Dashboard Setup
This document explains where merchants create stores, sub-merchants, and API keys before starting an integration.
Dashboard:
https://merchant.thyris.cloud/app/merchant-services
Merchant Account
A merchant account is the top-level business account. A merchant must exist before stores, API keys, catalog products, MCP, UCP, or webhooks can be used.
Merchant accounts are normally created during onboarding or by the Thyris team. After login, users with access to more than one merchant will see an account selector.
Roles:
| Role | What It Can Usually Do |
|---|---|
owner | Manage merchant settings, team, stores, API keys, and sub-merchants. |
admin | Manage operational settings and integrations. |
member | Work with store/catalog areas depending on merchant configuration. |
viewer | Read-only access where enabled. |
For integration setup, use an owner or admin user.
Create A Store
A store is the unit that owns catalog products, carts, orders, webhooks, and store-specific integrations.
Steps:
- Sign in to the Merchant Dashboard.
- Select the merchant account.
- Open
Stores. - Click
Create Store. - Fill the required fields.
- Click
Create Store.
Store fields:
| Field | Required | Notes |
|---|---|---|
| Name | Yes | Display name for the store. |
| URL | No | Public store URL, for example https://store.example.com. |
| Description | No | Short store description. |
| Logo URL | No | Public logo image URL. |
| Type | Yes | E-Commerce, Travel, or Generic. Defaults to E-Commerce. |
| Category | No | Store category such as Fashion, Electronics, Beauty, etc. |
| Currency | Yes | Currently USD, EUR, or TRY. |
| Language | Yes | Store language. Defaults to English. |
After the store is created, open the store or call GET /api/v1/catalog/stores with an API key to get the storeId.
Find Store IDs
The easiest API-safe way to find store IDs is:
curl "https://merchant.thyris.cloud/api/v1/catalog/stores" \
-H "Authorization: Bearer tr_live_your_key_here"
Response:
{
"success": true,
"data": [
{
"id": "store_uuid",
"name": "Main Store",
"slug": "main-store",
"merchantId": "merchant_uuid",
"currency": "USD",
"language": "en"
}
]
}
Use id as storeId in product, cart, order, webhook, UCP, and MCP requests.
Create A Sub-Merchant
Sub-merchants are child merchant accounts under a main merchant. Use them for branches, subsidiaries, regional sellers, marketplace sellers, or separate business units.
Steps:
- Sign in as an owner of the main merchant.
- Open the account selector.
- Click
Create Sub-merchant. - Enter the sub-merchant name.
- Create stores under the sub-merchant if needed.
Sub-merchant stores can be included in integrations only when the API key scope allows them.
Create An API Key
API keys are created from the merchant's Developers page.
Steps:
- Sign in to the Merchant Dashboard.
- Select the merchant account.
- Open
Developers. - Click
Create New Key. - Enter a key name, for example
Production ERP Sync. - Choose the access scope.
- Select stores if the chosen scope requires it.
- Choose a lifetime in minutes, hours, days, months, or years, or choose
Never. - Click create.
- Copy the generated key immediately.
The full key is shown only once. If it is lost, create a new key and revoke the old one. The Developers page is dedicated to API key management; the former Integration Sources section has been removed.
The key table shows scopes as plain text, uses a three-dot menu for Revoke/Delete, displays expiration and revocation dates in English, and does not add a decorative key icon to each row. Reopening Create New Key starts a fresh form and never reuses the previously generated secret screen.
Key format:
tr_live_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
API Key Types
| Dashboard Label | API Scope | Best For | Store Access |
|---|---|---|---|
| Merchant stores only | merchant | Main merchant ERP/PIM sync, dashboard-owned stores | Stores owned directly by the selected merchant. Does not include sub-merchants. |
| Single store | store | One store integration, one agency/vendor, least-privilege setup | Exactly one selected store. |
| Merchant + sub-merchants | merchant_network | Marketplace, franchise, or merchant group sync | Main merchant stores and all sub-merchant stores. |
| Custom stores | custom | Selective rollout, partial migration, vendor-limited access | Only the selected stores, including accessible sub-merchant stores when selected. |
Which Key Type Should I Use?
Use this rule of thumb:
| Scenario | Recommended Key |
|---|---|
| A single commerce platform/commerce platform store syncs only itself | Single store |
| A central ERP syncs all stores of the main merchant | Merchant stores only |
| A marketplace operator syncs main merchant and seller/sub-merchant stores | Merchant + sub-merchants |
| A migration starts with two pilot stores | Custom stores |
| An AI/MCP client should only see one store | Single store |
| A customer support tool should read a selected set of stores | Custom stores |
Prefer the narrowest key that supports the integration.
What Each Key Can Access
| Operation | Merchant | Store | Merchant Network | Custom |
|---|---|---|---|---|
| List stores | Main merchant stores | Selected store | Main + sub-merchant stores | Selected stores |
| Product read/write | Main merchant stores | Selected store | Main + sub-merchant stores | Selected stores |
| Cart create/list | Main merchant stores | Selected store | Main + sub-merchant stores | Selected stores |
| Order create/list/update | Main merchant stores | Selected store | Main + sub-merchant stores | Selected stores |
| Inbound webhook product sync | Main merchant stores | Selected store | Main + sub-merchant stores | Selected stores |
| MCP catalog tools | Main merchant stores | Selected store | Main + sub-merchant stores | Selected stores |
| UCP catalog endpoints | Main merchant stores | Selected store | Main + sub-merchant stores | Selected stores |
Scope is enforced server-side. If a request includes a storeId outside the key's scope, the API returns 403.
Revoke Or Rotate A Key
Use key rotation when a key is exposed, shared with the wrong party, or no longer needed.
Steps:
- Open
Developers. - Find the key.
- Create a replacement key if the integration must continue.
- Deploy the replacement key to the integration.
- Revoke the old key.
- Confirm the old key returns
401.
Revocation records the revocation date and cannot be undone. A key, active or expired, must be revoked before permanent deletion. For multiple keys, select rows and use Bulk Actions: revoke applies to the non-revoked keys in the selection, and delete is available only when every selected key is already revoked.
Large Table And Image Management
- Catalog Products, Procurement Inventory, and Procurement Suppliers tables support checkbox selection and bulk deletion. Bulk Actions is unavailable until at least one row is selected.
- Product and procurement inventory detail forms accept an optional ordered image gallery. A record may have no images, one legacy
imageUrl, or up to 20imageUrls; the first gallery item is the primary image. - Destructive table actions use the dashboard's standard confirmation popup. Native browser alert/confirm banners are not used.
Setup Checklist
- Merchant account exists.
- Integrating user has
owneroradminaccess. - Store exists.
- Store ID is known.
- API key is created with the correct scope.
- API key was copied and stored securely.
GET /api/v1/catalog/storesreturns the expected stores.- Postman environment has
baseUrl,apiKey, andstoreIdset.