Create a standing instruction
Leaves a standing instruction for the shopper, bounded on every side: reorder an item every interval_days
(7–365, at most 12 times), or watch for it to come back in stock (back_in_stock) or to reach a price (price_drop) —
always at or below max_unit_price per unit. When the condition holds, Galactic Core prepares a hosted checkout
intent for the shopper, sends the agent.mandate.triggered webhook event with its confirmation link, and emails the
shopper that link under the store’s own name. The shopper confirms; nothing is paid without them, and a prepared
checkout stays open for 48 hours. Requires the shopper’s credential and personalization consent. A shopper can keep
at most 10 with one store; a mandate pauses if consent is withdrawn.
Authorizations
API Key Authentication
Use your API key in the Authorization header:
Key Types:
Secret Keys (Server-Side Only):
- Format:
tybrite_sk_live_*(production) ortybrite_sk_test_*(sandbox) - Full read/write access to all endpoints
- ⚠️ NEVER expose in client-side code or public repositories
- Required for: every write a shopper does not make for themselves, authentication, payment verification, AI recommendations
Publishable Keys (Client-Safe):
- Format:
tybrite_pk_live_*(production) ortybrite_pk_test_*(sandbox) - Catalogue reads, plus the actions a shopper takes for themselves
- ✅ Safe for client-side JavaScript, mobile apps, and public code
- Allowed for: browsing products, search, CMS content, pricing queries, cart and wishlist, reviews, storefront events, and the Agent API's quotes, cart drafts and checkout intents
Endpoint-Specific Requirements:
- Authentication endpoints (
/v1/auth/*): Secret key required - Payment verification (
POST /v1/payments/verify): Secret key required - AI Recommendations (
POST /v1/recommendations): Secret key required - Semantic Search (
POST /v1/search): Both key types allowed (read-only operation) - Shopper actions (cart, wishlist, reviews, storefront events, Agent API quotes, cart drafts and checkout intents): Both key types allowed
- All other write operations: Secret key required
- All read operations: Both key types allowed
Using a publishable key for restricted operations returns 403 Forbidden.
Headers
Customer session token from POST /v1/auth/login or POST /v1/auth/verify-otp. Provide exactly one of x-auth-token, x-external-auth, or x-idp-token.
Bring-your-own-auth assertion identifying the customer. Provide exactly one of x-auth-token, x-external-auth, or x-idp-token.
A raw token from the store's own identity provider, verified by the store's configured Auth verifier. Provide exactly one of x-auth-token, x-external-auth, or x-idp-token.
Body
reorder, price_drop, back_in_stock The most the shopper will pay per unit, in the store's currency.
Where to deliver: line1 (or latitude/longitude) and country are required.
Defaults to 1.
1 <= x <= 10Required for reorder; not allowed otherwise.
7 <= x <= 365reorder only: how many times it may fire. Defaults to 1.
1 <= x <= 12Defaults to 180.
1 <= x <= 365
