Set sandbox stock levels
Sets a sandbox-only stock level for one or more variants, so you can exercise low-stock and sold-out behaviour without touching the merchant’s real inventory.
A sandbox order never lowers live stock. For a variant with a level, a test key reads the level
in place of live stock everywhere stock appears — product reads, priced products, shoppable
posts and lookbooks, cart and wishlist stock checks, and checkout reservations — and a paid
sandbox order takes its quantity from the level. A level of 0 makes the variant sold out for
test keys: adding it to a cart or reserving it is refused. Setting a level again replaces it.
Send one level as { variant_id, stock }, or up to 100 as items. Every variant must belong to
your store. A live key, and the merchant’s own admin, keep reading live stock throughout.
Levels are removed with DELETE, and by POST /v1/sandbox/reset.
Requires a secret test key (tybrite_sk_test_*).
curl --request POST \
--url https://api.tybritelabs.com/v1/sandbox/stock \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"items": [
{
"variant_id": "86eb90c5-48ea-41b0-a82e-069b1b170f1e",
"stock": 0
}
]
}
'import requests
url = "https://api.tybritelabs.com/v1/sandbox/stock"
payload = { "items": [
{
"variant_id": "86eb90c5-48ea-41b0-a82e-069b1b170f1e",
"stock": 0
}
] }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({items: [{variant_id: '86eb90c5-48ea-41b0-a82e-069b1b170f1e', stock: 0}]})
};
fetch('https://api.tybritelabs.com/v1/sandbox/stock', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.tybritelabs.com/v1/sandbox/stock",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'items' => [
[
'variant_id' => '86eb90c5-48ea-41b0-a82e-069b1b170f1e',
'stock' => 0
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.tybritelabs.com/v1/sandbox/stock"
payload := strings.NewReader("{\n \"items\": [\n {\n \"variant_id\": \"86eb90c5-48ea-41b0-a82e-069b1b170f1e\",\n \"stock\": 0\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.tybritelabs.com/v1/sandbox/stock")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"items\": [\n {\n \"variant_id\": \"86eb90c5-48ea-41b0-a82e-069b1b170f1e\",\n \"stock\": 0\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.tybritelabs.com/v1/sandbox/stock")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"items\": [\n {\n \"variant_id\": \"86eb90c5-48ea-41b0-a82e-069b1b170f1e\",\n \"stock\": 0\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"stock_levels": [
{
"variant_id": "86eb90c5-48ea-41b0-a82e-069b1b170f1e",
"product_id": "f7e24571-1fa9-4264-9ca4-298de2336a35",
"name": "The Multi-managed Snowboard",
"variant_name": "Default",
"sku": "sku-managed-1",
"stock": 0,
"live_stock": 80,
"updated_at": "2026-10-03T23:14:17.072238+00:00"
}
]
}{
"error": {
"code": "invalid_request",
"message": "Invalid request parameters",
"details": "The 'email' field is required"
}
}{
"error": {
"code": "unauthorized",
"message": "Missing or invalid Authorization header"
}
}{
"error": {
"code": "forbidden",
"message": "This operation requires a secret key. Publishable keys cover catalogue reads and the actions a shopper takes for themselves."
}
}{
"error": {
"code": "not_found",
"message": "Variant 00000000-0000-4000-8000-000000000000 does not belong to this store",
"hint": "Use a variant id from GET /v1/products for this store."
}
}{
"error": {
"code": "rate_limited",
"message": "Too many requests for this API key. Please slow down and try again shortly.",
"remaining": 0,
"reset": 1706198400
}
}{
"error": {
"code": "server_error",
"message": "An unexpected error occurred"
}
}Authorizations
API Key Authentication
Use your API key in the Authorization header:
Authorization: Bearer tybrite_sk_live_YOUR_KEY
Key Types:
Secret Keys (Server-Side Only):
- Format:
tybrite_sk_live_*(production) ortybrite_sk_test_*(sandbox) - Full read/write access to all endpoints
- ⚠️ NEVER expose in client-side code or public repositories
- Required for: every write a shopper does not make for themselves, authentication, payment verification, AI recommendations
Publishable Keys (Client-Safe):
- Format:
tybrite_pk_live_*(production) ortybrite_pk_test_*(sandbox) - Catalogue reads, plus the actions a shopper takes for themselves
- ✅ Safe for client-side JavaScript, mobile apps, and public code
- Allowed for: browsing products, search, CMS content, pricing queries, cart and wishlist, reviews, storefront events, and the Agent API's quotes, cart drafts and checkout intents
Endpoint-Specific Requirements:
- Authentication endpoints (
/v1/auth/*): Secret key required - Payment verification (
POST /v1/payments/verify): Secret key required - AI Recommendations (
POST /v1/recommendations): Secret key required - Semantic Search (
POST /v1/search): Both key types allowed (read-only operation) - Shopper actions (cart, wishlist, reviews, storefront events, Agent API quotes, cart drafts and checkout intents): Both key types allowed
- All other write operations: Secret key required
- All read operations: Both key types allowed
Using a publishable key for restricted operations returns 403 Forbidden.
Body
Response
The levels as set.
Show child attributes
Show child attributes
curl --request POST \
--url https://api.tybritelabs.com/v1/sandbox/stock \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"items": [
{
"variant_id": "86eb90c5-48ea-41b0-a82e-069b1b170f1e",
"stock": 0
}
]
}
'import requests
url = "https://api.tybritelabs.com/v1/sandbox/stock"
payload = { "items": [
{
"variant_id": "86eb90c5-48ea-41b0-a82e-069b1b170f1e",
"stock": 0
}
] }
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({items: [{variant_id: '86eb90c5-48ea-41b0-a82e-069b1b170f1e', stock: 0}]})
};
fetch('https://api.tybritelabs.com/v1/sandbox/stock', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.tybritelabs.com/v1/sandbox/stock",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'items' => [
[
'variant_id' => '86eb90c5-48ea-41b0-a82e-069b1b170f1e',
'stock' => 0
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.tybritelabs.com/v1/sandbox/stock"
payload := strings.NewReader("{\n \"items\": [\n {\n \"variant_id\": \"86eb90c5-48ea-41b0-a82e-069b1b170f1e\",\n \"stock\": 0\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.tybritelabs.com/v1/sandbox/stock")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"items\": [\n {\n \"variant_id\": \"86eb90c5-48ea-41b0-a82e-069b1b170f1e\",\n \"stock\": 0\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.tybritelabs.com/v1/sandbox/stock")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"items\": [\n {\n \"variant_id\": \"86eb90c5-48ea-41b0-a82e-069b1b170f1e\",\n \"stock\": 0\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"stock_levels": [
{
"variant_id": "86eb90c5-48ea-41b0-a82e-069b1b170f1e",
"product_id": "f7e24571-1fa9-4264-9ca4-298de2336a35",
"name": "The Multi-managed Snowboard",
"variant_name": "Default",
"sku": "sku-managed-1",
"stock": 0,
"live_stock": 80,
"updated_at": "2026-10-03T23:14:17.072238+00:00"
}
]
}{
"error": {
"code": "invalid_request",
"message": "Invalid request parameters",
"details": "The 'email' field is required"
}
}{
"error": {
"code": "unauthorized",
"message": "Missing or invalid Authorization header"
}
}{
"error": {
"code": "forbidden",
"message": "This operation requires a secret key. Publishable keys cover catalogue reads and the actions a shopper takes for themselves."
}
}{
"error": {
"code": "not_found",
"message": "Variant 00000000-0000-4000-8000-000000000000 does not belong to this store",
"hint": "Use a variant id from GET /v1/products for this store."
}
}{
"error": {
"code": "rate_limited",
"message": "Too many requests for this API key. Please slow down and try again shortly.",
"remaining": 0,
"reset": 1706198400
}
}{
"error": {
"code": "server_error",
"message": "An unexpected error occurred"
}
}
