Accept a store credit offer
Accepts a pending store-credit offer on one of the customer’s own returns. The store credit is issued to the customer’s balance (spendable at checkout) and the return is finalized.
Only valid while the return has a pending store-credit offer
(credit_offer.status is pending); otherwise returns 409.
Authentication: API key in the Authorization: Bearer header and a
customer session — either x-auth-token or x-external-auth.
Authorizations
API Key Authentication
Use your API key in the Authorization header:
Key Types:
Secret Keys (Server-Side Only):
- Format:
tybrite_sk_live_*(production) ortybrite_sk_test_*(sandbox) - Full read/write access to all endpoints
- ⚠️ NEVER expose in client-side code or public repositories
- Required for: write operations, authentication, payment verification, AI recommendations
Publishable Keys (Client-Safe):
- Format:
tybrite_pk_live_*(production) ortybrite_pk_test_*(sandbox) - Read-only access (GET requests only, plus POST semantic search)
- ✅ Safe for client-side JavaScript, mobile apps, and public code
- Allowed for: browsing products, search, CMS content, pricing queries
Endpoint-Specific Requirements:
- Authentication endpoints (
/v1/auth/*): Secret key required - Payment verification (
POST /v1/payments/verify): Secret key required - AI Recommendations (
POST /v1/recommendations): Secret key required - Semantic Search (
POST /v1/search): Both key types allowed (read-only operation) - All write operations: Secret key required
- All read operations: Both key types allowed
Using a publishable key for restricted operations returns 403 Forbidden.
Headers
Provide exactly one of x-auth-token, x-external-auth, or x-idp-token.
Provide exactly one of x-auth-token, x-external-auth, or x-idp-token.
A raw token from the store's own identity provider (e.g. a Firebase ID token). Galactic Core forwards it to the store's configured Auth verifier, which validates it and returns the identity.
Verification is fail-closed: if the verifier rejects the token or is unreachable, the request is unauthenticated (401). Requires an Auth verifier to be configured for the store. Provide exactly one of x-auth-token, x-external-auth, or x-idp-token.
Path Parameters
Return UUID.
Query Parameters
Marketplace operator key only — and required for operator keys. The merchant the return belongs to. Ignored for single-store keys.
Response
Store credit accepted and issued

