Server API
Server API
Customers, payments, payouts and classes from your backend, with a secret key.
The storefront API is what a shop front calls from the browser. The server API is for your backend: an ERP sync, an accounting export, a school's own sign-up flow. It uses a secret key with only the scopes you grant, and refuses publishable keys outright.
Base URL
https://api.mercestack.com/v1
# Self-hosted: your API's /api path
https://mercestack.example.com/api/v1Scopes
| Scope | Grants |
|---|---|
customers:read / customers:write | CRM customers |
payments:read | Payment links and transactions |
payments:write | Create and deactivate payment links |
payouts:read | Your balance and payout history |
classrooms:read | Classes and their students |
classrooms:write | Enrol people without payment |
products:* inventory:* orders:* … | The commerce Management API — see Keys & authentication |
Responses
Every response is an envelope: { "success": true, "statusCode": 200, "message": "…", "data": … }. The examples on these pages show data. The SDKs unwrap it for you. Errors have success: false, a human message, and an HTTP status — see Errors.
Pagination
Lists are newest first and page by cursor. Pass limit (1–100) and, for the next page, the nextCursor you were given. A cursor stays valid while rows are being added — you will not see an item twice or skip one.
{
"object": "list",
"data": [ … ],
"hasMore": true,
"nextCursor": "MjAyNi0wOS0yN1QxMDowMDowMC4wMDBafDBiMWQ…"
}Idempotency
Creates accept an Idempotency-Key header. Send a unique value — an order id, a UUID — and a retry with the same key returns the first result instead of creating a second payment link. Keys are remembered for 24 hours per API key. Reusing a key for a different request is a 409.