[{"data":1,"prerenderedAt":446},["ShallowReactive",2],{"navigation_docs_en":3,"-en-oauth-authorization-code-pkce":342,"-en-oauth-authorization-code-pkce-surround":441},[4,23,41,51,65,83,314,328],{"title":5,"icon":6,"path":7,"stem":8,"children":9,"page":22},"Getting started","i-lucide-rocket","\u002Fen\u002Fgetting-started","en\u002F1.getting-started",[10,14,18],{"title":11,"path":12,"stem":13},"Quick start","\u002Fen\u002Fgetting-started\u002Fquick-start","en\u002F1.getting-started\u002F1.quick-start",{"title":15,"path":16,"stem":17},"Trust model","\u002Fen\u002Fgetting-started\u002Ftrust-model","en\u002F1.getting-started\u002F2.trust-model",{"title":19,"path":20,"stem":21},"Enterprise integration journey","\u002Fen\u002Fgetting-started\u002Fenterprise-integration","en\u002F1.getting-started\u002F3.enterprise-integration",false,{"title":24,"icon":25,"path":26,"stem":27,"children":28,"page":22},"Storefront","i-lucide-store","\u002Fen\u002Fstorefront","en\u002F2.storefront",[29,33,37],{"title":30,"path":31,"stem":32},"Third-party Storefront","\u002Fen\u002Fstorefront\u002Fthird-party-storefront","en\u002F2.storefront\u002F1.third-party-storefront",{"title":34,"path":35,"stem":36},"Turnstile trust boundary","\u002Fen\u002Fstorefront\u002Fchallenge-and-turnstile","en\u002F2.storefront\u002F2.challenge-and-turnstile",{"title":38,"path":39,"stem":40},"Third-party Storefront public API","\u002Fen\u002Fstorefront\u002Fpublic-api","en\u002F2.storefront\u002F3.public-api",{"title":42,"icon":43,"path":44,"stem":45,"children":46,"page":22},"OAuth and identity","i-lucide-key-round","\u002Fen\u002Foauth","en\u002F3.oauth",[47],{"title":48,"path":49,"stem":50},"Third-party account authorization boundary","\u002Fen\u002Foauth\u002Fauthorization-code-pkce","en\u002F3.oauth\u002F1.authorization-code-pkce",{"title":52,"icon":53,"path":54,"stem":55,"children":56,"page":22},"Developer platform","i-lucide-blocks","\u002Fen\u002Fplatform","en\u002F4.platform",[57,61],{"title":58,"path":59,"stem":60},"Apps, versions, installations, and scopes","\u002Fen\u002Fplatform\u002Fapps-installations-scopes","en\u002F4.platform\u002F1.apps-installations-scopes",{"title":62,"path":63,"stem":64},"Origins, redirects, proxies, and environments","\u002Fen\u002Fplatform\u002Fsecurity-and-environments","en\u002F4.platform\u002F2.security-and-environments",{"title":66,"icon":67,"path":68,"stem":69,"children":70,"page":22},"Runtime extensions","i-lucide-workflow","\u002Fen\u002Fruntime","en\u002F5.runtime",[71,75,79],{"title":72,"path":73,"stem":74},"Installation Webhooks","\u002Fen\u002Fruntime\u002Fwebhooks","en\u002F5.runtime\u002F1.webhooks",{"title":76,"path":77,"stem":78},"Inventory synchronization","\u002Fen\u002Fruntime\u002Finventory-sync","en\u002F5.runtime\u002F2.inventory-sync",{"title":80,"path":81,"stem":82},"Automatic fulfillment providers","\u002Fen\u002Fruntime\u002Fauto-fulfillment","en\u002F5.runtime\u002F3.auto-fulfillment",{"title":84,"icon":85,"path":86,"stem":87,"children":88,"page":22},"API reference","i-lucide-braces","\u002Fen\u002Freference","en\u002F6.reference",[89,93,97],{"title":90,"path":91,"stem":92},"API Reference","\u002Fen\u002Freference\u002Fapi","en\u002F6.reference\u002F1.api",{"title":94,"path":95,"stem":96},"Errors, idempotency, and rate limits","\u002Fen\u002Freference\u002Ferrors-and-limits","en\u002F6.reference\u002F2.errors-and-limits",{"title":98,"path":99,"stem":100,"children":101,"page":22},"Endpoint catalog","\u002Fen\u002Freference\u002Foperations","en\u002F6.reference\u002F3.operations",[102,106,110,114,118,122,126,130,134,138,142,146,150,154,158,162,166,170,174,178,182,186,190,194,198,202,206,210,214,218,222,226,230,234,238,242,246,250,254,258,262,266,270,274,278,282,286,290,294,298,302,306,310],{"title":103,"path":104,"stem":105},"Get the public site bootstrap configuration","\u002Fen\u002Freference\u002Foperations\u002Fget-public-bootstrap","en\u002F6.reference\u002F3.operations\u002F01.get-public-bootstrap",{"title":107,"path":108,"stem":109},"List public categories","\u002Fen\u002Freference\u002Foperations\u002Flist-public-categories","en\u002F6.reference\u002F3.operations\u002F02.list-public-categories",{"title":111,"path":112,"stem":113},"Get a public product for a store","\u002Fen\u002Freference\u002Foperations\u002Fget-public-merchant-product","en\u002F6.reference\u002F3.operations\u002F03.get-public-merchant-product",{"title":115,"path":116,"stem":117},"List public categories for a store","\u002Fen\u002Freference\u002Foperations\u002Flist-public-merchant-categories","en\u002F6.reference\u002F3.operations\u002F04.list-public-merchant-categories",{"title":119,"path":120,"stem":121},"List public products for a store","\u002Fen\u002Freference\u002Foperations\u002Flist-public-merchant-products","en\u002F6.reference\u002F3.operations\u002F05.list-public-merchant-products",{"title":123,"path":124,"stem":125},"Get a public store profile","\u002Fen\u002Freference\u002Foperations\u002Fget-public-merchant","en\u002F6.reference\u002F3.operations\u002F06.get-public-merchant",{"title":127,"path":128,"stem":129},"Get a public product by slug","\u002Fen\u002Freference\u002Foperations\u002Fget-public-product","en\u002F6.reference\u002F3.operations\u002F07.get-public-product",{"title":131,"path":132,"stem":133},"List the public product catalog","\u002Fen\u002Freference\u002Foperations\u002Flist-public-products","en\u002F6.reference\u002F3.operations\u002F08.list-public-products",{"title":135,"path":136,"stem":137},"List current published legal documents by locale","\u002Fen\u002Freference\u002Foperations\u002Flist-public-legal-documents","en\u002F6.reference\u002F3.operations\u002F09.list-public-legal-documents",{"title":139,"path":140,"stem":141},"describeOAuthAuthorization","\u002Fen\u002Freference\u002Foperations\u002Fdescribe-oauth-authorization","en\u002F6.reference\u002F3.operations\u002F10.describe-oauth-authorization",{"title":143,"path":144,"stem":145},"revokeOAuthToken","\u002Fen\u002Freference\u002Foperations\u002Frevoke-oauth-token","en\u002F6.reference\u002F3.operations\u002F11.revoke-oauth-token",{"title":147,"path":148,"stem":149},"exchangeOAuthToken","\u002Fen\u002Freference\u002Foperations\u002Fexchange-oauth-token","en\u002F6.reference\u002F3.operations\u002F12.exchange-oauth-token",{"title":151,"path":152,"stem":153},"List public categories with an API Key","\u002Fen\u002Freference\u002Foperations\u002Flist-api-key-catalog-categories","en\u002F6.reference\u002F3.operations\u002F13.list-api-key-catalog-categories",{"title":155,"path":156,"stem":157},"Get a public product with an API Key","\u002Fen\u002Freference\u002Foperations\u002Fget-api-key-catalog-product","en\u002F6.reference\u002F3.operations\u002F14.get-api-key-catalog-product",{"title":159,"path":160,"stem":161},"List public products with an API Key","\u002Fen\u002Freference\u002Foperations\u002Flist-api-key-catalog-products","en\u002F6.reference\u002F3.operations\u002F15.list-api-key-catalog-products",{"title":163,"path":164,"stem":165},"Cancel a hosted checkout session","\u002Fen\u002Freference\u002Foperations\u002Fcancel-hosted-checkout-session","en\u002F6.reference\u002F3.operations\u002F16.cancel-hosted-checkout-session",{"title":167,"path":168,"stem":169},"Get a hosted checkout session","\u002Fen\u002Freference\u002Foperations\u002Fget-hosted-checkout-session","en\u002F6.reference\u002F3.operations\u002F17.get-hosted-checkout-session",{"title":171,"path":172,"stem":173},"Create a hosted checkout session","\u002Fen\u002Freference\u002Foperations\u002Fcreate-hosted-checkout-session","en\u002F6.reference\u002F3.operations\u002F18.create-hosted-checkout-session",{"title":175,"path":176,"stem":177},"Initiate a hosted login session","\u002Fen\u002Freference\u002Foperations\u002Finitiate-hosted-login","en\u002F6.reference\u002F3.operations\u002F19.initiate-hosted-login",{"title":179,"path":180,"stem":181},"Consume a hosted login return","\u002Fen\u002Freference\u002Foperations\u002Fconsume-hosted-login-return","en\u002F6.reference\u002F3.operations\u002F20.consume-hosted-login-return",{"title":183,"path":184,"stem":185},"Get the current API Key identity and scopes","\u002Fen\u002Freference\u002Foperations\u002Fget-api-key-identity","en\u002F6.reference\u002F3.operations\u002F21.get-api-key-identity",{"title":187,"path":188,"stem":189},"Get the installation credential identity","\u002Fen\u002Freference\u002Foperations\u002Fget-installation-credential-identity","en\u002F6.reference\u002F3.operations\u002F22.get-installation-credential-identity",{"title":191,"path":192,"stem":193},"Get the installation credential readiness","\u002Fen\u002Freference\u002Foperations\u002Fget-installation-credential-readiness","en\u002F6.reference\u002F3.operations\u002F23.get-installation-credential-readiness",{"title":195,"path":196,"stem":197},"setPublicCartAddress","\u002Fen\u002Freference\u002Foperations\u002Fset-public-cart-address","en\u002F6.reference\u002F3.operations\u002F24.set-public-cart-address",{"title":199,"path":200,"stem":201},"quotePublicCartCheckout","\u002Fen\u002Freference\u002Foperations\u002Fquote-public-cart-checkout","en\u002F6.reference\u002F3.operations\u002F25.quote-public-cart-checkout",{"title":203,"path":204,"stem":205},"checkoutPublicCart","\u002Fen\u002Freference\u002Foperations\u002Fcheckout-public-cart","en\u002F6.reference\u002F3.operations\u002F26.checkout-public-cart",{"title":207,"path":208,"stem":209},"clearPublicCart","\u002Fen\u002Freference\u002Foperations\u002Fclear-public-cart","en\u002F6.reference\u002F3.operations\u002F27.clear-public-cart",{"title":211,"path":212,"stem":213},"removePublicCartItem","\u002Fen\u002Freference\u002Foperations\u002Fremove-public-cart-item","en\u002F6.reference\u002F3.operations\u002F28.remove-public-cart-item",{"title":215,"path":216,"stem":217},"updatePublicCartItemQuantity","\u002Fen\u002Freference\u002Foperations\u002Fupdate-public-cart-item-quantity","en\u002F6.reference\u002F3.operations\u002F29.update-public-cart-item-quantity",{"title":219,"path":220,"stem":221},"addPublicCartItem","\u002Fen\u002Freference\u002Foperations\u002Fadd-public-cart-item","en\u002F6.reference\u002F3.operations\u002F30.add-public-cart-item",{"title":223,"path":224,"stem":225},"removePublicCartPromotion","\u002Fen\u002Freference\u002Foperations\u002Fremove-public-cart-promotion","en\u002F6.reference\u002F3.operations\u002F31.remove-public-cart-promotion",{"title":227,"path":228,"stem":229},"applyPublicCartPromotion","\u002Fen\u002Freference\u002Foperations\u002Fapply-public-cart-promotion","en\u002F6.reference\u002F3.operations\u002F32.apply-public-cart-promotion",{"title":231,"path":232,"stem":233},"quotePublicCart","\u002Fen\u002Freference\u002Foperations\u002Fquote-public-cart","en\u002F6.reference\u002F3.operations\u002F33.quote-public-cart",{"title":235,"path":236,"stem":237},"revokePublicCart","\u002Fen\u002Freference\u002Foperations\u002Frevoke-public-cart","en\u002F6.reference\u002F3.operations\u002F34.revoke-public-cart",{"title":239,"path":240,"stem":241},"getPublicCart","\u002Fen\u002Freference\u002Foperations\u002Fget-public-cart","en\u002F6.reference\u002F3.operations\u002F35.get-public-cart",{"title":243,"path":244,"stem":245},"createPublicCart","\u002Fen\u002Freference\u002Foperations\u002Fcreate-public-cart","en\u002F6.reference\u002F3.operations\u002F36.create-public-cart",{"title":247,"path":248,"stem":249},"getStorefrontOrderAfterSalesEligibility","\u002Fen\u002Freference\u002Foperations\u002Fget-storefront-order-after-sales-eligibility","en\u002F6.reference\u002F3.operations\u002F37.get-storefront-order-after-sales-eligibility",{"title":251,"path":252,"stem":253},"requestStorefrontOrderAfterSales","\u002Fen\u002Freference\u002Foperations\u002Frequest-storefront-order-after-sales","en\u002F6.reference\u002F3.operations\u002F38.request-storefront-order-after-sales",{"title":255,"path":256,"stem":257},"getStorefrontOrderCancellationEligibility","\u002Fen\u002Freference\u002Foperations\u002Fget-storefront-order-cancellation-eligibility","en\u002F6.reference\u002F3.operations\u002F39.get-storefront-order-cancellation-eligibility",{"title":259,"path":260,"stem":261},"cancelStorefrontOrder","\u002Fen\u002Freference\u002Foperations\u002Fcancel-storefront-order","en\u002F6.reference\u002F3.operations\u002F40.cancel-storefront-order",{"title":263,"path":264,"stem":265},"getStorefrontOrder","\u002Fen\u002Freference\u002Foperations\u002Fget-storefront-order","en\u002F6.reference\u002F3.operations\u002F41.get-storefront-order",{"title":267,"path":268,"stem":269},"replayInstallationWebhookDelivery","\u002Fen\u002Freference\u002Foperations\u002Freplay-installation-webhook-delivery","en\u002F6.reference\u002F3.operations\u002F42.replay-installation-webhook-delivery",{"title":271,"path":272,"stem":273},"listInstallationWebhookDeliveries","\u002Fen\u002Freference\u002Foperations\u002Flist-installation-webhook-deliveries","en\u002F6.reference\u002F3.operations\u002F43.list-installation-webhook-deliveries",{"title":275,"path":276,"stem":277},"getInstallationWebhookSignatureFixture","\u002Fen\u002Freference\u002Foperations\u002Fget-installation-webhook-signature-fixture","en\u002F6.reference\u002F3.operations\u002F44.get-installation-webhook-signature-fixture",{"title":279,"path":280,"stem":281},"updateInstallationWebhook","\u002Fen\u002Freference\u002Foperations\u002Fupdate-installation-webhook","en\u002F6.reference\u002F3.operations\u002F45.update-installation-webhook",{"title":283,"path":284,"stem":285},"listInstallationWebhooks","\u002Fen\u002Freference\u002Foperations\u002Flist-installation-webhooks","en\u002F6.reference\u002F3.operations\u002F46.list-installation-webhooks",{"title":287,"path":288,"stem":289},"createInstallationWebhook","\u002Fen\u002Freference\u002Foperations\u002Fcreate-installation-webhook","en\u002F6.reference\u002F3.operations\u002F47.create-installation-webhook",{"title":291,"path":292,"stem":293},"listInstallationWebhookEvents","\u002Fen\u002Freference\u002Foperations\u002Flist-installation-webhook-events","en\u002F6.reference\u002F3.operations\u002F48.list-installation-webhook-events",{"title":295,"path":296,"stem":297},"Get public contact channels","\u002Fen\u002Freference\u002Foperations\u002Fget-public-contact","en\u002F6.reference\u002F3.operations\u002F49.get-public-contact",{"title":299,"path":300,"stem":301},"Get the public store security configuration","\u002Fen\u002Freference\u002Foperations\u002Fget-public-store-security-config","en\u002F6.reference\u002F3.operations\u002F50.get-public-store-security-config",{"title":303,"path":304,"stem":305},"Get the public runtime configuration","\u002Fen\u002Freference\u002Foperations\u002Fget-public-runtime-config","en\u002F6.reference\u002F3.operations\u002F51.get-public-runtime-config",{"title":307,"path":308,"stem":309},"Search public products","\u002Fen\u002Freference\u002Foperations\u002Fsearch-public-products","en\u002F6.reference\u002F3.operations\u002F52.search-public-products",{"title":311,"path":312,"stem":313},"Get the published Storefront decoration","\u002Fen\u002Freference\u002Foperations\u002Fget-public-storefront-decoration","en\u002F6.reference\u002F3.operations\u002F53.get-public-storefront-decoration",{"title":315,"icon":316,"path":317,"stem":318,"children":319,"page":22},"Examples","i-lucide-code-xml","\u002Fen\u002Fexamples","en\u002F7.examples",[320,324],{"title":321,"path":322,"stem":323},"Minimal Nuxt Storefront","\u002Fen\u002Fexamples\u002Fnuxt-storefront","en\u002F7.examples\u002F1.nuxt-storefront",{"title":325,"path":326,"stem":327},"Webhook verification","\u002Fen\u002Fexamples\u002Fwebhook-verification","en\u002F7.examples\u002F2.webhook-verification",{"title":329,"icon":330,"path":331,"stem":332,"children":333,"page":22},"Versions and support","i-lucide-life-buoy","\u002Fen\u002Foperations","en\u002F8.operations",[334,338],{"title":335,"path":336,"stem":337},"Versions, migrations, and changelog","\u002Fen\u002Foperations\u002Fversions-and-migrations","en\u002F8.operations\u002F1.versions-and-migrations",{"title":339,"path":340,"stem":341},"Support and security disclosure","\u002Fen\u002Foperations\u002Fsupport-and-security","en\u002F8.operations\u002F2.support-and-security",{"id":343,"title":48,"body":344,"description":431,"extension":432,"links":433,"meta":434,"navigation":438,"path":49,"seo":439,"stem":50,"__hash__":440},"docs_en\u002Fen\u002F3.oauth\u002F1.authorization-code-pkce.md",{"type":345,"value":346,"toc":425},"minimark",[347,351,358,382,387,390,411,415,418],[348,349,48],"h1",{"id":350},"third-party-account-authorization-boundary",[352,353,354],"blockquote",{},[355,356,357],"p",{},"Status: the OAuth authorization description, token exchange, revocation contracts, and DPoP are in the verified public-only artifact. A real app, official authorization domain, and redirect URI still require platform enablement. This page provides no curl command, server URL, or speculative token example.",[355,359,360,361,365,366,369,370,373,374,377,378,381],{},"Users enter their email, password, and MFA only on the official Ayalink authorization domain. A third party must not proxy, embed, or imitate the Ayalink sign-in page, collect account factors, or receive or forward the Ayalink global-session Cookie. Third-party authorization is limited to Authorization Code with PKCE: every attempt uses high-entropy ",[362,363,364],"code",{},"state",", ",[362,367,368],{},"nonce",", and ",[362,371,372],{},"code_verifier",", only ",[362,375,376],{},"S256",", and an exactly registered HTTPS ",[362,379,380],{},"redirect_uri",".",[383,384,386],"h2",{"id":385},"a-session-is-not-a-grant","A session is not a grant",[355,388,389],{},"The Ayalink global session serves Ayalink-owned domains only. A third-party app grant is separate, minimal, and revocable. It is constrained to a specific app, installation, store\u002Fresource, audience, and user-approved scopes. It cannot become a platform session or prove ownership of another store or resource.",[355,391,392,393,365,396,399,400,365,403,406,407,410],{},"Do not put access tokens, refresh tokens, authorization codes, or verifiers in URLs, ",[362,394,395],{},"localStorage",[362,397,398],{},"sessionStorage",", IndexedDB, analytics, logs, error reports, support tickets, or recordings. For a durable session, use a same-origin BFF. The BFF stores only its own app grant and gives its frontend an ",[362,401,402],{},"HttpOnly",[362,404,405],{},"Secure",", appropriately ",[362,408,409],{},"SameSite"," application-session Cookie. It never forwards an Ayalink Cookie and never asks for an Ayalink password or MFA.",[383,412,414],{"id":413},"phishing-warning-and-recovery","Phishing warning and recovery",[355,416,417],{},"A malicious proxy can copy the page appearance, use a look-alike domain, terminate TLS, inject scripts, and record every input. Before authorizing, check the official authorization domain in the browser address bar. Never enter Ayalink credentials through chat, email, or a third-party page. If compromise is suspected, close the page, revoke the affected app\u002Finstallation grant from an official entry point, sign out of Ayalink sessions, update the password and reconfigure MFA, then report through the official security channel. Never send a token, Cookie, or verification code to a third party.",[355,419,420,421,424],{},"DPoP is declared by the public contract. Refresh-token rotation, token-family replay detection, and a user grant-management entry point are still not declared by the artifact, so do not design a production dependency around them. Use the ",[422,423,90],"a",{"href":91}," for executable methods, paths, and schemas.",{"title":426,"searchDepth":427,"depth":427,"links":428},"",2,[429,430],{"id":385,"depth":427,"text":386},{"id":413,"depth":427,"text":414},"Use the official authorization domain, PKCE S256, and isolated app grants without exposing account credentials to a proxy.","md",null,{"sourceGuide":435,"sourceHash":436,"sourceLocale":437},"oauth-developer-guide","b0c5e9b7dbff3d903c5b6ebccc42873e965852e9eafb8804570c40440a829ee9","en",true,{"title":48,"description":431},"Y5WjUWJ3vjkHCnvLq1eRkQrPJwOlSjntQh70HIhUqy0",[442,444],{"title":38,"path":39,"stem":40,"description":443,"children":-1},"The Storefront public API entry generated from the authoritative public-only artifact.",{"title":58,"path":59,"stem":60,"description":445,"children":-1},"Model immutable app versions and store-bound installations with least-privilege scopes.",1786201412569]