Skip to content

Reference

API overview

A small, predictable REST API: JSON in, JSON out, one error format everywhere.

Base URL

https://api.askmerra.com/v1

Two public APIs

APIWho calls itAuthentication
Catalog Push APIYour servers, ERPs, platform connectorsSecret key: Authorization: Bearer sk_live_…
Widget APIBrowsers on your allowed domains (the widget, or your own chat UI)Site key in the query string + proof-of-work session token

Secret keys

Create secret keys in Dashboard → API keys (owners and admins). The full key is shown once; we only store a hash. Up to 10 keys can be active per shop, so you can rotate without downtime: create a new key, deploy it, revoke the old one.

curl https://api.askmerra.com/v1/catalog/ping -H "Authorization: Bearer $ASKMERRA_SECRET_KEY"

Keep secret keys on the server

Never embed a secret key in a web page, mobile app or public repository. If one leaks, revoke it immediately in the dashboard.

Errors

Every error has the same shape:

{
  "error": {
    "code": "rate_limited",
    "message": "Rate limit: 120 requests per minute per key",
    "details": { "retryAfterSec": 12 },
    "requestId": "req_7f3c…"
  }
}
StatusCodeMeaning
400validation_errorThe body or query does not match the schema. details lists each issue (path + message).
401unauthorizedMissing Authorization header.
401invalid_api_keyUnknown or revoked secret key.
401invalid_site_keyUnknown or revoked site key (widget API).
401session_expired / session_mismatchWidget session token expired or issued for another shop, visitor or site.
403origin_not_allowedWidget API called from a domain that is not in the shop’s allowed domains.
403client_not_allowedWidget API called by something that is not a browser.
404not_foundUnknown route or resource.
413fst_err_ctp_body_too_largeRequest body too large (Push API: 10 MB).
429rate_limitedToo many requests. Wait for the number of seconds in the Retry-After header.
500internal_errorSomething went wrong on our side. Retry with backoff; contact us with the requestId if it persists.

Every response carries an x-request-id header. Include it when contacting support.

Rate limits

  • Push API: 120 requests per minute per secret key (up to 500 products per request → 60,000 products per minute).
  • Widget API: per visitor, per IP address and per shop (see the security model).

When limited you receive 429 with a Retry-After header. Retry with exponential backoff and jitter.

Versioning

The version is part of the path (/v1). Within a version we only make additive changes (new endpoints, new optional fields, new response fields, new error codes), so ignore unknown fields. Breaking changes ship as a new version with at least 12 months of overlap.