merce.STACK
merce.STACK
Skip to content
PricingDevelopersSecurityAbout
Log inRequest access
{}Developers
GuidesAPI referenceChangelogGet API keys →
  • Get started

    • Quickstart
    • Keys & authentication
  • Storefront

    • Products & catalog
    • Carts
    • Checkout & payment
    • Customer accounts
    • Digital products
    • Without a build step
  • Server API

    • Server API
    • Customers
    • Payment links & transactions
    • Balance & payouts
    • Classes & students
    • Node SDK
  • Events & errors

    • Webhooks
    • Errors
  • Reference

    • API reference
    • Changelog

Storefront

Customer accounts

Sign up, sign in with a password or Google, sign out, reset a password, keep addresses.

Shoppers can have an account on your store. It is separate from your team's Mercestack logins — a shopper never becomes a member of your workspace — and it works the same on the hosted storefront and on your own site through the API.

Every sign-in returns a customer session: a token you send as X-Mercestack-Customer-Token next to your publishable key. The JavaScript SDK stores it for you. Orders are matched by email, so a new account sees everything bought with its address before it existed.

  • —Passwords are at least 8 characters. Five wrong attempts lock sign-in for that email for 15 minutes.
  • —Signing out revokes the session everywhere, not just on this device.
  • —A reset link works once, expires in 30 minutes, and stops working if the password changes first.
  • —Every account is linked to a customer in your CRM, created if needed.

Create an account

POST/v1/storefront/customer/register
Publishable key

Creates the account and signs it in. Returns 409 if the email already has an account — send the shopper to sign in instead.

Body

emailstringrequired
Shopper's email.
passwordstringrequired
At least 8 characters.
namestringrequired
Full name.
phonestring
Optional.
curl -X POST https://api.mercestack.com/v1/storefront/customer/register \
  -H "Authorization: Bearer pk_test_…" \
  -H "Content-Type: application/json" \
  -d '{"email":"[email protected]","password":"a-long-password","name":"Bola Adeyemi"}'
Response
{
  "token": "eyJhbGciOi…",
  "customer": {
    "id": "0b1d6e0e-…",
    "email": "[email protected]",
    "name": "Bola Adeyemi",
    "phone": "+2348030000000",
    "emailVerified": true,
    "hasPassword": true,
    "google": false,
    "addresses": [],
    "createdAt": "2026-09-27T10:00:00.000Z"
  }
}

Sign in

POST/v1/storefront/customer/login
Publishable key

Email and password. A wrong password and an unknown email give the same answer, so the endpoint can't be used to find out who shops with you.

Body

emailstringrequired
Shopper's email.
passwordstringrequired
Their password.
curl -X POST https://api.mercestack.com/v1/storefront/customer/login \
  -H "Authorization: Bearer pk_test_…" \
  -H "Content-Type: application/json" \
  -d '{"email":"[email protected]","password":"a-long-password"}'
Response
{ "token": "eyJhbGciOi…", "customer": { … } }

Sign in with Google

POST/v1/storefront/customer/google
Publishable key

Creates the account on first use and signs it in. Send either the idToken from Google Identity Services, or an authorization code with its PKCE codeVerifier and redirectUri. The token's audience must be your platform's Google client.

Body

idTokenstring
A Google ID token.
codestring
Or: an OAuth authorization code…
codeVerifierstring
…its PKCE verifier…
redirectUristring
…and the redirect URI it was issued for.
curl -X POST https://api.mercestack.com/v1/storefront/customer/google \
  -H "Authorization: Bearer pk_test_…" \
  -H "Content-Type: application/json" \
  -d '{"idToken":"eyJhbGciOiJSUzI1NiIs…"}'
Response
{ "token": "eyJhbGciOi…", "customer": { … }, "verifyUrl": "https://…" }

Sign out

POST/v1/storefront/customer/logout
Publishable key + customer session

Ends every session the account has. The token you sent stops working immediately.

curl -X POST https://api.mercestack.com/v1/storefront/customer/logout \
  -H "Authorization: Bearer pk_test_…" \
  -H "X-Mercestack-Customer-Token: <session>"
Response
{ "signedOut": true }

Send a reset link

POST/v1/storefront/customer/password/forgot
Publishable key

Emails a link to <your store>/account/reset?token=…. Always answers the same way, whether or not the email has an account.

Body

emailstringrequired
Account email.
curl -X POST https://api.mercestack.com/v1/storefront/customer/password/forgot \
  -H "Authorization: Bearer pk_test_…" \
  -H "Content-Type: application/json" \
  -d '{"email":"[email protected]"}'
Response
{ "sent": true, "previewUrl": null }

Set a new password

POST/v1/storefront/customer/password/reset
Publishable key

Takes the token from the reset link. Signs the shopper in and ends their other sessions.

Body

tokenstringrequired
From the reset link.
passwordstringrequired
The new password.
curl -X POST https://api.mercestack.com/v1/storefront/customer/password/reset \
  -H "Authorization: Bearer pk_test_…" \
  -H "Content-Type: application/json" \
  -d '{"token":"eyJhbGciOi…","password":"a-new-password"}'
Response
{ "token": "eyJhbGciOi…", "customer": { … } }

Get the signed-in shopper

GET/v1/storefront/customer/me
Publishable key + customer session

Profile and saved addresses. A shopper signed in with an emailed link but no account gets id: null.

curl https://api.mercestack.com/v1/storefront/customer/me \
  -H "Authorization: Bearer pk_test_…" \
  -H "X-Mercestack-Customer-Token: <session>"
Response
{
  "id": "0b1d6e0e-…",
  "email": "[email protected]",
  "name": "Bola Adeyemi",
  "phone": "+2348030000000",
  "emailVerified": true,
  "hasPassword": true,
  "google": false,
  "addresses": [],
  "createdAt": "2026-09-27T10:00:00.000Z"
}

Update the profile

PATCH/v1/storefront/customer/me
Publishable key + customer session

Name and phone. Email changes aren't supported yet.

Body

namestring
Full name.
phonestring | null
Phone, or null to clear it.
curl -X PATCH https://api.mercestack.com/v1/storefront/customer/me \
  -H "Authorization: Bearer pk_test_…" \
  -H "X-Mercestack-Customer-Token: <session>" \
  -H "Content-Type: application/json" \
  -d '{"phone":"+2348030000000"}'
Response
{
  "id": "0b1d6e0e-…",
  "email": "[email protected]",
  "name": "Bola Adeyemi",
  "phone": "+2348030000000",
  "emailVerified": true,
  "hasPassword": true,
  "google": false,
  "addresses": [],
  "createdAt": "2026-09-27T10:00:00.000Z"
}

Add an address

POST/v1/storefront/customer/me/addresses
Publishable key + customer session

Saves an address for checkout. Setting isDefault makes it the only default. Up to 20 per account.

Body

namestringrequired
Recipient.
line1stringrequired
Street address.
citystringrequired
City.
countrystringrequired
Country name.
labelstring
"Home", "Office".
line2, state, postalCode, phonestring
Optional.
isDefaultboolean
Use at checkout by default.
curl -X POST https://api.mercestack.com/v1/storefront/customer/me/addresses \
  -H "Authorization: Bearer pk_test_…" \
  -H "X-Mercestack-Customer-Token: <session>" \
  -H "Content-Type: application/json" \
  -d '{"name":"Bola Adeyemi","line1":"1 Marina","city":"Lagos","country":"Nigeria","isDefault":true}'
Response
[ { "id": "…", "label": "Home", "city": "Lagos", "isDefault": true, … } ]

Remove an address

DELETE/v1/storefront/customer/me/addresses/:id
Publishable key + customer session

Returns the addresses that are left.

curl -X DELETE https://api.mercestack.com/v1/storefront/customer/me/addresses/ADDRESS_ID \
  -H "Authorization: Bearer pk_test_…" \
  -H "X-Mercestack-Customer-Token: <session>"
Response
[]

In React

TypeScript
import { useCustomer } from "@mercestack/commerce-react";

function Account() {
  const { customer, signedIn, login, logout, loading } = useCustomer();
  if (loading) return null;
  if (!signedIn) return <SignInForm onSubmit={login} />;
  return <button onClick={logout}>Sign out {customer!.name}</button>;
}
← PreviousCheckout & paymentNext →Digital products

On this page

  • POSTCreate an account
  • POSTSign in
  • POSTSign in with Google
  • POSTSign out
  • POSTSend a reset link
  • POSTSet a new password
  • GETGet the signed-in shopper
  • PATCHUpdate the profile
  • POSTAdd an address
  • DELETERemove an address
  • In React
Request accessTalk to usPricing

Mercestack is the business operating system — your team, customers, store, classes and payouts in one place.

Request access

Platform

  • Overview
  • Organization & work
  • Customers, support & messaging
  • Payments, store & classes
  • Flow, AI & Marverse
  • Analytics, growth & files

Developers

  • Quickstart
  • Server API
  • Customer accounts
  • Payment links
  • Webhooks
  • Changelog

Company

  • About
  • Pricing
  • Security
  • Contact
  • Report a vulnerability

Legal

  • Privacy
  • Terms
  • Cookie policy
  • GDPR
  • Privacy contact

© 2026 Mercestack. All rights reserved.

Mercestack StructureOS

mercestack