RetailLink

Authentication

Three auth modes exist in the platform. Pick the right one for your client.

1. Merchant API keys

For partner / middleware integrations against /api/v1/*. Keys are hashed at rest; the plaintext secret is shown once in Admin → Settings → API credentials.

Authorization: Bearer sk_live_YOUR_KEY
# or
X-RetailLink-Access-Token: sk_live_YOUR_KEY

2. Admin / POS sessions

Staff login issues HTTP-only cookies (admin_session / pos_session). Admin UI and POS register use these. POS also uses employee # + PIN on the till lock screen (configured in Admin → User management). Do not use shop API keys inside the Admin SPA.

Cookie: admin_session=<http-only session>
# POS till
Cookie: pos_session=<http-only session>

3. Public storefront

Unauthenticated catalogue endpoints plus customer session for accounts. Payment providers use signed notify / webhook callbacks (Stripe, PayHere) — those secrets are platform-side, not merchant API keys.

curl -s "http://localhost:3003/api/public/store/omni-enterprise/products" \
  -H "Accept: application/json"

Security

Rotate keys by revoking in Admin and creating a new one. Never commit secrets. Prefer server-side calls only.