Skip to main content

Request Field Requirements

This document lists required and optional values for each customer-facing integration request.

All authenticated requests require one API key header:

Authorization: Bearer tr_live_your_key_here

or:

x-api-key: tr_live_your_key_here

REST Catalog API​

Base URL:

https://merchant.thyris.cloud/api/v1/catalog

GET /stores​

Lists stores available to the API key.

Required:

LocationFieldNotes
HeaderAPI keyRequired for authentication.

Optional:

LocationFieldNotes
QueryqSearch by store name, slug, or ID.

GET /products​

Lists or searches products.

Required:

LocationFieldNotes
HeaderAPI keyRequired for authentication.

Optional:

LocationFieldNotes
QuerystoreIdLimits results to one store. Store-scoped keys default to their bound store.
QueryqSearches name, SKU, external ID, and catalog ID.

POST /products​

Creates or upserts a product.

Required:

LocationFieldTypeNotes
HeaderAPI keystringRequired for authentication.
BodystoreIdUUID stringTarget store. Must be accessible by the API key.
BodynamestringProduct name.
BodypricenumberMust be 0 or greater.

Optional:

FieldTypeDefaultNotes
skustringnullIdempotency key within the store. Max 120 chars.
externalIdstringnullSource system ID. Idempotency key within the store. Max 255 chars.
descriptionstringnullProduct description.
currencystringUSDExactly 3 letters.
statusstringactivedraft, active, or archived.
inStockbooleantrueStock availability.
inventoryQuantityinteger0Must be 0 or greater.
imageUrlURL stringnullLegacy primary image URL; synchronized with the first imageUrls entry.
imageUrlsURL string[]nullOptional ordered gallery, maximum 20 URLs. The first URL is primary.
productUrlURL stringnullPublic product page URL.
metadataobjectnullInternal integration metadata.
otherDetailsobjectnullFlexible product attributes.
variantsarray[]Product variant objects.

Required variant fields:

FieldTypeNotes
namestringVariant name.
pricenumberMust be 0 or greater.

Optional variant fields:

FieldTypeDefault
skustringnull
externalIdstringnull
descriptionstringnull
currencystringUSD
statusstringactive
inStockbooleantrue
inventoryQuantityinteger0
imageUrlURL stringnull
productUrlURL stringnull
otherDetailsobjectnull

GET /products/{productId}​

Gets one product by Thyris product UUID.

Required:

LocationFieldNotes
HeaderAPI keyRequired for authentication.
PathproductIdInternal product UUID returned by create/list/search.

Optional: none.

GET /product-details​

Gets the complete authorized product record directly from Merchant Catalog. No ACP Runtime or Flow execution is involved.

Required:

LocationFieldNotes
HeaderAPI keyRequired for authentication and merchant/store scope.
QueryOne of catalogId, productId, sku, or externalIdPrefer the ten-digit catalogId returned by search.

Optional:

LocationFieldNotes
QuerystoreIdRestricts lookup to one accessible store; recommended for SKU or external-ID lookup.

Product list, search, legacy lookup, and detail responses include store plus a public merchant object. The merchant object exposes only id, name, slug, description, logoUrl, websiteUrl, industry, and language.

storefront UI profile rule: a renderable product requires non-empty catalogId, name, price, currency, imageUrl, merchant.name, and merchant.logoUrl. merchant.websiteUrl is present in the response shape but may be null, because it cannot be guaranteed for every merchant. Enforce the required values at merchant onboarding/catalog synchronization or exclude the incomplete item from storefront render results.

PATCH /products/{productId}​

Updates one product.

Required:

LocationFieldNotes
HeaderAPI keyRequired for authentication.
PathproductIdInternal product UUID.

Optional body fields:

FieldTypeNotes
storeIdUUID stringMove/update target store if key can access it.
skustring or nullReplaces SKU.
externalIdstring or nullReplaces external ID.
namestringReplaces name.
descriptionstring or nullReplaces description.
pricenumberReplaces price.
currencystringExactly 3 letters.
statusstringdraft, active, or archived.
inStockbooleanReplaces stock status.
inventoryQuantityintegerReplaces stock quantity.
imageUrlURL string or empty stringReplaces image URL.
imageUrlsURL string[] or nullReplaces the ordered gallery; maximum 20 valid URLs. First URL becomes primary.
productUrlURL string or empty stringReplaces product URL.
metadataobject or nullReplaces metadata.
otherDetailsobject or nullReplaces flexible attributes.
variantsarrayReplaces variants.

At least one body field should be provided.

inventoryQuantity replaces the current quantity with an absolute snapshot. It must not be interpreted as “subtract this amount.” Use source event/version metadata to prevent duplicate or out-of-order updates from changing stock twice.

DELETE /products/{productId}​

Deletes one product by Thyris product UUID.

Required:

LocationFieldNotes
HeaderAPI keyRequired for authentication.
PathproductIdInternal product UUID.

Optional: none.

GET /carts​

Lists carts.

Required:

LocationFieldNotes
HeaderAPI keyRequired for authentication.

Optional:

LocationFieldNotes
QuerystoreIdLimits results to one store. Store-scoped keys default to their bound store.

POST /carts​

Creates a checkout-ready cart.

Required:

LocationFieldTypeNotes
HeaderAPI keystringRequired for authentication.
BodystoreIdUUID stringTarget store.
BodyitemsarrayOne or more cart items. Max 100 items.
Body itemcatalogIdstring10 digit product catalog ID. Not the product UUID.
Body itemquantityintegerMust be 1 or greater.

Optional:

FieldTypeDefaultNotes
metadataobjectnullInternal cart metadata.
otherDetailsobjectnullChannel/agent context.
Item metadataobjectnullInternal line-item metadata.
Item otherDetailsobjectnullLine-item context.

POST/PATCH/DELETE /carts/items​

Mutates an existing open cart after creation. POST adds items, PATCH replaces quantities, and DELETE removes lines. Single item fields and bundle items[] are both supported.

Required:

LocationFieldTypeNotes
HeaderAPI keystringRequired for authentication.
HeaderIdempotency-KeystringRequired for safe write replay.
BodycartIdUUID stringTarget cart.
Bodyitems[] or single catalogId/itemIdarray/stringBundle or single-item mutation.
Body itemquantityintegerRequired for add/update; must be 1 or greater.

Optional:

FieldTypeNotes
Body item metadataobjectInternal line metadata for add.
Body item otherDetailsobjectLine context for add.
Body itemIds[]arrayDelete multiple lines by item UUID.

POST /carts/clear?cartId={cartId}​

Clears cart line items only when no checkout ID exists.

Required:

LocationFieldNotes
HeaderAPI keyRequired for authentication.
QuerycartIdInternal cart UUID.

Optional: none.

POST /carts/archive?cartId={cartId}​

Archives a cart permanently. Archived carts cannot be reopened or mutated.

Required:

LocationFieldNotes
HeaderAPI keyRequired for authentication.
Query or bodycartIdInternal cart UUID.

Optional: none.

GET /orders​

Lists orders.

Required:

LocationFieldNotes
HeaderAPI keyRequired for authentication.

Optional:

LocationFieldNotes
QuerystoreIdLimits results to one store.
QueryqSearches order ID, checkout ID, and payment ID.

POST /orders​

Completes an order from a checkout ID.

Required:

LocationFieldTypeNotes
HeaderAPI keystringRequired for authentication.
BodycheckoutIdstringCheckout ID returned by cart creation.
BodycustomerobjectCustomer data.
BodyshippingAddressobjectShipping address data.

Optional:

FieldTypeDefaultNotes
billingAddressobjectnullBilling address data.
paymentobjectgenerated referenceOptional safe payment reference. When omitted, Catalog generates an internal payment ID.
payment.idstringgeneratedExisting non-sensitive payment reference when the caller has one.
payment.providerstringomittedOptional provider name inside the payment object.
payment.statusstringomittedOptional; when supplied it must be paid.
metadataobjectnullInternal order metadata.
otherDetailsobjectnullIntegration-specific order data.

Recommended customer fields:

FieldRequired By APINotes
nameNoStrongly recommended.
emailNoStrongly recommended.
phoneNoOptional.

Recommended address fields:

FieldRequired By APINotes
line1NoStrongly recommended.
cityNoStrongly recommended.
countryNoStrongly recommended. Use ISO country code when possible.
postalCodeNoStrongly recommended when applicable.

GET /orders/{orderId}​

Gets one order.

Required:

LocationFieldNotes
HeaderAPI keyRequired for authentication.
PathorderIdInternal order UUID, public orderId, or checkoutId.

Optional: none.

PATCH /orders/{orderId}​

Updates order details or status.

Required:

LocationFieldNotes
HeaderAPI keyRequired for authentication.
PathorderIdInternal order UUID, public orderId, or checkoutId.

Optional body fields:

FieldTypeNotes
statusstringcompleted or cancelled.
customerobjectReplaces customer data.
shippingAddressobjectReplaces shipping address.
billingAddressobject or nullReplaces billing address.
paymentDetailsobject or nullReplaces payment details.
metadataobject or nullReplaces metadata.
otherDetailsobject or nullReplaces other details.

At least one body field should be provided.

Inbound Catalog Webhook​

Endpoint:

POST https://webhooks.thyris.cloud/webhooks/catalog

Product Create/Update/Upsert Events​

Events:

  • product.created
  • product.updated
  • product.upserted
  • product.inventory.updated
  • product.price.updated
  • catalog.batch.upserted

Required:

LocationFieldTypeNotes
HeaderAPI keystringRequired for authentication.
BodyeventstringOne of the supported events.
Bodyproduct or productsobject or arraySingle product or product array.
ProductstoreIdUUID stringTarget store.
ProductnamestringRequired for create/update/upsert events.
ProductpricenumberRequired for create/update/upsert events.

Optional:

FieldTypeNotes
sourcestringSource system label, for example shopify, erp, or pim.
directionstringDefaults to inbound.
Product skustringIdempotency key.
Product externalIdstringIdempotency key.
Product descriptionstringProduct description.
Product currencystringDefaults to USD.
Product statusstringDefaults to active.
Product inStockbooleanDefaults to true.
Product inventoryQuantityintegerDefaults to 0.
Product imageUrlURL stringProduct image URL.
Product imageUrlsURL string[]Ordered product gallery, maximum 20 valid URLs. First URL becomes primary.
Product productUrlURL stringProduct page URL.
Product metadataobjectInternal metadata.
Product otherDetailsobjectFlexible attributes.
Product variantsarrayVariant objects.

Batch requests use products and support up to 250 product objects.

Product Delete Events​

Events:

  • product.deleted
  • catalog.batch.deleted

Required:

LocationFieldTypeNotes
HeaderAPI keystringRequired for authentication.
BodyeventstringDelete event.
Bodyproduct or productsobject or arraySingle product identity or product identity array.
ProductstoreIdUUID stringTarget store.
Productsku or externalIdstringAt least one identity is needed to find the product.

Optional:

FieldTypeNotes
sourcestringSource system label.
Product skustringOptional only if externalId is present.
Product externalIdstringOptional only if sku is present.

Outbound Webhook Receiver​

Outbound webhooks are sent by Thyris to a merchant receiver URL configured in the dashboard.

Receiver URL requirements:

FieldRequiredNotes
Destination URLYesPublic HTTPS URL. Private/internal URLs are blocked.
EventsYesAt least one outbound event must be selected.
SecretNoSent as x-webhook-secret when configured.

Headers sent by Thyris:

HeaderRequiredNotes
Content-Type: application/jsonYesAlways sent.
x-webhook-secretNoSent only if configured.

Receiver response:

RequirementNotes
2xx statusTreated as successful delivery.
Response within 10 secondsLonger requests time out and are logged as failed.

Outbound payloads always include:

FieldTypeNotes
eventstringEvent name.
directionstringoutbound.
sourcestringSource that triggered the event.
versionstringWebhook schema/source version combined with timestamp, for example catalog.v1@2026-09-12T18:00:00Z.
timestampstringRFC 3339 event timestamp.

Payload-specific fields:

Event FamilyRequired Payload Field
Product eventsproduct
Cart/checkout eventscart when emitted by cart flow
Order eventsorder

REST Procurement API​

Base URL:

https://merchant.thyris.cloud/api/v1/procurement

GET /stores​

Lists stores available to the API key.

Required:

LocationFieldNotes
HeaderAPI keyRequired for authentication.

GET /suppliers​

Required:

LocationFieldNotes
HeaderAPI keyRequired for authentication.

Optional:

LocationFieldNotes
QuerystoreIdLimits results to one store.
QuerylimitMaximum result count.

POST /suppliers​

Required:

LocationFieldTypeNotes
HeaderAPI keystringRequired for authentication.
BodystoreIdUUID stringTarget store.
BodynamestringSupplier name.

Optional fields: domain, logoUrl, websiteUrl, externalId, channel, status, reliabilityScore, leadTimeDays, activeItems, currency, supportedCurrencies, capabilities, endpoints, contact, metadata.

Supplier currency is the primary currency used for supplier order requests and inbound supplier quote processing. supportedCurrencies is an array of 3-letter currency codes; the primary currency is always included.

GET /inventory​

Required:

LocationFieldNotes
HeaderAPI keyRequired for authentication.

Optional:

LocationFieldNotes
QuerystoreIdLimits results to one store.
QueryqSearches name, SKU, external ID, and procurement item ID.
QuerylimitMaximum result count.

POST /inventory​

Required:

LocationFieldTypeNotes
HeaderAPI keystringRequired for authentication.
BodystoreIdUUID stringTarget store.
BodynamestringInventory item name.

Optional fields: preferredSupplierId, sku, externalId, description, imageUrl, imageUrls, itemUrl, category, targetProduct, status, quantityOnHand, reorderPoint, targetStockLevel, reorderThresholdPercent, maxOrdersPerWeek, autoReorderEnabled, customOrderPolicy, leadTimeDays, unitCost, currency, aiSignal, metadata, otherDetails. imageUrls is an ordered array of at most 20 valid URLs; its first item is synchronized to imageUrl. reorderQuantity is legacy/system-managed; order quantity is calculated from target stock and current stock.

PATCH /inventory/{itemId}​

Required:

LocationFieldNotes
HeaderAPI keyRequired for authentication.
PathitemIdInternal procurement inventory item UUID.

Optional body fields are the same as POST /inventory.

GET /orders​

Required:

LocationFieldNotes
HeaderAPI keyRequired for authentication.

Optional:

LocationFieldNotes
QuerystoreIdLimits results to one store.
QuerylimitMaximum result count.

POST /orders​

Required:

LocationFieldTypeNotes
HeaderAPI keystringRequired for authentication.
BodystoreIdUUID stringTarget store.
BodyitemsarrayOne or more order lines.
Body itemnamestringLine item name.
Body itemquantityintegerMust be 1 or greater.

Optional fields: supplierId, status, source, reason, approvalRequired, eta, currency, metadata, otherDetails.

Use status=requested to start the supplier quote request workflow. Manual quote states (quote_requested, quote_received, pending_approval) are rejected; supplier quote states are created only through the supported quote intake flow.

Optional item fields: inventoryItemId, procurementItemId, unitCost, currency, metadata.

PATCH /orders/{orderId}​

Required:

LocationFieldNotes
HeaderAPI keyRequired for authentication.
PathorderIdInternal procurement order UUID.

Optional body fields: status, reason, approvalRequired, eta, metadata, otherDetails.

POST /quotes​

Deprecated. This endpoint rejects manual quote creation. Create an order request and use the supported supplier quote intake flow.

Inbound Procurement Webhook​

Endpoint:

POST https://webhooks.thyris.cloud/webhooks/procurement

Required:

LocationFieldNotes
HeaderAPI keyRequired for authentication.
BodyeventEvent name.
BodyOne of supplier, inventoryItem, or orderAt least one supported payload object is required. quote payloads are rejected.

Procurement webhook payload object fields follow the REST Procurement API requirements above.

Outbound Procurement Webhooks​

Outbound procurement webhooks require the same destination fields as outbound catalog webhooks: name, HTTPS URL, selected events, and optional secret.

Payload-specific fields:

Event FamilyRequired Payload Field
Supplier eventssupplier
Inventory eventsinventoryItem
Quote eventsorder, email, or quote
Procurement order eventsorder

UCP Catalog API​

Base URL:

https://merchant.thyris.cloud/api/protocols/ucp/catalog

UCP endpoints use the same required and optional fields as the REST Catalog API:

UCP EndpointSame Requirements As
GET /productsREST GET /products
POST /productsREST POST /products
GET /products/{productId}REST GET /products/{productId}
PATCH /products/{productId}REST PATCH /products/{productId}
DELETE /products/{productId}REST DELETE /products/{productId}
GET /cartsREST GET /carts
POST /cartsREST POST /carts
POST /carts/clear?cartId={cartId}REST POST /carts/clear?cartId={cartId}
GET /ordersREST GET /orders
POST /ordersREST POST /orders
GET /orders/{orderId}REST GET /orders/{orderId}
PATCH /orders/{orderId}REST PATCH /orders/{orderId}

UCP Procurement API​

Base URL:

https://merchant.thyris.cloud/api/protocols/ucp/procurement

UCP procurement endpoints use the same required and optional fields as the REST Procurement API:

UCP EndpointSame Requirements As
GET /storesREST Procurement GET /stores
GET /suppliersREST Procurement GET /suppliers
POST /suppliersREST Procurement POST /suppliers
GET /inventoryREST Procurement GET /inventory
POST /inventoryREST Procurement POST /inventory
GET /ordersREST Procurement GET /orders
POST /ordersREST Procurement POST /orders
PATCH /orders/{orderId}REST Procurement PATCH /orders/{orderId}
POST /quotesDeprecated; quote creation is reserved for supplier email replies.

Merchant MCP​

Endpoint:

https://merchant.thyris.cloud/mcp

All MCP JSON-RPC POST /mcp requests require:

LocationFieldNotes
HeaderAPI keyRequired for catalog and procurement tools.
BodyjsonrpcUse 2.0.
BodyidRequest ID.
BodymethodJSON-RPC method, for example tools/call.

initialize​

Required:

FieldNotes
jsonrpc2.0.
idRequest ID.
methodinitialize.
params.protocolVersionMCP protocol version.
params.clientInfo.nameClient name.
params.clientInfo.versionClient version.

Optional: none for the provided Postman request.

tools/list​

Required:

FieldNotes
jsonrpc2.0.
idRequest ID.
methodtools/list.

Optional: none.

tools/call​

Required wrapper fields:

FieldNotes
jsonrpc2.0.
idRequest ID.
methodtools/call.
params.nameTool name.
params.argumentsTool arguments object.

Tool argument requirements:

ToolRequired ArgumentsOptional Arguments
catalog_list_storesnonenone
catalog_search_productsnonequery, storeId, limit, includeDraft
catalog_searchnonequery, storeId, limit
catalog_get_product_detailsOne of catalogId, productId, sku, or externalIdstoreId; recommended with sku or externalId
catalog_get_productOne of productId, sku, or externalIdstoreId when using sku or externalId
catalog_upsert_productstoreId, name, pricesku, externalId, description, currency, status, inStock, inventoryQuantity, imageUrl, imageUrls, productUrl, metadata, otherDetails, variants
catalog_delete_productproductIdnone
catalog_create_cartstoreId, items, item catalogId, item quantitymetadata, otherDetails, item metadata, item otherDetails
catalog_mutate_cart_itemsoperation, cartId, idempotencyKeycatalogId, itemId, quantity, items bundle array
catalog_clear_cartcartIdnone
catalog_archive_cartcartIdnone
catalog_complete_ordercheckoutId, customer, shippingAddresspayment, payment.id, payment.provider, payment.status, billingAddress, metadata, otherDetails
procurement_list_storesnonenone
procurement_list_inventorynonestoreId, query, limit
procurement_create_inventory_itemstoreId, namepreferredSupplierId, sku, externalId, description, imageUrl, imageUrls, itemUrl, category, targetProduct, status, quantityOnHand, reorderPoint, targetStockLevel, reorderThresholdPercent, maxOrdersPerWeek, autoReorderEnabled, customOrderPolicy, leadTimeDays, unitCost, currency, metadata, otherDetails
procurement_list_suppliersnonestoreId, limit
procurement_create_supplierstoreId, namedomain, logoUrl, websiteUrl, externalId, channel, status, reliabilityScore, leadTimeDays, activeItems, currency, supportedCurrencies, capabilities, endpoints, contact, metadata
procurement_list_ordersnonestoreId, limit
procurement_create_orderstoreId, itemssupplierId, status, source, reason, approvalRequired, eta, currency, metadata, otherDetails
procurement_create_quote_orderDeprecatedQuotes are created only from supplier email replies.
procurement_update_order_statusorderId, statusQuote statuses are not manually writable.

MCP cart creation uses the 10 digit catalogId, not the Thyris product UUID.

For both catalog products and procurement inventory items, imageUrls is optional, ordered, limited to 20 valid URL strings, and uses its first entry as the primary imageUrl.