Custom Storefronts
Storefront rules
The store settings, security rules, and API behaviour that a custom storefront must handle, and the go-live checklist
Read this page before you build. It lists what the API does not do for you.
Security
- Keep the client secret on your server. Do not put it in browser code, mobile applications, or a repository.
- Call the Auth API from your server only.
- Verify an access token (signature, issuer, expiry) before you trust its claims. Refer to Access tokens.
- Access tokens are valid for 9 hours and cannot be revoked. Store them carefully.
Store settings that you must apply
Your storefront must apply the settings of the store. The API does not apply all of them for you. The settings come from GET /operator.
| Setting | What your storefront must do |
|---|---|
loginStage | If it is BEFORE_PRICE, ask for sign-in before uploads and prices. |
maximumFileSize | Reject larger part files before the upload. |
| Payment methods | Show only the methods that the store and the customer type permit. Refer to Choose the payment methods. |
purchasability.canBePurchased | If it is false, offer "request a quote", not payment. |
termsOfServiceLink | Show the link where customers upload files and sign in. |
Differences from what you possibly expect
| Behaviour | Details |
|---|---|
| There is no OAuth redirect and no hosted login page. | You build the login screens. Refer to Authentication. |
| There is no refresh token and no sign-out endpoint. | Refer to Lifetime, refresh, and sign-out. |
| Part files must be compressed with gzip before the upload. | Refer to Upload parts. |
| The analysis result is MessagePack, and you can read it one time only. | Refer to Read the analysis result. |
| A guest cannot read a cart back. | Keep the cart ID and the items in your storefront. |
| A cart contains no prices. | Prices come from POST /pre-order. Refer to Get a price. |
| A quote and an order are one resource. | state changes from QUOTE to ORDER. |
| There are no webhooks or push channels for customers. | Poll for status. Refer to Order tracking. |
Go-live checklist
Credentials and tokens
- Separate storefront credentials for each environment.
- The client secret is in a secret store, not in the code.
- The client secret is only in server-side environment variables.
- All Auth API calls come from your server.
- You verify tokens (signature, issuer, expiry) before you trust claims.
- Session cookies are
HttpOnlyandSecure.
Sign-in
- Sign-up and sign-in handle
WAIT_FOR_APPROVAL. - Sign-in handles
["PASSWORD", "OTP"](two factors). - You handle
429responses. - The guest cart is claimed after sign-in and after sign-up.
- An expired token (
401) sends the customer to sign-in, or gets a new guest token. - You sign the customer out when the token expires.
Store settings and checkout
- The storefront applies
loginStageandmaximumFileSize. - Checkout handles
canBePurchased: falseand lines with no instant price. - Error handling reads the HTTP status first and accepts an empty body.
Last updated on