Availability
What partners can rely on today versus what is still being built. This page is the public capability matrix (no internal implementation details).
Legend
| Label | Meaning |
|---|---|
| Available | Usable on sandbox and/or production Partner API hosts |
| In development | Documented target; not live for partners yet |
| Contract | Shape described for planning; may change before release |
| Roadmap | Intentionally deferred |
Capability matrix
| Capability | Status | Notes |
|---|---|---|
REST /v1 (products, orders, customers, inventory, categories) | Available | List responses use { data, pagination }; see API Reference |
Partner API keys (isk_test_ / isk_live_) | Available | Create/revoke in Merchant BO → Developers |
| Webhooks (HMAC, retries) | Available | Create/list/get/delete via API; PATCH/rotate/test in development — Webhooks |
| Rate limits per plan | Available | Rate limits; raises via Merchant BO / support |
| Sandbox host | Available | https://sandbox-api.ioneshop.cloud (test keys only) |
Cursor pagination + updated_since | Available | Opaque cursors; raw offset rejected |
| OAuth 2.0 for partner apps | In development | Use API keys until changelog announces GA |
| GraphQL | In development | Same auth/scopes planned when shipped |
| Official npm SDK publish | In development | In-repo client may exist; public registry later |
| Official n8n node | In development | Use HTTP Request + patterns in n8n |
| Enterprise private API / EDI | Contract | Via Enterprise programme / Order Form |
Honesty rules
- Do not claim SOC 2 / ISO 27001 / PCI DSS certification without evidence.
- NIS2 / DORA: platform designed toward requirements — not a certificate for the merchant.
- Card data: PSP tokens only; no PAN/CVV in IoneShop APIs.
- Never recommend direct database access to partners.
When asking “is it live today?”, use this page and Status.