The v3 data endpoint is authenticated with a bearer token that is scoped to
a single store.
Getting your credentials
API token
To create an API token:
- Log in to your Redo Dashboard
- Go to Settings → Developer
- In API tokens, click Create token, then name it and choose its scopes
- Copy the token from the confirmation dialog. It starts with
redo_sk_.
Store your API token securely. It is only shown once, when created.
Store ID
Your Store ID is part of the data endpoint path. It is shown in the General
section of Settings → Developer in the Redo Dashboard.
Making authenticated requests
Send every operation as a POST to the data endpoint for your store, with the
token in the Authorization header:
The token is checked against the store in the path. A malformed header, an
unknown token, and a token that belongs to a different store all fail the same
way, with HTTP 401 and an Unauthorized error, so they cannot be told apart:
Never share your API token publicly or commit it to version control.
Scopes
Tokens carry scopes that determine which fields they may read or write.
Because a nested field’s scope adds to its parent’s, a request needs the union
of every scope along its selection paths. A request that selects any field its
token is not scoped for is rejected before it runs, with HTTP 403 and the
error code INSUFFICIENT_SCOPE.
Choose a token’s scopes in Settings → Developer when you create it, and
grant only the scopes it needs. See
Access scopes for the full list, and
the Required scopes on each query, mutation, and field in the reference.
Introspection without a token
The schema endpoint
(https://api.getredo.com/v3/graphql-schema) is unauthenticated and exposes the
schema only, never store data. Use it to explore types and generate clients
without a token.