API
Keys and permissions
Secret keys
Make one on resell.store/tools/api. Secret keys start with rs_live_ and can do everything you can do in the app, apart from changing where your money goes, which only you can do, signed in.
- We show a key once, when it's made. We only keep a fingerprint of it, so we can't show it again.
- You have one secret key at a time. Making a new one stops the old one straight away.
- Requests made with it count towards your monthly limit (see Errors and limits).
Sending your key
Put it in the Authorization header as a bearer token. X-Api-Key: rs_live_… works too, for tools that can only set a plain header.
curl https://api.resell.store/v1/me \
-H "Authorization: Bearer rs_live_..."A missing key on an endpoint that needs one answers 401 unauthorized. A key without the right permission answers 403 forbidden and names the permission it needs.
Agent links
The private link on Your agent is a key too, made for AI apps. It only has the permissions you switch on there, and you can change them at any time without making a new link. Its token works as a bearer token on this API, so a script can act exactly as your agent would. See MCP.
Permissions
Each endpoint in the reference says which permission it needs. Secret keys have all of them. Reads (GET) need read unless they say otherwise.
| Permission | Lets the key |
|---|---|
read | See your shops, listings, offers, sales, messages, likes, follows and stats. |
shops | Open shops and change or delete them, including their address. |
listings | Make, change, publish, take down and delete listings; photos; research; writing the words. |
messages | Reply to conversations and mark them read. |
offers | Accept, decline and counter offers on your listings. |
orders | Mark sales shipped. |
buying | Like, follow, share, make offers, message shops, get checkout links and confirm deliveries. |
webhooks | Set where we send events. |
Never through a key
Keeping keys safe
- Keep keys in environment variables or a secrets manager, never in code you share or in a web page.
- Calls from a browser are allowed (CORS is open), but only do that with your own key, on your own machine.
- If a key might have leaked, make a new one. The old one stops working at once.