rewards and payments platform founded in 2014, operating across 13 markets in Asia-Pacific, Europe and the United States with more than 20 million members and 20,000 merchant partners. Alongside its consumer cashback and discovery app, ShopBack runs a merchant-facing payments business — ShopBack Pay and ShopBack PayLater — and publishes a public developer hub at docs.shopback.com covering two REST APIs. The Online Payments API (v2.0, also called the Online Bespoke API) handles merchant login, order initiation, order status, refunds, and a tokenized-payments surface for account linking, pre-authorization hold/capture/void, immediate charge and cashback-balance lookup. The In-Store Payments API (v1.4) covers merchant-presented and customer-presented QR ordering, order status, refunds, cancellations, and a payment-notification webhook for point-of-sale and customer-facing app checkout. Both are HMAC- or JWT-authenticated over HTTPS/TLS 1.2+, support an X-ShopBack-Idempotent-Id idempotency header, and ship e-commerce plugins for Shopify, WooCommerce, Magento, PrestaShop, EasyStore and Salesforce Commerce Cloud.

## Kin Score — 50.1 / 100 (developing)

Scored 2026-08-25 under rubric 0.14.0. Trend: flat (+0.0 from 50.1).

| Facet | Score |
|---|---|
| Discoverability | 81.5 |
| Contract Quality | 59.6 |
| Governance | 16.7 |
| Contract Governance | 16.7 |
| Operational Transparency | 42.1 |
| Developer Ergonomics | 49.4 |
| Commercial Clarity | 31.6 |
| Access Clarity | 31.6 |

Regulatory layer — **Payments**: 54.7 (matched via tags).

## Agent readiness — 37.2 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | no |
| Reversibility Documented | documented |
| MCP Server | no |
| Auth Clarity | bearer |
| Idempotency | verified |
| Error Semantics | verified |
| OpenAPI Examples | partial |
| Rate Limit Signal | no |
| Event Surface Described | yes |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | no |
| Agent Card | no |
| Dry Run Mode | no |
| Delegated Identity | no |
| Protected Resource Metadata | no |
| Dynamic Client Registration | no |
| Agentic Commerce | no |

## APIs (5)

- **ShopBack Account Linking API** — The Account Linking API from ShopBack — 4 operation(s) for account linking.
- **ShopBack Authentication API** — The Authentication API from ShopBack — 1 operation(s) for authentication.
- **ShopBack Notification API** — The Notification API from ShopBack — 1 operation(s) for notification.
- **ShopBack Orders API** — The Orders API from ShopBack — 8 operation(s) for orders.
- **ShopBack Pre Auth API** — The Pre-Auth API from ShopBack — 6 operation(s) for pre-auth.

## MCP servers (1)

- **ShopBack MCP Server**

## Security (2)

- **Shopback Authentication** — http/hmac/apiKey · 3 schemes
- **Shopback Domain Security** — TLSv1.3 · HSTS · DMARC

## Tags

Company, Payments, Cashback, Rewards, Loyalty, E-Commerce, Buy Now Pay Later, Point-of-Sale, Checkout, Singapore

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/shopback/). Scores are computed from the provider's own public artifacts under a published rubric.
