Skip to content
pcreative Commerce

API routes

Routes under /gestion require a panel session (and seller routes, a seller's session).

Generated by scripts/generar-referencia.mjs. Do not edit by hand.

Routes under /gestion require a panel session (and seller routes, a seller's session). Routes under /tienda require the sales channel's publishable key in the x-pcc-clave header, and the customer account ones also the customer's session. The rest have their own policy: gateway and provider notices, licences, installation, health.

Admin panel (/gestion)

RouteMethodsAccessWhat it does
/gestion/aiGET, POSTpanel sessionGET: AI settings, which provider keys are set and the model catalogue; POST: validate and save the AI settings
/gestion/ai/contenidoPOSTpanel sessionDrafts product copy with AI (tarea: ficha, alt or traducir) and returns it as a proposal; saves nothing, logs the cost
/gestion/ai/copilotoPOSTpanel sessionAnswers a question about the store by reading its data; write actions come back as proposals and are never executed
/gestion/ai/copiloto/aplicarPOSTpanel sessionApplies a copilot proposal a person approved: change a variant's EUR price or approve/reject a review
/gestion/ai/indiceGET, POSTpanel sessionGET: state of the semantic search index; POST: re-index every published product and return the cost (400 without pgvector)
/gestion/ai/mcpGET, POSTpanel sessionGET: whether the AI agents endpoint is on and what is missing to turn it on; POST: turn it on or off (needs an AI provider key)
/gestion/ai/probarPOSTpanel sessionMakes a real test call to the configured chat provider with the saved settings
/gestion/ai/usoGETpanel sessionAI spend over the last dias days (30 by default): totals, breakdown per task and the last 20 calls
/gestion/autores/solicitudesGETpanel sessionLists applications to become an author, optionally filtered by estado
/gestion/autores/solicitudes/{id}POSTpanel sessionDecides on an author application (aceptada, rechazada or revisando); accepting creates the seller and emails a password link
/gestion/avisosGETpanel sessionWhat needs looking at today, as a list of warnings; an empty list is good news
/gestion/boletinGETpanel sessionLists newsletter subscribers who have confirmed their address
/gestion/boletin-conectorGETpanel sessionGET: the email services the newsletter can sync with, which one is connected, how the last sync went and how many addresses the service does not know yet
/gestion/boletin-conector/{nombre}DELETE, POSTpanel sessionPOST: saves that service's keys and connects it, or, with accion, tests the connection or forces a sweep now; DELETE: deletes its keys (the store's own list is untouched). Administrator only: these are a third party's keys
/gestion/boletin/{id}/bajaPOSTpanel sessionUnsubscribes that person from the panel, without needing their link
/gestion/boletin/csvGETpanel sessionThe same list as a CSV file, consent proof included
/gestion/boletin/suscritosGETpanel sessionThe newsletter list with each person's consent proof: the exact text shown, its version, the IP, the browser and the confirmation date
/gestion/capabilitiesGETpanel sessionExtra panel sections this installation has (flags and menu entries), such as the marketplace when it is enabled
/gestion/cart-recoveryGETpanel sessionAbandoned carts from the last 30 days (with email, idle 30+ minutes) and recovery statistics
/gestion/cart-recovery/{id}/resendPOSTpanel sessionEmails a cart's recovery reminder by hand and marks it as sent; 400 if it has no email or is already an order
/gestion/categoriasGET, PATCH, POSTpanel sessionGET: the flat category list with its parent; POST: creates one; PATCH: reorders them, the position in the list being the order
/gestion/categorias/{id}DELETE, POSTpanel sessionPOST: changes a category's name, handle, description, order, parent or visibility; DELETE: takes it down, its children move up and its products are freed
/gestion/clave-tiendaGETpanel sessionReturns the sales channel's publishable key that storefronts send
/gestion/clientesGETpanel sessionLists customers, with text search (q) and pagination
/gestion/clientes/{id}GET, PATCHpanel sessionGET: one customer; PATCH: update their details with If-Match (412 on conflict); the email cannot be changed here (422)
/gestion/cobros/pagos/{id}POSTpanel sessionSettles a scheduled author payout by hand: confirm it with a bank reference, or mark it failed with accion: fallido
/gestion/cobros/pagos/{id}/enviarPOSTpanel sessionSends a scheduled author payout through the configured payout rail; the payout id is the reference, so retries are safe
/gestion/cobros/por-pagarGETpanel sessionAuthors due a payout in this run, for one currency (moneda, eur by default)
/gestion/cobros/vendedores/{id}/bloquearPOSTpanel sessionBlocks an author's payouts with a reason (they are told by email), or unblocks them with accion: desbloquear
/gestion/cobros/vendedores/{id}/pagarPOSTpanel sessionSchedules a payout to an author for a period (all that is available unless importe); 400 if they cannot be paid yet
/gestion/cobros/vendedores/{id}/pagosGETpanel sessionThe scheduled payouts of one author, seen from the store; the destination is the stored hint, never the account
/gestion/codigos/lotes/{lote}/revocarPOSTpanel sessionRevokes a batch of digital keys, with a mandatory reason
/gestion/collectionsGET, POSTpanel sessionGET: the store's collections with how many products each one holds; POST: creates one
/gestion/collections/{id}DELETE, POSTpanel sessionPOST: renames a collection or changes its handle; DELETE: takes it down and frees its products
/gestion/create-staffPOSTpanel sessionCreates a staff account for the panel; 409 if the email is taken, 400 if the password is too weak
/gestion/customer-statsGETpanel sessionOrder count, spend in the store's main currency and last order date for the customers in ids (200 at most)
/gestion/desistimientosGETpanel sessionLists withdrawal requests (right of withdrawal) sent by buyers
/gestion/desistimientos/{id}/atenderPOSTpanel sessionMarks a withdrawal request as handled, with an optional note
/gestion/enviosGETpanel sessionThe shipping setup: zones, rates, shipping classes and the carriers available
/gestion/envios/clasesPOSTpanel sessionCreates a shipping class; 422 if it is not valid
/gestion/envios/clases/{id}DELETE, PATCHpanel sessionPATCH: update a shipping class (422 if not valid); DELETE: remove it (404 if it does not exist)
/gestion/envios/clases/{id}/productosGET, POSTpanel sessionGET: products in this shipping class; POST: assign the class to the given productos
/gestion/envios/tarifasPOSTpanel sessionCreates a shipping rate in a zone, with its conditions; 422 if it is not valid
/gestion/envios/tarifas/{id}DELETE, PATCHpanel sessionPATCH: update a shipping rate (422 if not valid); DELETE: remove it (404 if it does not exist)
/gestion/envios/zonasPOSTpanel sessionCreates a shipping zone; 422 if it is not valid
/gestion/envios/zonas/{id}DELETE, PATCHpanel sessionPATCH: update a shipping zone (422 if not valid); DELETE: remove it (404 if it does not exist)
/gestion/facturas-manualesGET, POSTpanel sessionGET: list manual invoices; POST: create a draft manual invoice (422 if it cannot be created)
/gestion/facturas-manuales/{id}DELETE, GET, PATCHpanel sessionGET: one manual invoice; PATCH: edit the draft or mark it paid (pagada); DELETE: delete the draft; 409 when no longer editable
/gestion/facturas-manuales/{id}/emitirPOSTpanel sessionIssues a manual invoice: gives it its number and freezes it with the store's tax ID; 409 if it cannot be issued
/gestion/facturas-manuales/{id}/rectificarPOSTpanel sessionCreates a corrective invoice for an issued manual invoice, with a reason; 409 if not allowed
/gestion/idiomasDELETE, GET, POSTpanel sessionGET: store languages and translation progress; POST: add a language (codigo, e.g. fr or pt-BR); DELETE: remove one (?codigo=, not the base)
/gestion/idiomas/traducirPOSTpanel sessionTranslates with AI whatever is missing for one entity type (tipo) into a language; rehacer redoes existing translations
/gestion/impuestosGETpanel sessionTax regions and rates, which currencies have tax-inclusive prices and how the storefront shows prices
/gestion/impuestos/csvGET, POSTpanel sessionGET: export every tax rate as CSV; POST: import rates from CSV text (reemplazar replaces them); 422 with per-row errors
/gestion/impuestos/ossGETpanel sessionEU OSS VAT report between desde and hasta (YYYY-MM-DD), as JSON or as CSV with formato=csv
/gestion/impuestos/precios-con-impuestoPOSTpanel sessionSets whether the prices in a currency already include tax (moneda, dentro)
/gestion/impuestos/precios-escaparatePOSTpanel sessionSets whether the storefront shows prices with or without tax (muestra)
/gestion/impuestos/referenciasGETpanel sessionProduct types and shipping options to choose from when writing tax rules
/gestion/impuestos/regiones/{id}DELETEpanel sessionDeletes a tax region
/gestion/impuestos/tasasPOSTpanel sessionCreates a tax rate; 422 if it is not valid
/gestion/impuestos/tasas/{id}DELETE, PATCHpanel sessionPATCH: update a tax rate (422 if not valid); DELETE: remove it
/gestion/impuestos/ueGET, POSTpanel sessionGET: the store's EU VAT settings; POST: save them (422 if not valid)
/gestion/impuestos/ue/tiposPOSTpanel sessionLoads the EU member states' VAT rates; only the missing ones unless reemplazar: true
/gestion/inventarioPOSTpanel sessionSets a variant's stock at a location (variant_id, location_id, stocked_quantity), recording who and why
/gestion/inventario/{id}/nivelesGET, POSTpanel sessionGET: an inventory item's stock at each location; POST: set its level at a location, creating it if missing
/gestion/legalGET, POSTpanel sessionGET: legal settings, countries with a legal profile and what applies; POST: save country, custom-item and digital-consent rules
/gestion/marketplace/mi-cuentaGETseller sessionA seller's own view: profile, balances, ledger, sub-orders and products; 403 unless the seller is active
/gestion/marketplace/vendedoresGET, POSTpanel sessionGET: sellers with their balances; POST: register a seller and email them a link to set a password (409 if duplicate)
/gestion/marketplace/vendedores/{id}GET, POSTpanel sessionGET: a seller's profile, balances, ledger and sub-orders; POST: change their details, status or commission (the slug cannot change)
/gestion/marketplace/vendedores/{id}/enviosGET, POSTpanel sessionGET: the seller's own shipping options and the store's ones they inherit; POST: set their options (option_ids)
/gestion/marketplace/vendedores/{id}/liquidarPOSTpanel sessionRecords a settlement paid to a seller (amount in cents, bank reference required); cannot exceed what is owed
/gestion/mercado/cobrosGET, POSTseller sessionGET: the author's payout profile, balance on hold and available, and payout history; POST: save their payout profile
/gestion/mercado/cobros/altaPOSTseller sessionRegisters the author with the payout provider and returns the identity verification (KYC) link
/gestion/mercado/cobros/cancelarPOSTseller sessionPOST: the author calls off their own withdrawal while it has not left yet (pago). Only theirs, only while previsto
/gestion/mercado/cobros/informeGETseller sessionThe author's statement between desde and hasta: every ledger line on the day the money moved, so a refund lands in the month it was refunded. CSV with formato=csv (para=excel for Excel)
/gestion/mercado/cobros/refrescarPOSTseller sessionAsks the payout provider again how the author's verification is going
/gestion/mercado/cobros/retirarPOSTseller sessionThe author withdraws their available balance (or importe); same checks as a scheduled payout, a double click cannot pay twice
/gestion/mercado/colaGETpanel sessionReview queue: authors' items waiting for the store to review them
/gestion/mercado/licenciasGETseller sessionLicences sold for the author's items, searchable with busca
/gestion/mercado/licencias/soltarPOSTseller sessionPOST: the author frees one activation of a licence for one of THEIR items (clave, instancia), so the buyer can move domain. Rate limited per licence and per author
/gestion/mercado/operador/licenciasGETpanel sessionEvery licence in the marketplace, for whoever runs it; filter with autor and search with busca. The buyer's address comes masked: searching by the whole address still finds it
/gestion/mercado/operador/piezas/{id}GETpanel sessionAn item in full for whoever runs the marketplace, without being its author: details, versions, review history and screenshots. Of the author only what is already public (name and slug), never their address or payout details
/gestion/mercado/perfilGET, POSTseller sessionGET: the author's public profile and support reputation; POST: save the profile
/gestion/mercado/piezasGET, POSTseller sessionGET: the author's own items (themes and extensions); POST: create a new item
/gestion/mercado/piezas/{id}GET, POSTseller sessionGET: one of the author's items; POST: save changes, or accion revisar to submit it for review or retirar to withdraw it
/gestion/mercado/piezas/{id}/capturasPOSTseller sessionUploads screenshots for an item (multipart); files are checked by content and SVGs with scripts are rejected
/gestion/mercado/piezas/{id}/capturas/{captura}DELETEseller sessionRemoves a screenshot from an item
/gestion/mercado/piezas/{id}/capturas/ordenPOSTseller sessionReorders an item's screenshots (ids in the new order)
/gestion/mercado/piezas/{id}/revisionPOSTpanel sessionThe store's review decision on an item: publicada, cambios or rechazada, with notes
/gestion/mercado/piezas/{id}/versionPOSTseller sessionUploads a new version package of an item (multipart: the file, version and notas)
/gestion/mercado/resumenGETseller sessionThe author's dashboard summary: figures for their items, their balance split into available and on hold, and how many support threads are waiting for their reply
/gestion/mercado/soporteGETseller sessionThe author's support inbox, filterable by estado
/gestion/mercado/soporte/{id}GET, POSTseller sessionGET: a support thread of the author; POST: reply (texto) or close it (cerrar)
/gestion/mercado/ventasGETseller sessionThe author's sales, one by one and by item, between desde and hasta. Each sale carries what was refunded from it, whenever that happened, and the buyer's billing country (nothing else about the buyer). CSV with formato=csv (para=excel for Excel)
/gestion/migracion/analizarPOSTpanel sessionDry run of a CSV import (products or customers, source detected): reports what would happen and changes nothing
/gestion/migracion/importarPOSTpanel sessionImports products or customers from a CSV; 422 if the analysis finds errors, unless forzar
/gestion/migracion/redireccionesPOSTpanel sessionBuilds old-to-new URL redirects from a CSV export, as nginx, apache, json or csv (?formato=)
/gestion/mudanzasGET, POSTpanel sessionGET: the latest 20 store migrations; POST: start one from Shopify or WooCommerce by API, checking the credentials first (422)
/gestion/mudanzas/{id}GET, POSTpanel sessionGET: a migration's progress by stage and its problems; POST: accion pausar, seguir or deshacer
/gestion/order-originGETpanel sessionWhere each of the given orders came from (ids): the storefront's sales channel, the dashboard or the migration that brought it over
/gestion/orders/{id}/notify-confirmedPOSTpanel sessionEmails the customer their order confirmation, with the invoice PDF attached when there is one
/gestion/paginasGET, POSTpanel sessionGET: every content page, drafts included; POST: create one (422 without titulo)
/gestion/paginas/{id}DELETE, POSTpanel sessionPOST: update a page; DELETE: soft-delete it (it can be recovered)
/gestion/paginas/{id}/traduccionesDELETE, GET, PUTpanel sessionGET: what is written in each language; PUT: save one language (idioma plus titulo, extracto, contenido, seo; a blank field falls back to the base language); DELETE ?idioma=: back to the base language
/gestion/pagos-ajustesGET, POSTpanel sessionGET: payment providers, regions with their providers and method texts; POST: set a region's providers and/or method texts and surcharges
/gestion/pasarelasGETpanel sessionPayment gateways configured from the panel, their state and webhook URLs; 404 if gateways are managed outside the panel
/gestion/pasarelas/{nombre}DELETE, POSTpanel sessionPOST: save a gateway's credentials, turn it on or off or switch test mode; DELETE: forget its configuration; both return the list
/gestion/pedidosGET, POSTpanel sessionGET: lists orders, with text search (q) and pagination; POST: creates a draft order by hand with a customer, its lines (prices in cents) and its totals
/gestion/pedidos/{id}GETpanel sessionOne order with everything the panel shows about it
/gestion/pedidos/{id}/cancelarPOSTpanel sessionCancels an order with a reason; 409 if it cannot be cancelled, e.g. already charged unless permitir_con_cobro
/gestion/pedidos/{id}/cobrarPOSTpanel sessionCaptures the order's authorised payments and marks them as charged
/gestion/pedidos/{id}/completarPOSTpanel sessionMarks an order as completed; 409 if it is not ready yet, which forzar overrides
/gestion/pedidos/{id}/envios/{envio}/entregadoPOSTpanel sessionMarks one of the order's shipments as delivered; 409 if that is not possible
/gestion/pedidos/{id}/envios/{envio}/enviadoPOSTpanel sessionMarks one of the order's shipments as shipped and emails the customer that it is on its way; the tracking numbers go in seguimiento; doing it twice sends nothing
/gestion/pedidos/{id}/prepararPOSTpanel sessionCreates a fulfilment, taking all or the given items out of stock at a location; 200 if it was already done, 201 if new
/gestion/pedidos/{id}/rectificarPOSTpanel sessionIssues a corrective invoice for an order, with a reason; 409 if not allowed
/gestion/pedidos/{id}/reembolsosGET, POSTpanel sessionGET: what can still be refunded and what already has been; POST: refund (amount, payment, restock); send Idempotency-Key, 409 if invalid
/gestion/pluginsGET, POSTpanel sessionGET: installed plugins with their state, permissions, routes and last error; POST: reload every plugin
/gestion/plugins/{id}GETpanel sessionThe last 200 log lines of a plugin
/gestion/plugins/{id}/ajustesGET, PUTpanel sessionGET: a plugin's settings fields and values, secrets hidden; PUT: validate and save them (422 if invalid; needs a reload)
/gestion/postsGET, POSTpanel sessionGET: blog posts, drafts included; POST: create a post (the handle comes from the title if missing)
/gestion/posts/{id}DELETE, GET, POSTpanel sessionGET: one blog post; POST: update it; DELETE: delete it
/gestion/productosGET, POSTpanel sessionGET: products with search, status filter and pagination; POST: create a product (Idempotency-Key supported, 200 on repeat)
/gestion/productos/{id}DELETE, GET, POSTpanel sessionGET: the full product; POST: update it with If-Match (412 on conflict); DELETE: delete it
/gestion/productos/{id}/editor-variantesGETpanel sessionData for the variant editor: the product's options, values and variants
/gestion/productos/{id}/historialGETpanel sessionThe product's change history: who changed what and when
/gestion/productos/{id}/historial-stockGETpanel sessionThe stock movements of the product's variants: who changed them, when, in which warehouse and from what to what
/gestion/productos/{id}/opcionesPOSTpanel sessionSaves the product's options and, unless generar: false, creates the variants that are missing
/gestion/productos/{id}/opciones/vista-previaPOSTpanel sessionPreviews which variants the given options would create or remove, without saving anything
/gestion/productos/{id}/personalizacionGET, POSTpanel sessionGET: the customisation fields buyers fill in; POST: save them (400 naming the faulty field)
/gestion/productos/{id}/precios-por-cantidadDELETE, GET, POSTpanel sessionGET: the product's quantity pricing rule; POST: save it; DELETE: remove it
/gestion/productos/{id}/variantesPOSTpanel sessionCreates one variant from its option valores
/gestion/productos/{id}/variantes-lotePOSTpanel sessionApplies the same cambios to several variants (ids)
/gestion/productos/{id}/variantes-ordenPOSTpanel sessionSets the order in which the variants are shown (ids)
/gestion/productos/{id}/variantes/{variante}POSTpanel sessionUpdates a variant and its price with If-Match (412 on conflict)
/gestion/productos/{id}/variantes/{variante}/codigosGET, POSTpanel sessionGET: the variant's key batches with free and delivered counts, plus its settings; POST: import keys from text as a new batch
/gestion/productos/{id}/variantes/{variante}/codigos/ajustesPOSTpanel sessionSaves the variant's digital key settings and recalculates its stock from the free keys
/gestion/productos/{id}/variantes/{variante}/detallePOSTpanel sessionUpdates a variant's details from the variant editor
/gestion/productos/{id}/variantes/{variante}/digitalGET, POSTpanel sessionGET: the variant's downloadable files and settings; POST: upload one file (multipart)
/gestion/productos/{id}/variantes/{variante}/digital/{fichero}DELETEpanel sessionDeletes one of the variant's downloadable files
/gestion/productos/{id}/variantes/{variante}/digital/ajustesPOSTpanel sessionSaves the variant's download settings and marks it as digital
/gestion/productos/{id}/variantes/{variante}/packDELETE, GET, POSTpanel sessionGET: what the bundle variant is made of; POST: save its contents; DELETE: stop it being a bundle
/gestion/products/visibilityPOSTpanel sessionBulk visibility (action): show-all publishes all, hide-all drafts all, limit publishes only the first count products
/gestion/promocionesGET, POSTpanel sessionGET: the store's promotions and coupons with their rules; POST: creates one
/gestion/promociones/{id}DELETE, GET, POSTpanel sessionGET: the full promotion with its conditions, targets and buy rules; POST: rewrites it whole; DELETE: takes it down without touching the orders that already used it
/gestion/proveedores-pagoGETpanel sessionLists the payment providers
/gestion/puntosGETpanel sessionLoyalty programme overview: settings, liability, breakage, movements over dias days and customers by balance
/gestion/puntos/ajustesGET, POSTpanel sessionGET: the points programme settings and their defaults; POST: change them (only known keys; 400 if nothing to change)
/gestion/puntos/clientes/{id}GET, POSTpanel sessionGET: a customer's points ledger with their live batches; POST: manual adjustment with a mandatory note
/gestion/quien-soyGETpanel sessionThe signed-in panel user; 403 if the session is not a panel one
/gestion/regionesGETpanel sessionLists the regions
/gestion/regiones/{id}PATCHpanel sessionUpdates a region with If-Match (412 on conflict); 409 if the currency changes while orders use it
/gestion/reviewsGETpanel sessionReviews to moderate, filterable by status (200 at most)
/gestion/reviews/{id}DELETE, POSTpanel sessionPOST: set a review's status (pending, approved or rejected); DELETE: delete it
/gestion/saldoGETpanel sessionStore credit owed and the list of balances (gift cards and customer credit), filterable by tipo, paginated
/gestion/saldo/{id}DELETE, GETpanel sessionGET: a balance with its movements; DELETE: deactivate it
/gestion/saldo/clientesPOSTpanel sessionAdds or removes store credit for a customer (amount in units, note required); 409 if it would go negative
/gestion/saldo/tarjetasPOSTpanel sessionIssues a gift card by hand; the code is returned only once and emailed to the recipient if one is given
/gestion/scanGETpanel sessionFinds a variant by exact barcode, or searches by SKU, barcode or title (q), with its stock at location_id (the first warehouse if none is given) and the total across warehouses in stock_all_locations; 404 if that warehouse does not exist
/gestion/scan/adjustPOSTpanel sessionAdds, subtracts or sets a variant's stock at location_id (mode: add, sub or set); without it, the first warehouse. 404 if that warehouse does not exist, 409 if there is none and 400 if the variant does not track inventory there
/gestion/scan/bindPOSTpanel sessionAssigns a barcode to a variant; 409 if another variant already has it
/gestion/scan/count-applyPOSTpanel sessionApplies a full stock count: sets each listed variant to its counted quantity and reports the ones skipped
/gestion/send-invoicePOSTpanel sessionEmails an invoice PDF through the normal mail queue. Say which invoice it is (pedido or factura); the recipient must be its customer or an address in PCC_FACTURA_DESTINOS, and the send is rate limited and audited
/gestion/soporteGETpanel sessionThe store's support inbox (100 at most), longest-waiting first, filterable by estado
/gestion/soporte/{id}DELETE, GET, POSTpanel sessionGET: the whole conversation; POST: set its status (abierta, esperando or resuelta); DELETE: delete it with its messages
/gestion/soporte/{id}/borradorPOSTpanel sessionDrafts a reply with AI from the conversation and the customer's orders; saves it as a draft and does not send it
/gestion/soporte/{id}/responderPOSTpanel sessionEmails the reply to the customer, discards any draft and marks the conversation as waiting
/gestion/soporte/borrarGET, POSTpanel sessionGET: the retention period in months; POST: delete now, either what is past the period or everything from one email
/gestion/tema-activoGET, POSTpanel sessionGET: the active theme, installed themes and which have settings; POST: switch to another theme (tema)
/gestion/temas-ajustesGET, POSTpanel sessionGET: a theme's design settings (?tema=); POST: save them, merged or replaced with reemplazar
/gestion/temas-demoGET, POSTpanel sessionGET: what a theme's demo content includes, without importing it; POST: import it (409 unless the store is freshly installed)
/gestion/tiendaGET, PATCHpanel sessionGET: the store and its settings, with ETag; PATCH: merge settings into metadata (and name) with If-Match (412)
/gestion/tokensGET, POSTpanel sessionGET: the store's service tokens and the catalogue of areas they can be given; POST: mints one and returns it the only time it is ever shown
/gestion/tokens/{id}DELETEpanel sessionRevokes a service token; it stops working on its next request and the row is kept so it is still known what it could reach
/gestion/ubicacionesGETpanel sessionLists the stock locations (warehouses)
/gestion/uploadsPOSTpanel sessionUploads images (multipart, 16 MB) and returns their URLs; files are checked by content and rejected ones are listed
/gestion/usuariosGETpanel sessionLists the store's staff, with search and pagination
/gestion/usuarios/{id}DELETE, GET, PATCHpanel sessionGET: one staff user; PATCH: update with If-Match (412); DELETE: remove them and close their sessions (409 if last admin)
/gestion/wishlistGETpanel sessionThe most wished-for products across customers' wishlists, with totals

Store (/tienda)

RouteMethodsAccessWhat it does
/tienda/autores/{slug}GETpublic, with publishable keyAn author's public profile with their items for sale in this store, at catalogue prices, and their support reputation
/tienda/autores/solicitudesPOSTpublic, with publishable keySends an application to become an author in the store's marketplace
/tienda/boletinPOSTpublic, with publishable keyNewsletter sign-up recording the consent given; emails a confirmation link (double opt-in)
/tienda/boletin/bajaPOSTpublic, with publishable keyUnsubscribes from the newsletter with the token from the email
/tienda/boletin/confirmarPOSTpublic, with publishable keyConfirms a newsletter subscription with the emailed token (single use, expires)
/tienda/buscarGETpublic, with publishable keyStore search (q), semantic when available; cached 10 minutes, falls back to keyword search when rate-limited
/tienda/carritosPOSTpublic, with publishable keyCreates a cart (currency, region, language) and returns it with 201
/tienda/carritos/{id}GETpublic, with publishable keyA cart with its lines and totals
/tienda/carritos/{id}/completarPOSTpublic, with publishable keyTurns the cart into an order after checking the payment; idempotent (201 new, 200 already done); 409 if payment unconfirmed
/tienda/carritos/{id}/consentimiento-digitalPOSTpublic, with publishable keyRecords the buyer's consent to immediate digital delivery, with the legal text and version they saw
/tienda/carritos/{id}/cuponPOSTpublic, with publishable keyApplies a discount code; returns whether it applied and, if not, why
/tienda/carritos/{id}/cupon/{codigo}DELETEpublic, with publishable keyRemoves a discount code from the cart
/tienda/carritos/{id}/datosPOSTpublic, with publishable keySets the cart's email and shipping and billing addresses
/tienda/carritos/{id}/enviosGET, POSTpublic, with publishable keyGET: shipping options for the cart; POST: choose them, one per group in marketplace carts
/tienda/carritos/{id}/lineasPOSTpublic, with publishable keyAdds a variant with quantity, customisation and bundle choices; 400 with a code when quantity rules are broken
/tienda/carritos/{id}/lineas/{linea}DELETE, POSTpublic, with publishable keyPOST: change a line's quantity; DELETE: remove the line
/tienda/carritos/{id}/nif-ivaPOSTpublic, with publishable keySets or clears the buyer's EU VAT number for business purchases
/tienda/carritos/{id}/pagoPOSTpublic, with publishable keyChooses the payment method among those available for the cart
/tienda/carritos/{id}/pagosGETpublic, with publishable keyPayment methods available for the cart
/tienda/carritos/{id}/puntosDELETE, POSTcustomer sessionPOST: redeem the customer's points on their own cart; DELETE: take the redeemed points off
/tienda/carritos/{id}/saldoPOSTpublic, with publishable keyApplies a gift card by codigo, or the signed-in customer's credit when no code is sent
/tienda/carritos/{id}/saldo/{saldoId}DELETEpublic, with publishable keyRemoves an applied gift card or credit from the cart
/tienda/categoriasGETpublic, with publishable keyThe store's navigation categories, optionally one by handle
/tienda/contactPOSTpublic, with publishable keyContact form: emails the message to the store; rate-limited per IP, 503 if no recipient is configured
/tienda/cuentaGET, POSTcustomer sessionGET: the signed-in customer's profile; POST: update it
/tienda/cuenta/confirmarPOSTcustomer sessionConfirms the customer's email with the token and adopts their earlier guest orders
/tienda/cuenta/entrarPOSTpublic, with publishable keyCustomer sign-in returning a session token; rate-limited per account and IP; links the cart_id cart if sent
/tienda/cuenta/licenciasGETcustomer sessionThe signed-in customer's licences, each with the sites it is active on right now
/tienda/cuenta/licencias/soltarPOSTcustomer sessionDeactivates one of the customer's own sites so the slot goes back to them; capped per licence and per customer
/tienda/cuenta/pedidosGETcustomer sessionThe signed-in customer's orders, paginated
/tienda/cuenta/pedidos/{id}GETcustomer sessionOne of the signed-in customer's orders; 404 if it is not theirs
/tienda/cuenta/registrarPOSTpublic, with publishable keyRegisters a customer account; rate-limited per IP; says how many guest orders await email confirmation
/tienda/cuenta/salirPOSTpublicCloses the customer's current session
/tienda/descargas/{id}GETpublicDownloads a purchased file with its signed link (firma); 403 if the link expired, 410 if it is no longer available
/tienda/idiomasGETpublicThe store's languages, the default one and the one chosen from locale or Accept-Language
/tienda/marketplace/enviosGET, POSTpublic, with publishable keyGET: shipping options per seller package for cart_id; POST: choose one option for each package
/tienda/mi-saldoGETcustomer sessionThe signed-in customer's store credit and its movements
/tienda/mis-puntosGETcustomer sessionThe customer's points, programme rules, next expiry and last 50 movements
/tienda/paginasGETpublic, with publishable keyPublished content pages (handle, title and order), without their content
/tienda/paginas/{handle}GETpublic, with publishable keyA published page with its sanitised content and SEO fields
/tienda/pagos/recargoPOSTpublic, with publishable keyAdds the surcharge of the chosen payment method to the cart (cart_id, provider_id)
/tienda/pedidos/{id}GETpublic, with publishable keyAn order as the storefront shows it. Without the access proof (header x-pcc-pedido) it comes back without the email or the address; PCC_PEDIDO_ABIERTO=1 restores the old full answer
/tienda/pedidos/{id}/accesoPOSTpublic, with publishable keyExchanges the order id plus the buyer's email (POST, never in the URL) for a signed, time-limited proof of access to that order; rate limited per order and per IP
/tienda/pedidos/{id}/codigosGETpublic, with publishable keyThe digital keys of an order with their status, without the key itself; needs the access proof of that order
/tienda/pedidos/{id}/codigos/{codigo}/revelarPOSTpublic, with publishable keyReveals a delivered key and records it as proof of delivery; needs the access proof of that order. 409 if not delivered, revoked or from another order
/tienda/pedidos/{id}/descargasGETpublic, with publishable keyThe downloadable files of an order, with signed links; needs the access proof of that order
/tienda/pedidos/{id}/desistimientoGET, POSTpublic, with publishable keyGET: which lines of the order can be withdrawn and until when; POST: request withdrawal of lines, with reason and email
/tienda/pedidos/{id}/facturaGETpublic, with publishable keyThe invoice of one of the signed-in customer's orders, as a PDF
/tienda/pedidos/{id}/licenciasGETpublic, with publishable keyThe licences issued for an order, with their full keys; needs the access proof of that order
/tienda/personalizacion/ficherosPOSTpublic, with publishable keyUploads the file a buyer attaches to customise a product (multipart, one file)
/tienda/personalizacion/ficheros/{id}GETpublicDownloads a customisation file with its signed link; 403 if the signature is wrong
/tienda/postsGETpublic, with publishable keyPublished blog posts with sanitised HTML, or one by handle
/tienda/producto-extrasGETpublic, with publishable keyAI extras for a product page (product_id): similar products and a summary of its reviews
/tienda/productosGETpublic, with publishable keyCatalogue listing, translated, filterable by category, text, type or ids, with sorting and pagination
/tienda/productos/{handle}GETpublic, with publishable keyA product page by handle; marketplace items also bring screenshots, demo and version history
/tienda/products-by-priceGETpublic, with publishable keyProduct ids sorted by lowest base price, filterable by text and category, paginated
/tienda/provinciasGETpublic, with publishable keyProvinces or states of a country (pais) for address forms
/tienda/regionesGETpublic, with publishable keyRegions with their currency and taxes per country
/tienda/reviewsGET, POSTpublic, with publishable keyGET: approved reviews of a product with the average rating; POST: leave a review, pending moderation
/tienda/soportePOSTpublic, with publishable keyOpens a support thread with an item's author using the licence key; the author is emailed
/tienda/soporte/{id}POSTpublic, with publishable keyBuyer side of an author support thread, identified by the thread's email: read it, reply (texto) or rate it (resuelto)
/tienda/soporte/chatPOSTpublic, with publishable keyAI assistant that answers from the catalogue only; rate-limited, says when a person is needed, logs to support if email is sent
/tienda/stock-mapGETpublic, with publishable keyAvailable stock per variant capped at 10 (9999 when not tracked or backorders allowed); cached for a minute
/tienda/tiendaGETpublic, with publishable keyPublic store details: legal name, tax ID, address, contact, country, how prices are shown and legal notices
/tienda/wishlistDELETE, GET, POSTpublic, with publishable keyGET: the signed-in customer's wishlist; POST: add a product or merge a list; DELETE: remove a product (?product_id=)

Other

RouteMethodsAccessWhat it does
/auth-propia/entrarPOSTpublicPanel sign-in returning a session token; rate-limited per account and per IP
/auth-propia/restablecer/confirmarPOSTpublicSets a new password with the reset token and closes the user's open sessions
/auth-propia/restablecer/pedirPOSTpublicRequests a password reset email; always gives the same answer so accounts cannot be probed; rate-limited
/auth-propia/salirPOSTpublicCloses the current panel session
/auth-propia/yoDELETE, GETseller sessionGET: who the session belongs to (the user's details and their open sessions); DELETE: close every session of that user
/carriles/{carril}/avisosGET, POSTpublicWebhook for the author payout provider (POST for Stripe, GET for Mangopay); verified before updating the payout
/hooks/boletin/{servicio}GET, POSTpublicPOST: unsubscribe, hard bounce and spam complaint notices from the email service; the address carries its own key and, where the service signs, the signature is verified. GET: answers so the service accepts the address
/hooks/sendcloudPOSTpublicSendcloud webhook verified by HMAC signature; for now it only logs parcel status changes
/licencias/activarPOSTpublicActivates a licence key on a site, called by the installed theme or extension; 409 if it cannot be activated
/licencias/comprobarPOSTpublicChecks whether a licence key (and optionally an activation) is valid; 404 if unknown
/licencias/soltarPOSTpublicReleases one activation of a licence key so it can be used on another site
/listoGETpublicReadiness check: 503 while shutting down or when a plugin failed to load
/mcpGET, POSTpublicMCP server (JSON-RPC 2.0) for AI agents: search products, product detail and store info; GET: server summary and tools
/pagos/aviso/{proveedor}POSTpublicPayment gateway webhook, verified by each provider; 401 if not valid, repeated notices are acknowledged (idempotent)
/payment-configGETpublicPayment methods to show at checkout with their texts and surcharges, filtered by plugins (optional cart_id)
/saludGETpublicLiveness check: the process answers
/setupGETpublicInstallation status and the checks the wizard shows; 409 once the store is installed or when it installs itself from its configuration, 503 if that cannot be checked
/setup/databaseGETpublicDatabase connection and migration status; 409 once the store is installed, 503 if that cannot be checked
/setup/database/migratePOSTpublicRuns the migrations and streams the output as server-sent events; 409 if already installed or already running
/setup/demoPOSTpublicImports the active theme's demo content, streaming progress as server-sent events; 409 if already installed or running
/setup/finishPOSTpublicCreates the first admin, names the store and closes the installation; 409 if already installed or an admin exists
/site-statusGETpublicWhether the store is in maintenance mode and which message to show
/static/{fichero}GETpublicServes a static image file with long caching; SVGs get a restrictive content security policy
/telegram/webhookPOSTpublicTelegram bot: answers questions about the store from authorised chats with AI, read-only; always replies 200