API reference / Stores
8 operations.
/api/v1/store-invitesStore teams that invited the caller’s confirmed email, newest first.
collector.listMyStoreInvites()stores:read(API keys are coming soon)If-None-MatchX-Request-Idobject
unauthorized: Not signed in (no session or token, or an expired one).
internal: Something went wrong on our side (quote the requestId).
curl 'https://collection.id/api/v1/store-invites' \
-H "Authorization: Bearer $COLLECTOR_TOKEN"await collector.listMyStoreInvites();/api/v1/store-invites/{inviteId}/respondAccepting joins the store’s team and answers its slug; declining answers slug: null.
collector.respondToStoreInvite()stores:write(API keys are coming soon)X-Request-Id| Name | In | Type | About |
|---|---|---|---|
inviteIdrequired | path | string (uuid) |
object
acceptbooleanrequiredobject
slugstring or nullrequiredinvalid_request: The query or body doesn’t match the schema (see errors[]).
invalid_json: The body isn’t JSON.
unauthorized: Not signed in (no session or token, or an expired one).
not_found: Nothing at that address.
invite_closed: It was already answered or withdrawn.
invite_expired: It expired.
already_member: The caller is already on the team.
internal: Something went wrong on our side (quote the requestId).
curl -X POST 'https://collection.id/api/v1/store-invites/<inviteId>/respond' \
-H "Authorization: Bearer $COLLECTOR_TOKEN" \
-H 'Content-Type: application/json' \
-d @body.jsonawait collector.respondToStoreInvite({ path: { inviteId }, body: { … } });/api/v1/stores/{storeId}/membersPeople join by accepting an invitation, never directly.
collector.listStoreMembers()store:staff:read(API keys are coming soon)If-None-MatchX-Request-Id| Name | In | Type | About |
|---|---|---|---|
storeIdrequired | path | string (uuid) |
object
unauthorized: Not signed in (no session or token, or an expired one).
not_found: Nothing at that address.
internal: Something went wrong on our side (quote the requestId).
curl 'https://collection.id/api/v1/stores/<storeId>/members' \
-H "Authorization: Bearer $COLLECTOR_TOKEN"await collector.listStoreMembers({ path: { storeId } });/api/v1/stores/{storeId}/members/{userId}Owners remove people; anyone may remove themselves (leave). A store keeps at least one owner.
collector.removeStoreMember()store:staff:write(API keys are coming soon)X-Request-Id| Name | In | Type | About |
|---|---|---|---|
storeIdrequired | path | string (uuid) | |
userIdrequired | path | string (uuid) |
{ left: true } when the caller left, else the team after the change.object or object
Option 1: object
left"true"requiredOption 2: object
unauthorized: Not signed in (no session or token, or an expired one).
forbidden: Only the owner can remove other people.
not_found: Nothing at that address.
last_owner: A store needs an owner: add another before leaving.
owner_role: Owners can only leave on their own.
internal: Something went wrong on our side (quote the requestId).
curl -X DELETE 'https://collection.id/api/v1/stores/<storeId>/members/<userId>' \
-H "Authorization: Bearer $COLLECTOR_TOKEN"await collector.removeStoreMember({ path: { storeId, userId } });/api/v1/stores/{storeId}/members/{userId}Owners only. Owners keep the owner role.
collector.updateStoreMember()store:staff:write(API keys are coming soon)X-Request-Id| Name | In | Type | About |
|---|---|---|---|
storeIdrequired | path | string (uuid) | |
userIdrequired | path | string (uuid) |
object
roleenumrequiredOne ofstaffadmin
object
invalid_request: The query or body doesn’t match the schema (see errors[]).
invalid_json: The body isn’t JSON.
unauthorized: Not signed in (no session or token, or an expired one).
forbidden: Only the store’s owners can do this.
not_found: Nothing at that address.
owner_role: Owners keep the owner role.
internal: Something went wrong on our side (quote the requestId).
curl -X PATCH 'https://collection.id/api/v1/stores/<storeId>/members/<userId>' \
-H "Authorization: Bearer $COLLECTOR_TOKEN" \
-H 'Content-Type: application/json' \
-d @body.jsonawait collector.updateStoreMember({ path: { storeId, userId }, body: { … } });/api/v1/stores/{storeId}/members/invitesOwners only: the invited email, role and expiry (never whether the email has an account).
collector.listStoreInvites()store:staff:read(API keys are coming soon)If-None-MatchX-Request-Id| Name | In | Type | About |
|---|---|---|---|
storeIdrequired | path | string (uuid) |
object
unauthorized: Not signed in (no session or token, or an expired one).
forbidden: Only the store’s owners can do this.
not_found: Nothing at that address.
internal: Something went wrong on our side (quote the requestId).
curl 'https://collection.id/api/v1/stores/<storeId>/members/invites' \
-H "Authorization: Bearer $COLLECTOR_TOKEN"await collector.listStoreInvites({ path: { storeId } });/api/v1/stores/{storeId}/members/invitesOwners only. Invites an email as staff or admin; the answer is the same whether or not the email has an account, and they join once they accept (invitations last 14 days).
collector.inviteStoreMember()store:staff:write(API keys are coming soon)Idempotency-KeyX-Request-Id| Name | In | Type | About |
|---|---|---|---|
storeIdrequired | path | string (uuid) |
object
emailstringrequiredroleenumoptionaldefault "staff"One ofstaffadmin
object
invalid_request: The query or body doesn’t match the schema (see errors[]).
invalid_json: The body isn’t JSON.
invalid_idempotency_key: The Idempotency-Key isn’t 1–255 visible ASCII characters.
unauthorized: Not signed in (no session or token, or an expired one).
forbidden: Only the store’s owners can do this.
not_found: Nothing at that address.
idempotency_in_progress: The first request with this key is still running.
already_member: That email is already on the team.
too_many_invites: Too many open invitations.
idempotency_key_reused: This key was used for a different request.
rate_limited: Too many requests; wait the Retry-After seconds.
internal: Something went wrong on our side (quote the requestId).
curl -X POST 'https://collection.id/api/v1/stores/<storeId>/members/invites' \
-H "Authorization: Bearer $COLLECTOR_TOKEN" \
-H "Idempotency-Key: $(uuidgen)" \
-H 'Content-Type: application/json' \
-d @body.jsonawait collector.inviteStoreMember({ path: { storeId }, body: { … } });/api/v1/stores/{storeId}/members/invites/{inviteId}Owners only.
collector.revokeStoreInvite()store:staff:write(API keys are coming soon)X-Request-Id| Name | In | Type | About |
|---|---|---|---|
storeIdrequired | path | string (uuid) | |
inviteIdrequired | path | string (uuid) |
object
unauthorized: Not signed in (no session or token, or an expired one).
forbidden: Only the store’s owners can do this.
not_found: Nothing at that address.
internal: Something went wrong on our side (quote the requestId).
curl -X DELETE 'https://collection.id/api/v1/stores/<storeId>/members/invites/<inviteId>' \
-H "Authorization: Bearer $COLLECTOR_TOKEN"await collector.revokeStoreInvite({ path: { storeId, inviteId } });