Skip to main content

Initialize SPS Commerce OAuth Flow

POST 

/api/spscommerce/integrations/initialize

Initialize the SPS Commerce OAuth 2.0 authorization flow.

Not yet available to API tokens

This endpoint currently requires session authentication; Personal Access Token scope support is in progress.

Client credentials (client_id, client_secret) are read from server config (SPS_COMMERCE_CLIENT_ID, SPS_COMMERCE_CLIENT_SECRET env vars).

Request Body:

  • name - Integration name (optional, defaults to "SPS Commerce")
  • integration_settings - EDI configuration (optional):
    • sender_id - Your EDI sender ID
    • receiver_id - Your EDI receiver ID (trading partner)
    • protocol - Communication protocol ("api")
    • sandbox - Use sandbox environment (true/false)

Process:

  1. Generates a unique state parameter for CSRF protection
  2. Creates SPS Commerce OAuth authorization URL
  3. Stores credentials and settings temporarily in cache for OAuth completion
  4. Sets collection variable 'sps-state' for use in complete endpoint

Response:

  • state - UUID to use in complete endpoint (matches OAuth callback state parameter)
  • authorization_url - Visit this URL in browser to authorize SPS Commerce access

Next Steps:

  1. Visit the authorization_url in browser
  2. Complete SPS Commerce authorization
  3. Use the Complete endpoint with the stored state and your auto-polling preference

Security:

  • State parameter prevents CSRF attacks
  • OAuth data temporarily cached for 1 hour
  • OAuth follows SPS Commerce security best practices

Request​

Responses​

OK

Response Headers
    Content-Type