Quickstart
Create a key and make your first API request in five minutes.
You'll need a store on the Pro plan or above, and permission to manage API keys.
Open APIs & Webhooks
In your dashboard, go to Settings and open APIs & Webhooks.
Create an API key
On the API keys tab, choose Create API key.
API keys
Let your own systems read and update this store.
0 of 5 keys used
Choose what the key may do
Name the key after what will use it, then pick its access. Start with Read only — you can always create a key with more access later. You can only grant access you have yourself in the dashboard.
Create API key
Name
Copy the key
The full key is shown once. Copy it into your server's environment
variables, e.g. ZAHER_API_KEY. If you lose it, revoke it and create a new
one.
Copy your API key now
This is the only time the full key is shown. Store it somewhere safe.
zk_live_4f7Qm9xKp2LwR8vT1nYc6bHs3dJe0aGu CopyMake your first request
GET/v1/storeAny valid key can call it. It returns the store the key belongs to and what the key may do:
curl https://api.zaher.io/v1/store \
-H "Authorization: Bearer $ZAHER_API_KEY"{
"object": "store",
"name": "Sara's Shop",
"currency": "SAR",
"plan": "pro",
"api_key": {
"name": "ERP sync",
"prefix": "zk_live_ab12",
"scopes": ["orders:read", "bookings:read", "products:read", "customers:read"],
"expires_at": null
}
}List your latest orders
GET/v1/orderscurl "https://api.zaher.io/v1/orders?limit=5" \
-H "Authorization: Bearer $ZAHER_API_KEY"Lists return { "object": "list", "data": [...], "has_more", "next_cursor" }.
See Pagination to walk through every page.
Make a change
POST/v1/orders/{id}/fulfillmentWriting needs a key with a :write scope. Mark an order as shipped:
curl https://api.zaher.io/v1/orders/ORDER_ID/fulfillment \
-X POST \
-H "Authorization: Bearer $ZAHER_API_KEY" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: shipment-1042" \
-d '{ "fulfillment_status": "shipped", "tracking_number": "AWB123456789" }'The customer is notified and your order.* webhooks fire, exactly as when
the change is made in the dashboard. The Idempotency-Key makes it safe to
retry — see Idempotency.
In code
const API = "https://api.zaher.io/v1";
export async function zaher<T>(path: string, init: RequestInit = {}) {
const response = await fetch(`${API}${path}`, {
...init,
headers: {
Authorization: `Bearer ${process.env.ZAHER_API_KEY}`,
"Content-Type": "application/json",
...init.headers,
},
});
const body = await response.json();
if (!response.ok) {
// { error: { type, code, message, param, request_id } }
throw new Error(`${body.error.code}: ${body.error.message}`);
}
return body as T;
}
const store = await zaher<{ name: string }>("/store");