Authentication
Three auth modes exist in the platform. Pick the right one for your client.
1. Merchant API keys
For partner / middleware integrations against /api/v1/*. Keys are hashed at rest; the plaintext secret is shown once in Admin → Settings → API credentials.
http
Authorization: Bearer sk_live_YOUR_KEY
# or
X-RetailLink-Access-Token: sk_live_YOUR_KEY2. Admin / POS sessions
Staff login issues HTTP-only cookies (admin_session / pos_session). Admin UI and POS register use these. POS also uses employee # + PIN on the till lock screen (configured in Admin → User management). Do not use shop API keys inside the Admin SPA.
http
Cookie: admin_session=<http-only session>
# POS till
Cookie: pos_session=<http-only session>3. Public storefront
Unauthenticated catalogue endpoints plus customer session for accounts. Payment providers use signed notify / webhook callbacks (Stripe, PayHere) — those secrets are platform-side, not merchant API keys.
bash
curl -s "http://localhost:3003/api/public/store/omni-enterprise/products" \
-H "Accept: application/json"Security
Rotate keys by revoking in Admin and creating a new one. Never commit secrets. Prefer server-side calls only.