Initialize SPS Commerce OAuth Flow
POST/api/spscommerce/integrations/initialize
Initialize the SPS Commerce OAuth 2.0 authorization flow.
This endpoint currently requires session authentication; Personal Access Token scope support is in progress.
Client credentials (client_id, client_secret) are read from server config (SPS_COMMERCE_CLIENT_ID, SPS_COMMERCE_CLIENT_SECRET env vars).
Request Body:
name- Integration name (optional, defaults to "SPS Commerce")integration_settings- EDI configuration (optional):sender_id- Your EDI sender IDreceiver_id- Your EDI receiver ID (trading partner)protocol- Communication protocol ("api")sandbox- Use sandbox environment (true/false)
Process:
- Generates a unique state parameter for CSRF protection
- Creates SPS Commerce OAuth authorization URL
- Stores credentials and settings temporarily in cache for OAuth completion
- Sets collection variable 'sps-state' for use in complete endpoint
Response:
state- UUID to use in complete endpoint (matches OAuth callback state parameter)authorization_url- Visit this URL in browser to authorize SPS Commerce access
Next Steps:
- Visit the authorization_url in browser
- Complete SPS Commerce authorization
- Use the Complete endpoint with the stored state and your auto-polling preference
Security:
- State parameter prevents CSRF attacks
- OAuth data temporarily cached for 1 hour
- OAuth follows SPS Commerce security best practices
Request
Responses
- 200
- 401
- 403
- 422
- 429
OK
Response Headers
Unauthenticated — the bearer token is missing, revoked, expired, or malformed. Never retry automatically; fix the credential. See the Errors guide.
Forbidden — the token lacks a required scope, the endpoint is not available to API tokens, or the user behind the token lacks the permission. A human must adjust the token scopes or user permissions; do not retry.
Validation failed — the body is a field → messages map (Laravel shape) or the platform envelope with a stable machine-readable code. Fix the payload and resubmit.
Rate limited — platform limit is 1,000 requests/min; individual tokens may carry lower limits. Honor the Retry-After header before retrying. See the Rate Limits guide.