API

Keys and permissions

Every request that touches your account carries a key. Marketplace reads don't need one.

Secret keys

Make one on resell.store/tools/api. Secret keys start with rs_live_ and can do everything you can do in the app, apart from changing where your money goes, which only you can do, signed in.

  • We show a key once, when it's made. We only keep a fingerprint of it, so we can't show it again.
  • You have one secret key at a time. Making a new one stops the old one straight away.
  • Requests made with it count towards your monthly limit (see Errors and limits).

Sending your key

Put it in the Authorization header as a bearer token. X-Api-Key: rs_live_… works too, for tools that can only set a plain header.

Terminal
curl https://api.resell.store/v1/me \
  -H "Authorization: Bearer rs_live_..."

A missing key on an endpoint that needs one answers 401 unauthorized. A key without the right permission answers 403 forbidden and names the permission it needs.

The private link on Your agent is a key too, made for AI apps. It only has the permissions you switch on there, and you can change them at any time without making a new link. Its token works as a bearer token on this API, so a script can act exactly as your agent would. See MCP.

Permissions

Each endpoint in the reference says which permission it needs. Secret keys have all of them. Reads (GET) need read unless they say otherwise.

PermissionLets the key
readSee your shops, listings, offers, sales, messages, likes, follows and stats.
shopsOpen shops and change or delete them, including their address.
listingsMake, change, publish, take down and delete listings; photos; research; writing the words.
messagesReply to conversations and mark them read.
offersAccept, decline and counter offers on your listings.
ordersMark sales shipped.
buyingLike, follow, share, make offers, message shops, get checkout links and confirm deliveries.
webhooksSet where we send events.

Never through a key

Connecting PayPal, changing where payouts go and deleting your account only happen in the app, signed in as you.

Keeping keys safe

  • Keep keys in environment variables or a secrets manager, never in code you share or in a web page.
  • Calls from a browser are allowed (CORS is open), but only do that with your own key, on your own machine.
  • If a key might have leaked, make a new one. The old one stops working at once.