Skip to main content
POST
Create a standing instruction

Authorizations

Authorization
string
header
required

API Key Authentication

Use your API key in the Authorization header:

Key Types:

Secret Keys (Server-Side Only):

  • Format: tybrite_sk_live_* (production) or tybrite_sk_test_* (sandbox)
  • Full read/write access to all endpoints
  • ⚠️ NEVER expose in client-side code or public repositories
  • Required for: every write a shopper does not make for themselves, authentication, payment verification, AI recommendations

Publishable Keys (Client-Safe):

  • Format: tybrite_pk_live_* (production) or tybrite_pk_test_* (sandbox)
  • Catalogue reads, plus the actions a shopper takes for themselves
  • ✅ Safe for client-side JavaScript, mobile apps, and public code
  • Allowed for: browsing products, search, CMS content, pricing queries, cart and wishlist, reviews, storefront events, and the Agent API's quotes, cart drafts and checkout intents

Endpoint-Specific Requirements:

  • Authentication endpoints (/v1/auth/*): Secret key required
  • Payment verification (POST /v1/payments/verify): Secret key required
  • AI Recommendations (POST /v1/recommendations): Secret key required
  • Semantic Search (POST /v1/search): Both key types allowed (read-only operation)
  • Shopper actions (cart, wishlist, reviews, storefront events, Agent API quotes, cart drafts and checkout intents): Both key types allowed
  • All other write operations: Secret key required
  • All read operations: Both key types allowed

Using a publishable key for restricted operations returns 403 Forbidden.

Headers

x-auth-token
string

Customer session token from POST /v1/auth/login or POST /v1/auth/verify-otp. Provide exactly one of x-auth-token, x-external-auth, or x-idp-token.

x-external-auth
string

Bring-your-own-auth assertion identifying the customer. Provide exactly one of x-auth-token, x-external-auth, or x-idp-token.

x-idp-token
string

A raw token from the store's own identity provider, verified by the store's configured Auth verifier. Provide exactly one of x-auth-token, x-external-auth, or x-idp-token.

Body

application/json
kind
enum<string>
required
Available options:
reorder,
price_drop,
back_in_stock
variant_id
string<uuid>
required
max_unit_price
number
required

The most the shopper will pay per unit, in the store's currency.

shipping_address
object
required

Where to deliver: line1 (or latitude/longitude) and country are required.

quantity
integer

Defaults to 1.

Required range: 1 <= x <= 10
interval_days
integer

Required for reorder; not allowed otherwise.

Required range: 7 <= x <= 365
max_triggers
integer

reorder only: how many times it may fire. Defaults to 1.

Required range: 1 <= x <= 12
expires_in_days
integer

Defaults to 180.

Required range: 1 <= x <= 365

Response

The standing instruction was created

data
object
required
evidence
object[]
required
computed_at
string<date-time>
required
environment
enum<string>
required
Available options:
production,
sandbox
currency
string | null