For the complete documentation index, see llms.txt. This page is also available as Markdown.

Update subscription to a webhook

Management This method allows updating an existing webhook subscription. When hmacEnabled is set to true on a subscription that does not already have HMAC, the response includes a one-time plaintext HMAC secret key (whsec_ prefix). The key is never shown again — store it securely. When hmacEnabled is omitted, the HMAC state is not changed (backward compatible).

put
Authorizations
AuthorizationstringRequired

Open Loyalty has the JWT authorization. To learn what a JSON Web Token is and how it works, check out Introduction to JSON Web Tokens https://jwt.io/introduction/

Obtain an access token

Send a request with the parameters username and password

Definition

POST /api/admin/login_check Go to definition
POST /api/{storeCode}/member/login_check Go to definition

Example

curl {HOST}/api/admin/login_check
    -H 'Content-Type: application/json;charset=UTF-8'
    -H 'Accept: application/json, text/plain, */*'
    --data-binary '{"username":"admin","password":"password"}'

Example Response

{
    "token":"eyJhbGciOiJSUzI1NiIsInR5cCI6...",
    "refresh_token":"0558f8bb29948c4e54c443f..."
}

Using JSON Web Token

Add authorization header to each request
Authorization: Bearer eyJhbGciOiJSUzI1NiIsInR5cCI6...
You can now access any API method you want under the /api prefix.

Example

curl {HOST}/api/{storeCode}/analytics/members
    -H 'Accept: application/json'
    -H 'Content-type: application/x-www-form-urlencoded'
    -H 'Authorization: Bearer eyJhbGciOiJSUzI1NiIsInR5cCI6...'

Refresh JSON Web Token

You can refresh token using refresh_token that was given during login.
There are two endpoints
To refresh admin token POST /api/token/refresh Go to definition
To refresh member token POST /api/{storeCode}/token/refresh Go to definition

Path parameters
storeCodestringRequired

Store code

webhookSubscriptionstring · uuidRequired

Webhook Subscription ID

Body
or
Responses
200

HMAC was enabled on the subscription. Returns the one-time plaintext secret key. This key will never be shown again.

application/json
put/api/{storeCode}/webhook/subscription/{webhookSubscription}
PUT /api/{storeCode}/webhook/subscription/{webhookSubscription} HTTP/1.1
Host: openloyalty.localhost
Authorization: Bearer YOUR_SECRET_TOKEN
Content-Type: application/json
Accept: */*
Content-Length: 137

{
  "webhookSubscription": {
    "destinationType": "rest",
    "url": "text",
    "hmacEnabled": true,
    "headers": [
      {
        "headerName": "text",
        "headerValue": "text"
      }
    ]
  }
}
{
  "hmacSecretKey": "whsec_a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4e5f6a1b2",
  "hmacSecretKeyWarning": "This key will only be shown once. Store it securely."
}

Last updated

Was this helpful?