[{"data":1,"prerenderedAt":578},["ShallowReactive",2],{"navigation_docs_en":3,"-en-storefront-third-party-storefront":390,"-en-storefront-third-party-storefront-surround":573},[4,23,41,51,65,83,362,376],{"title":5,"icon":6,"path":7,"stem":8,"children":9,"page":22},"Getting started","i-lucide-rocket","\u002Fen\u002Fgetting-started","en\u002F1.getting-started",[10,14,18],{"title":11,"path":12,"stem":13},"Quick start","\u002Fen\u002Fgetting-started\u002Fquick-start","en\u002F1.getting-started\u002F1.quick-start",{"title":15,"path":16,"stem":17},"Trust model","\u002Fen\u002Fgetting-started\u002Ftrust-model","en\u002F1.getting-started\u002F2.trust-model",{"title":19,"path":20,"stem":21},"Enterprise integration journey","\u002Fen\u002Fgetting-started\u002Fenterprise-integration","en\u002F1.getting-started\u002F3.enterprise-integration",false,{"title":24,"icon":25,"path":26,"stem":27,"children":28,"page":22},"Storefront","i-lucide-store","\u002Fen\u002Fstorefront","en\u002F2.storefront",[29,33,37],{"title":30,"path":31,"stem":32},"Third-party Storefront","\u002Fen\u002Fstorefront\u002Fthird-party-storefront","en\u002F2.storefront\u002F1.third-party-storefront",{"title":34,"path":35,"stem":36},"Turnstile trust boundary","\u002Fen\u002Fstorefront\u002Fchallenge-and-turnstile","en\u002F2.storefront\u002F2.challenge-and-turnstile",{"title":38,"path":39,"stem":40},"Third-party Storefront public API","\u002Fen\u002Fstorefront\u002Fpublic-api","en\u002F2.storefront\u002F3.public-api",{"title":42,"icon":43,"path":44,"stem":45,"children":46,"page":22},"OAuth and identity","i-lucide-key-round","\u002Fen\u002Foauth","en\u002F3.oauth",[47],{"title":48,"path":49,"stem":50},"Third-party account authorization boundary","\u002Fen\u002Foauth\u002Fauthorization-code-pkce","en\u002F3.oauth\u002F1.authorization-code-pkce",{"title":52,"icon":53,"path":54,"stem":55,"children":56,"page":22},"Developer platform","i-lucide-blocks","\u002Fen\u002Fplatform","en\u002F4.platform",[57,61],{"title":58,"path":59,"stem":60},"Apps, versions, installations, and scopes","\u002Fen\u002Fplatform\u002Fapps-installations-scopes","en\u002F4.platform\u002F1.apps-installations-scopes",{"title":62,"path":63,"stem":64},"Origins, redirects, proxies, and environments","\u002Fen\u002Fplatform\u002Fsecurity-and-environments","en\u002F4.platform\u002F2.security-and-environments",{"title":66,"icon":67,"path":68,"stem":69,"children":70,"page":22},"Runtime extensions","i-lucide-workflow","\u002Fen\u002Fruntime","en\u002F5.runtime",[71,75,79],{"title":72,"path":73,"stem":74},"Installation Webhooks","\u002Fen\u002Fruntime\u002Fwebhooks","en\u002F5.runtime\u002F1.webhooks",{"title":76,"path":77,"stem":78},"Inventory synchronization","\u002Fen\u002Fruntime\u002Finventory-sync","en\u002F5.runtime\u002F2.inventory-sync",{"title":80,"path":81,"stem":82},"Automatic fulfillment providers","\u002Fen\u002Fruntime\u002Fauto-fulfillment","en\u002F5.runtime\u002F3.auto-fulfillment",{"title":84,"icon":85,"path":86,"stem":87,"children":88,"page":22},"API reference","i-lucide-braces","\u002Fen\u002Freference","en\u002F6.reference",[89,93,97],{"title":90,"path":91,"stem":92},"API Reference","\u002Fen\u002Freference\u002Fapi","en\u002F6.reference\u002F1.api",{"title":94,"path":95,"stem":96},"Errors, idempotency, and rate limits","\u002Fen\u002Freference\u002Ferrors-and-limits","en\u002F6.reference\u002F2.errors-and-limits",{"title":98,"path":99,"stem":100,"children":101,"page":22},"Endpoint catalog","\u002Fen\u002Freference\u002Foperations","en\u002F6.reference\u002F3.operations",[102,106,110,114,118,122,126,130,134,138,142,146,150,154,158,162,166,170,174,178,182,186,190,194,198,202,206,210,214,218,222,226,230,234,238,242,246,250,254,258,262,266,270,274,278,282,286,290,294,298,302,306,310,314,318,322,326,330,334,338,342,346,350,354,358],{"title":103,"path":104,"stem":105},"confirmOfficialPasswordReset","\u002Fen\u002Freference\u002Foperations\u002Fconfirm-official-password-reset","en\u002F6.reference\u002F3.operations\u002F01.confirm-official-password-reset",{"title":107,"path":108,"stem":109},"requestOfficialPasswordReset","\u002Fen\u002Freference\u002Foperations\u002Frequest-official-password-reset","en\u002F6.reference\u002F3.operations\u002F02.request-official-password-reset",{"title":111,"path":112,"stem":113},"registerOfficialStorefrontCustomer","\u002Fen\u002Freference\u002Foperations\u002Fregister-official-storefront-customer","en\u002F6.reference\u002F3.operations\u002F03.register-official-storefront-customer",{"title":115,"path":116,"stem":117},"Get the public site bootstrap configuration","\u002Fen\u002Freference\u002Foperations\u002Fget-public-bootstrap","en\u002F6.reference\u002F3.operations\u002F04.get-public-bootstrap",{"title":119,"path":120,"stem":121},"List public categories","\u002Fen\u002Freference\u002Foperations\u002Flist-public-categories","en\u002F6.reference\u002F3.operations\u002F05.list-public-categories",{"title":123,"path":124,"stem":125},"Get a public product for a store","\u002Fen\u002Freference\u002Foperations\u002Fget-public-merchant-product","en\u002F6.reference\u002F3.operations\u002F06.get-public-merchant-product",{"title":127,"path":128,"stem":129},"List public categories for a store","\u002Fen\u002Freference\u002Foperations\u002Flist-public-merchant-categories","en\u002F6.reference\u002F3.operations\u002F07.list-public-merchant-categories",{"title":131,"path":132,"stem":133},"List public products for a store","\u002Fen\u002Freference\u002Foperations\u002Flist-public-merchant-products","en\u002F6.reference\u002F3.operations\u002F08.list-public-merchant-products",{"title":135,"path":136,"stem":137},"Get a public store profile","\u002Fen\u002Freference\u002Foperations\u002Fget-public-merchant","en\u002F6.reference\u002F3.operations\u002F09.get-public-merchant",{"title":139,"path":140,"stem":141},"Get a public product by slug","\u002Fen\u002Freference\u002Foperations\u002Fget-public-product","en\u002F6.reference\u002F3.operations\u002F10.get-public-product",{"title":143,"path":144,"stem":145},"List the public product catalog","\u002Fen\u002Freference\u002Foperations\u002Flist-public-products","en\u002F6.reference\u002F3.operations\u002F11.list-public-products",{"title":147,"path":148,"stem":149},"Cancel the hosted checkout browser flow","\u002Fen\u002Freference\u002Foperations\u002Fcancel-hosted-checkout-browser","en\u002F6.reference\u002F3.operations\u002F12.cancel-hosted-checkout-browser",{"title":151,"path":152,"stem":153},"Continue the hosted checkout browser flow","\u002Fen\u002Freference\u002Foperations\u002Fcontinue-hosted-checkout-browser","en\u002F6.reference\u002F3.operations\u002F13.continue-hosted-checkout-browser",{"title":155,"path":156,"stem":157},"Get the hosted checkout browser projection","\u002Fen\u002Freference\u002Foperations\u002Fget-hosted-checkout-browser-projection","en\u002F6.reference\u002F3.operations\u002F14.get-hosted-checkout-browser-projection",{"title":159,"path":160,"stem":161},"Return from the hosted checkout browser flow","\u002Fen\u002Freference\u002Foperations\u002Freturn-hosted-checkout-browser","en\u002F6.reference\u002F3.operations\u002F15.return-hosted-checkout-browser",{"title":163,"path":164,"stem":165},"Consume a hosted checkout browser ticket","\u002Fen\u002Freference\u002Foperations\u002Fconsume-hosted-checkout-browser-ticket","en\u002F6.reference\u002F3.operations\u002F16.consume-hosted-checkout-browser-ticket",{"title":167,"path":168,"stem":169},"Consume a hosted login browser ticket","\u002Fen\u002Freference\u002Foperations\u002Fconsume-hosted-login-browser-ticket","en\u002F6.reference\u002F3.operations\u002F17.consume-hosted-login-browser-ticket",{"title":171,"path":172,"stem":173},"List current published legal documents by locale","\u002Fen\u002Freference\u002Foperations\u002Flist-public-legal-documents","en\u002F6.reference\u002F3.operations\u002F18.list-public-legal-documents",{"title":175,"path":176,"stem":177},"describeOAuthAuthorization","\u002Fen\u002Freference\u002Foperations\u002Fdescribe-oauth-authorization","en\u002F6.reference\u002F3.operations\u002F19.describe-oauth-authorization",{"title":179,"path":180,"stem":181},"revokeOAuthToken","\u002Fen\u002Freference\u002Foperations\u002Frevoke-oauth-token","en\u002F6.reference\u002F3.operations\u002F20.revoke-oauth-token",{"title":183,"path":184,"stem":185},"exchangeOAuthToken","\u002Fen\u002Freference\u002Foperations\u002Fexchange-oauth-token","en\u002F6.reference\u002F3.operations\u002F21.exchange-oauth-token",{"title":187,"path":188,"stem":189},"List public categories with an API Key","\u002Fen\u002Freference\u002Foperations\u002Flist-api-key-catalog-categories","en\u002F6.reference\u002F3.operations\u002F22.list-api-key-catalog-categories",{"title":191,"path":192,"stem":193},"Get a public product with an API Key","\u002Fen\u002Freference\u002Foperations\u002Fget-api-key-catalog-product","en\u002F6.reference\u002F3.operations\u002F23.get-api-key-catalog-product",{"title":195,"path":196,"stem":197},"List public products with an API Key","\u002Fen\u002Freference\u002Foperations\u002Flist-api-key-catalog-products","en\u002F6.reference\u002F3.operations\u002F24.list-api-key-catalog-products",{"title":199,"path":200,"stem":201},"Cancel a hosted checkout session","\u002Fen\u002Freference\u002Foperations\u002Fcancel-hosted-checkout-session","en\u002F6.reference\u002F3.operations\u002F25.cancel-hosted-checkout-session",{"title":203,"path":204,"stem":205},"Get a hosted checkout session","\u002Fen\u002Freference\u002Foperations\u002Fget-hosted-checkout-session","en\u002F6.reference\u002F3.operations\u002F26.get-hosted-checkout-session",{"title":207,"path":208,"stem":209},"Create a hosted checkout session","\u002Fen\u002Freference\u002Foperations\u002Fcreate-hosted-checkout-session","en\u002F6.reference\u002F3.operations\u002F27.create-hosted-checkout-session",{"title":211,"path":212,"stem":213},"Initiate a hosted login session","\u002Fen\u002Freference\u002Foperations\u002Finitiate-hosted-login","en\u002F6.reference\u002F3.operations\u002F28.initiate-hosted-login",{"title":215,"path":216,"stem":217},"Consume a hosted login return","\u002Fen\u002Freference\u002Foperations\u002Fconsume-hosted-login-return","en\u002F6.reference\u002F3.operations\u002F29.consume-hosted-login-return",{"title":219,"path":220,"stem":221},"Get the current API Key identity and scopes","\u002Fen\u002Freference\u002Foperations\u002Fget-api-key-identity","en\u002F6.reference\u002F3.operations\u002F30.get-api-key-identity",{"title":223,"path":224,"stem":225},"Get the installation credential identity","\u002Fen\u002Freference\u002Foperations\u002Fget-installation-credential-identity","en\u002F6.reference\u002F3.operations\u002F31.get-installation-credential-identity",{"title":227,"path":228,"stem":229},"Get the installation credential readiness","\u002Fen\u002Freference\u002Foperations\u002Fget-installation-credential-readiness","en\u002F6.reference\u002F3.operations\u002F32.get-installation-credential-readiness",{"title":231,"path":232,"stem":233},"setPublicCartAddress","\u002Fen\u002Freference\u002Foperations\u002Fset-public-cart-address","en\u002F6.reference\u002F3.operations\u002F33.set-public-cart-address",{"title":235,"path":236,"stem":237},"quotePublicCartCheckout","\u002Fen\u002Freference\u002Foperations\u002Fquote-public-cart-checkout","en\u002F6.reference\u002F3.operations\u002F34.quote-public-cart-checkout",{"title":239,"path":240,"stem":241},"checkoutPublicCart","\u002Fen\u002Freference\u002Foperations\u002Fcheckout-public-cart","en\u002F6.reference\u002F3.operations\u002F35.checkout-public-cart",{"title":243,"path":244,"stem":245},"clearPublicCart","\u002Fen\u002Freference\u002Foperations\u002Fclear-public-cart","en\u002F6.reference\u002F3.operations\u002F36.clear-public-cart",{"title":247,"path":248,"stem":249},"removePublicCartItem","\u002Fen\u002Freference\u002Foperations\u002Fremove-public-cart-item","en\u002F6.reference\u002F3.operations\u002F37.remove-public-cart-item",{"title":251,"path":252,"stem":253},"updatePublicCartItemQuantity","\u002Fen\u002Freference\u002Foperations\u002Fupdate-public-cart-item-quantity","en\u002F6.reference\u002F3.operations\u002F38.update-public-cart-item-quantity",{"title":255,"path":256,"stem":257},"addPublicCartItem","\u002Fen\u002Freference\u002Foperations\u002Fadd-public-cart-item","en\u002F6.reference\u002F3.operations\u002F39.add-public-cart-item",{"title":259,"path":260,"stem":261},"removePublicCartPromotion","\u002Fen\u002Freference\u002Foperations\u002Fremove-public-cart-promotion","en\u002F6.reference\u002F3.operations\u002F40.remove-public-cart-promotion",{"title":263,"path":264,"stem":265},"applyPublicCartPromotion","\u002Fen\u002Freference\u002Foperations\u002Fapply-public-cart-promotion","en\u002F6.reference\u002F3.operations\u002F41.apply-public-cart-promotion",{"title":267,"path":268,"stem":269},"quotePublicCart","\u002Fen\u002Freference\u002Foperations\u002Fquote-public-cart","en\u002F6.reference\u002F3.operations\u002F42.quote-public-cart",{"title":271,"path":272,"stem":273},"revokePublicCart","\u002Fen\u002Freference\u002Foperations\u002Frevoke-public-cart","en\u002F6.reference\u002F3.operations\u002F43.revoke-public-cart",{"title":275,"path":276,"stem":277},"getPublicCart","\u002Fen\u002Freference\u002Foperations\u002Fget-public-cart","en\u002F6.reference\u002F3.operations\u002F44.get-public-cart",{"title":279,"path":280,"stem":281},"createPublicCart","\u002Fen\u002Freference\u002Foperations\u002Fcreate-public-cart","en\u002F6.reference\u002F3.operations\u002F45.create-public-cart",{"title":283,"path":284,"stem":285},"getStorefrontOrderAfterSalesEligibility","\u002Fen\u002Freference\u002Foperations\u002Fget-storefront-order-after-sales-eligibility","en\u002F6.reference\u002F3.operations\u002F46.get-storefront-order-after-sales-eligibility",{"title":287,"path":288,"stem":289},"requestStorefrontOrderAfterSales","\u002Fen\u002Freference\u002Foperations\u002Frequest-storefront-order-after-sales","en\u002F6.reference\u002F3.operations\u002F47.request-storefront-order-after-sales",{"title":291,"path":292,"stem":293},"getStorefrontOrderCancellationEligibility","\u002Fen\u002Freference\u002Foperations\u002Fget-storefront-order-cancellation-eligibility","en\u002F6.reference\u002F3.operations\u002F48.get-storefront-order-cancellation-eligibility",{"title":295,"path":296,"stem":297},"cancelStorefrontOrder","\u002Fen\u002Freference\u002Foperations\u002Fcancel-storefront-order","en\u002F6.reference\u002F3.operations\u002F49.cancel-storefront-order",{"title":299,"path":300,"stem":301},"getStorefrontOrder","\u002Fen\u002Freference\u002Foperations\u002Fget-storefront-order","en\u002F6.reference\u002F3.operations\u002F50.get-storefront-order",{"title":303,"path":304,"stem":305},"listStorefrontOrders","\u002Fen\u002Freference\u002Foperations\u002Flist-storefront-orders","en\u002F6.reference\u002F3.operations\u002F51.list-storefront-orders",{"title":307,"path":308,"stem":309},"replayInstallationWebhookDelivery","\u002Fen\u002Freference\u002Foperations\u002Freplay-installation-webhook-delivery","en\u002F6.reference\u002F3.operations\u002F52.replay-installation-webhook-delivery",{"title":311,"path":312,"stem":313},"listInstallationWebhookDeliveries","\u002Fen\u002Freference\u002Foperations\u002Flist-installation-webhook-deliveries","en\u002F6.reference\u002F3.operations\u002F53.list-installation-webhook-deliveries",{"title":315,"path":316,"stem":317},"getInstallationWebhookSignatureFixture","\u002Fen\u002Freference\u002Foperations\u002Fget-installation-webhook-signature-fixture","en\u002F6.reference\u002F3.operations\u002F54.get-installation-webhook-signature-fixture",{"title":319,"path":320,"stem":321},"updateInstallationWebhook","\u002Fen\u002Freference\u002Foperations\u002Fupdate-installation-webhook","en\u002F6.reference\u002F3.operations\u002F55.update-installation-webhook",{"title":323,"path":324,"stem":325},"listInstallationWebhooks","\u002Fen\u002Freference\u002Foperations\u002Flist-installation-webhooks","en\u002F6.reference\u002F3.operations\u002F56.list-installation-webhooks",{"title":327,"path":328,"stem":329},"createInstallationWebhook","\u002Fen\u002Freference\u002Foperations\u002Fcreate-installation-webhook","en\u002F6.reference\u002F3.operations\u002F57.create-installation-webhook",{"title":331,"path":332,"stem":333},"listInstallationWebhookEvents","\u002Fen\u002Freference\u002Foperations\u002Flist-installation-webhook-events","en\u002F6.reference\u002F3.operations\u002F58.list-installation-webhook-events",{"title":335,"path":336,"stem":337},"Get public contact channels","\u002Fen\u002Freference\u002Foperations\u002Fget-public-contact","en\u002F6.reference\u002F3.operations\u002F59.get-public-contact",{"title":339,"path":340,"stem":341},"verifyStorefrontChallenge","\u002Fen\u002Freference\u002Foperations\u002Fverify-storefront-challenge","en\u002F6.reference\u002F3.operations\u002F60.verify-storefront-challenge",{"title":343,"path":344,"stem":345},"createStorefrontChallenge","\u002Fen\u002Freference\u002Foperations\u002Fcreate-storefront-challenge","en\u002F6.reference\u002F3.operations\u002F61.create-storefront-challenge",{"title":347,"path":348,"stem":349},"Get the public store security configuration","\u002Fen\u002Freference\u002Foperations\u002Fget-public-store-security-config","en\u002F6.reference\u002F3.operations\u002F62.get-public-store-security-config",{"title":351,"path":352,"stem":353},"Get the public runtime configuration","\u002Fen\u002Freference\u002Foperations\u002Fget-public-runtime-config","en\u002F6.reference\u002F3.operations\u002F63.get-public-runtime-config",{"title":355,"path":356,"stem":357},"Search public products","\u002Fen\u002Freference\u002Foperations\u002Fsearch-public-products","en\u002F6.reference\u002F3.operations\u002F64.search-public-products",{"title":359,"path":360,"stem":361},"Get the published Storefront decoration","\u002Fen\u002Freference\u002Foperations\u002Fget-public-storefront-decoration","en\u002F6.reference\u002F3.operations\u002F65.get-public-storefront-decoration",{"title":363,"icon":364,"path":365,"stem":366,"children":367,"page":22},"Examples","i-lucide-code-xml","\u002Fen\u002Fexamples","en\u002F7.examples",[368,372],{"title":369,"path":370,"stem":371},"Minimal Nuxt Storefront","\u002Fen\u002Fexamples\u002Fnuxt-storefront","en\u002F7.examples\u002F1.nuxt-storefront",{"title":373,"path":374,"stem":375},"Webhook verification","\u002Fen\u002Fexamples\u002Fwebhook-verification","en\u002F7.examples\u002F2.webhook-verification",{"title":377,"icon":378,"path":379,"stem":380,"children":381,"page":22},"Versions and support","i-lucide-life-buoy","\u002Fen\u002Foperations","en\u002F8.operations",[382,386],{"title":383,"path":384,"stem":385},"Versions, migrations, and changelog","\u002Fen\u002Foperations\u002Fversions-and-migrations","en\u002F8.operations\u002F1.versions-and-migrations",{"title":387,"path":388,"stem":389},"Support and security disclosure","\u002Fen\u002Foperations\u002Fsupport-and-security","en\u002F8.operations\u002F2.support-and-security",{"id":391,"title":30,"body":392,"description":566,"extension":567,"links":568,"meta":569,"navigation":570,"path":31,"seo":571,"stem":32,"__hash__":572},"docs_en\u002Fen\u002F2.storefront\u002F1.third-party-storefront.md",{"type":393,"value":394,"toc":563},"minimark",[395,399,403,408,462,495,498,501,531,538,548,559],[396,397,30],"h1",{"id":398},"third-party-storefront",[400,401,402],"p",{},"Public catalog reads use the API-selected store, market, and publication state. A custom domain must not infer access from a product ID, slug, search result, cached JSON-LD, sitemap, or OpenGraph response.",[404,405,407],"h2",{"id":406},"hosted-redirect-model","Hosted redirect model",[409,410,415],"pre",{"className":411,"code":412,"language":413,"meta":414,"style":414},"language-mermaid shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","flowchart LR\n  A[Third-party store: read and render the public catalog] --> B{User action}\n  B -->|Sign in or register| C[Official Ayalink authorization domain: not yet available]\n  B -->|Checkout or pay| D[Official Ayalink hosted checkout: not yet available]\n  C --> E[Reviewed exact return URL]\n  D --> E\n  E --> A\n","mermaid","",[416,417,418,426,432,438,444,450,456],"code",{"__ignoreMap":414},[419,420,423],"span",{"class":421,"line":422},"line",1,[419,424,425],{},"flowchart LR\n",[419,427,429],{"class":421,"line":428},2,[419,430,431],{},"  A[Third-party store: read and render the public catalog] --> B{User action}\n",[419,433,435],{"class":421,"line":434},3,[419,436,437],{},"  B -->|Sign in or register| C[Official Ayalink authorization domain: not yet available]\n",[419,439,441],{"class":421,"line":440},4,[419,442,443],{},"  B -->|Checkout or pay| D[Official Ayalink hosted checkout: not yet available]\n",[419,445,447],{"class":421,"line":446},5,[419,448,449],{},"  C --> E[Reviewed exact return URL]\n",[419,451,453],{"class":421,"line":452},6,[419,454,455],{},"  D --> E\n",[419,457,459],{"class":421,"line":458},7,[419,460,461],{},"  E --> A\n",[463,464,465,477,483,489],"ul",{},[466,467,468,472,473,476],"li",{},[469,470,471],"strong",{},"Catalog reads: Available."," Call only operations listed in the ",[474,475,38],"a",{"href":39},".",[466,478,479,482],{},[469,480,481],{},"Hosted login backend session foundation: Published contract."," The artifact includes server-side initiate and return operations protected by API Key and PKCE-related fields. The official login UI, authorization-domain production configuration, and browser-ready redirect flow are not complete, so there is no executable redirect example.",[466,484,485,488],{},[469,486,487],{},"Hosted checkout backend session foundation: Published contract."," The artifact includes server-side create, get, and cancel session operations. Official checkout UI, final order creation, provider payment progression, production configuration, and migrations are not complete; this is not evidence that checkout or payment is available.",[466,490,491,494],{},[469,492,493],{},"Return: Platform enablement required."," A future flow may return only to an exact HTTPS return URL reviewed by the platform; no open redirect or client-side override is allowed.",[400,496,497],{},"A third party must not collect an Ayalink email, password, or MFA; accept or forward the global Ayalink Cookie; handle card data, payment tokens, or any other payment credential; or iframe, proxy, or imitate an Ayalink sign-in, registration, checkout, or payment page. The third-party site renders the catalog and initiates only a future top-level redirect approved by a public contract.",[400,499,500],{},"When a store protects a page or resource, the API applies the same policy to details, prices, inventory, media, structured data, SSR, search, sitemap, and cache. Handle:",[463,502,503,509,515,521],{},[466,504,505,508],{},[416,506,507],{},"401",": send the user through system-domain OAuth and return to an allowlisted local route;",[466,510,511,514],{},[416,512,513],{},"403",": the authenticated user lacks the required membership, role, customer group, market, or scope;",[466,516,517,520],{},[416,518,519],{},"404",": the store chose anti-enumeration semantics for a hidden resource;",[466,522,523,526,527,530],{},[416,524,525],{},"429"," or ",[416,528,529],{},"CHALLENGE_REQUIRED",": render a scoped challenge and retry the original request once.",[400,532,533,534,537],{},"Cache public responses only by the complete server-declared key, including store, market, language, policy version, and authentication class. User-specific responses are ",[416,535,536],{},"private\u002Fno-store"," and must never enter a shared CDN cache.",[400,539,540,541,544,545,476],{},"The browser never receives a client secret or stores an access or refresh token, and it must not proxy or share the Ayalink global-session Cookie. Future sign-in occurs only on the official authorization domain confirmed by platform enablement materials, using Authorization Code with PKCE S256, an exact redirect URI, ",[416,542,543],{},"state",", and ",[416,546,547],{},"nonce",[400,549,550,551,554,555,558],{},"Use a same-origin BFF for a durable session. It stores only the minimal OAuth grant for its own app, installation, store\u002Fresource, and audience, then gives its frontend a secure application-session Cookie. It never forwards an Ayalink Cookie. OAuth APIs are pending security review, so the ",[474,552,553],{"href":49},"account authorization boundary"," and ",[474,556,557],{"href":370},"minimal Nuxt example"," provide no sign-in endpoint or token-exchange code.",[560,561,562],"style",{},"html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":414,"searchDepth":428,"depth":428,"links":564},[565],{"id":406,"depth":428,"text":407},"Build an independent storefront while preserving Ayalink identity, access policy, cache, and challenge boundaries.","md",null,{},true,{"title":30,"description":566},"KwjdEPrLEdOcSmRNHm01pytcnY8g0-9LC6oEBLnqnkY",[574,576],{"title":19,"path":20,"stem":21,"description":575,"children":-1},"An end-to-end path from readiness and platform enablement through authorization, API use, Webhooks, testing, production, and emergency revocation.",{"title":34,"path":35,"stem":36,"description":577,"children":-1},"Limit Turnstile to bot protection on official sign-in and authorization endpoints, not proof of site authenticity or login.",1786284815913]