Update existing tier list with conditions
Open Loyalty has the JWT authorization. To learn what a JSON Web Token is and how it works, check out Introduction to JSON Web Tokens https://jwt.io/introduction/
Obtain an access token
Send a request with the parameters username and password
Definition
POST /api/admin/login_check Go to definition
POST /api/{storeCode}/member/login_check Go to definition
Example
curl {HOST}/api/admin/login_check
-H 'Content-Type: application/json;charset=UTF-8'
-H 'Accept: application/json, text/plain, */*'
--data-binary '{"username":"admin","password":"password"}'
Example Response
{
"token":"eyJhbGciOiJSUzI1NiIsInR5cCI6...",
"refresh_token":"0558f8bb29948c4e54c443f..."
}
Using JSON Web Token
Add authorization header to each request
Authorization: Bearer eyJhbGciOiJSUzI1NiIsInR5cCI6...
You can now access any API method you want under the /api prefix.
Example
curl {HOST}/api/{storeCode}/analytics/members
-H 'Accept: application/json'
-H 'Content-type: application/x-www-form-urlencoded'
-H 'Authorization: Bearer eyJhbGciOiJSUzI1NiIsInR5cCI6...'
Refresh JSON Web Token
You can refresh token using refresh_token that was given during login.
There are two endpoints
To refresh admin token POST /api/token/refresh Go to definition
To refresh member token POST /api/{storeCode}/token/refresh Go to definition
Store code
TierSet ID
Success. No content.
No content
Bad request. Same envelope as the shared BadRequest response, with one addition specific to the tier list editor: when a tier is refused because a campaign references it, the error carries the campaigns standing in the way so the panel can link to them.
For guard refusals path is the id of the blocked tier — a tier removed from the submitted list has no field path to report — and code is a stable slug (delete_default_tier, delete_tier_has_members, delete_tier_used_in_campaign_visibility, delete_tier_used_in_campaign_effect, deactivate_tier_used_in_campaign_visibility, deactivate_tier_used_in_campaign_effect). Plain field-validation errors keep reporting a field path and carry no campaigns.
Leaving a tier out of the submitted list deletes it, and the default tier cannot be deleted. A list that names existing tiers by levelId and leaves the default tier out is therefore refused with delete_default_tier — that list is editing the tiers that exist, so the omission is a delete. A list of nothing but new tiers is defining the set rather than editing it, and leaving the default tier out of one has always meant "I do not manage it": it is kept, and the request succeeds.
Unauthorized
Forbidden.
Not found.
PUT /api/{storeCode}/tierSet/{tierSet}/tiers HTTP/1.1
Host: openloyalty.localhost
Authorization: Bearer YOUR_SECRET_TOKEN
Content-Type: application/json
Accept: */*
Content-Length: 486
{
"tiers": [
{
"levelId": "123e4567-e89b-12d3-a456-426614174000",
"translations": {
"en": {
"name": "text",
"description": "text"
},
"pl": {
"name": "text",
"description": "text"
}
},
"active": true,
"conditions": [
{
"conditionId": "123e4567-e89b-12d3-a456-426614174000",
"value": 1
}
],
"rewards": [
{
"rewardId": "123e4567-e89b-12d3-a456-426614174000",
"name": "text",
"value": 1,
"code": "text",
"labels": [
{
"key": "text",
"value": "text"
}
],
"active": true,
"startAt": "2026-01-01T00:00:00.000Z",
"endAt": "2026-01-01T00:00:00.000Z"
}
]
}
]
}No content
Last updated
Was this helpful?

