merce.STACK
merce.STACK
Skip to content
PricingDevelopersSecurityAbout
Log inRequest access
{}Developers
GuidesAPI referenceChangelogGet API keys →
  • Get started

    • Quickstart
    • Keys & authentication
  • Storefront

    • Products & catalog
    • Carts
    • Checkout & payment
    • Customer accounts
    • Digital products
    • Without a build step
  • Server API

    • Server API
    • Customers
    • Payment links & transactions
    • Balance & payouts
    • Classes & students
    • Node SDK
  • Events & errors

    • Webhooks
    • Errors
  • Reference

    • API reference
    • Changelog

Server API

Server API

Customers, payments, payouts and classes from your backend, with a secret key.

The storefront API is what a shop front calls from the browser. The server API is for your backend: an ERP sync, an accounting export, a school's own sign-up flow. It uses a secret key with only the scopes you grant, and refuses publishable keys outright.

Base URL

Shell
https://api.mercestack.com/v1

# Self-hosted: your API's /api path
https://mercestack.example.com/api/v1

Scopes

ScopeGrants
customers:read / customers:writeCRM customers
payments:readPayment links and transactions
payments:writeCreate and deactivate payment links
payouts:readYour balance and payout history
classrooms:readClasses and their students
classrooms:writeEnrol people without payment
products:* inventory:* orders:* …The commerce Management API — see Keys & authentication

Responses

Every response is an envelope: { "success": true, "statusCode": 200, "message": "…", "data": … }. The examples on these pages show data. The SDKs unwrap it for you. Errors have success: false, a human message, and an HTTP status — see Errors.

Pagination

Lists are newest first and page by cursor. Pass limit (1–100) and, for the next page, the nextCursor you were given. A cursor stays valid while rows are being added — you will not see an item twice or skip one.

JSON
{
  "object": "list",
  "data": [ … ],
  "hasMore": true,
  "nextCursor": "MjAyNi0wOS0yN1QxMDowMDowMC4wMDBafDBiMWQ…"
}

Idempotency

Creates accept an Idempotency-Key header. Send a unique value — an order id, a UUID — and a retry with the same key returns the first result instead of creating a second payment link. Keys are remembered for 24 hours per API key. Reusing a key for a different request is a 409.

Secret keys never go in a browser

A secret key sent from a page (with an Origin header) is refused, and so is a publishable key on any server route. If a secret key leaks, revoke it in Developers — the old one stops working immediately.

← PreviousWithout a build stepNext →Customers

On this page

  • Base URL
  • Scopes
  • Responses
  • Pagination
  • Idempotency
Request accessTalk to usPricing

Mercestack is the business operating system — your team, customers, store, classes and payouts in one place.

Request access

Platform

  • Overview
  • Organization & work
  • Customers, support & messaging
  • Payments, store & classes
  • Flow, AI & Marverse
  • Analytics, growth & files

Developers

  • Quickstart
  • Server API
  • Customer accounts
  • Payment links
  • Webhooks
  • Changelog

Company

  • About
  • Pricing
  • Security
  • Contact
  • Report a vulnerability

Legal

  • Privacy
  • Terms
  • Cookie policy
  • GDPR
  • Privacy contact

© 2026 Mercestack. All rights reserved.

Mercestack StructureOS

mercestack