API routes
Routes under /gestion require a panel session (and seller routes, a seller's session).
Generated by
scripts/generar-referencia.mjs. Do not edit by hand.
Routes under /gestion require a panel session (and seller routes, a seller's
session). Routes under /tienda require the sales channel's publishable key in
the x-pcc-clave header, and the customer account ones also the customer's
session. The rest have their own policy: gateway and provider notices,
licences, installation, health.
Admin panel (/gestion)
| Route | Methods | Access | What it does |
|---|---|---|---|
/gestion/ai | GET, POST | panel session | GET: AI settings, which provider keys are set and the model catalogue; POST: validate and save the AI settings |
/gestion/ai/contenido | POST | panel session | Drafts product copy with AI (tarea: ficha, alt or traducir) and returns it as a proposal; saves nothing, logs the cost |
/gestion/ai/copiloto | POST | panel session | Answers a question about the store by reading its data; write actions come back as proposals and are never executed |
/gestion/ai/copiloto/aplicar | POST | panel session | Applies a copilot proposal a person approved: change a variant's EUR price or approve/reject a review |
/gestion/ai/indice | GET, POST | panel session | GET: state of the semantic search index; POST: re-index every published product and return the cost (400 without pgvector) |
/gestion/ai/mcp | GET, POST | panel session | GET: whether the AI agents endpoint is on and what is missing to turn it on; POST: turn it on or off (needs an AI provider key) |
/gestion/ai/probar | POST | panel session | Makes a real test call to the configured chat provider with the saved settings |
/gestion/ai/uso | GET | panel session | AI spend over the last dias days (30 by default): totals, breakdown per task and the last 20 calls |
/gestion/autores/solicitudes | GET | panel session | Lists applications to become an author, optionally filtered by estado |
/gestion/autores/solicitudes/{id} | POST | panel session | Decides on an author application (aceptada, rechazada or revisando); accepting creates the seller and emails a password link |
/gestion/avisos | GET | panel session | What needs looking at today, as a list of warnings; an empty list is good news |
/gestion/boletin | GET | panel session | Lists newsletter subscribers who have confirmed their address |
/gestion/boletin-conector | GET | panel session | GET: the email services the newsletter can sync with, which one is connected, how the last sync went and how many addresses the service does not know yet |
/gestion/boletin-conector/{nombre} | DELETE, POST | panel session | POST: saves that service's keys and connects it, or, with accion, tests the connection or forces a sweep now; DELETE: deletes its keys (the store's own list is untouched). Administrator only: these are a third party's keys |
/gestion/boletin/{id}/baja | POST | panel session | Unsubscribes that person from the panel, without needing their link |
/gestion/boletin/csv | GET | panel session | The same list as a CSV file, consent proof included |
/gestion/boletin/suscritos | GET | panel session | The newsletter list with each person's consent proof: the exact text shown, its version, the IP, the browser and the confirmation date |
/gestion/capabilities | GET | panel session | Extra panel sections this installation has (flags and menu entries), such as the marketplace when it is enabled |
/gestion/cart-recovery | GET | panel session | Abandoned carts from the last 30 days (with email, idle 30+ minutes) and recovery statistics |
/gestion/cart-recovery/{id}/resend | POST | panel session | Emails a cart's recovery reminder by hand and marks it as sent; 400 if it has no email or is already an order |
/gestion/categorias | GET, PATCH, POST | panel session | GET: the flat category list with its parent; POST: creates one; PATCH: reorders them, the position in the list being the order |
/gestion/categorias/{id} | DELETE, POST | panel session | POST: changes a category's name, handle, description, order, parent or visibility; DELETE: takes it down, its children move up and its products are freed |
/gestion/clave-tienda | GET | panel session | Returns the sales channel's publishable key that storefronts send |
/gestion/clientes | GET | panel session | Lists customers, with text search (q) and pagination |
/gestion/clientes/{id} | GET, PATCH | panel session | GET: one customer; PATCH: update their details with If-Match (412 on conflict); the email cannot be changed here (422) |
/gestion/cobros/pagos/{id} | POST | panel session | Settles a scheduled author payout by hand: confirm it with a bank reference, or mark it failed with accion: fallido |
/gestion/cobros/pagos/{id}/enviar | POST | panel session | Sends a scheduled author payout through the configured payout rail; the payout id is the reference, so retries are safe |
/gestion/cobros/por-pagar | GET | panel session | Authors due a payout in this run, for one currency (moneda, eur by default) |
/gestion/cobros/vendedores/{id}/bloquear | POST | panel session | Blocks an author's payouts with a reason (they are told by email), or unblocks them with accion: desbloquear |
/gestion/cobros/vendedores/{id}/pagar | POST | panel session | Schedules a payout to an author for a period (all that is available unless importe); 400 if they cannot be paid yet |
/gestion/cobros/vendedores/{id}/pagos | GET | panel session | The scheduled payouts of one author, seen from the store; the destination is the stored hint, never the account |
/gestion/codigos/lotes/{lote}/revocar | POST | panel session | Revokes a batch of digital keys, with a mandatory reason |
/gestion/collections | GET, POST | panel session | GET: the store's collections with how many products each one holds; POST: creates one |
/gestion/collections/{id} | DELETE, POST | panel session | POST: renames a collection or changes its handle; DELETE: takes it down and frees its products |
/gestion/create-staff | POST | panel session | Creates a staff account for the panel; 409 if the email is taken, 400 if the password is too weak |
/gestion/customer-stats | GET | panel session | Order count, spend in the store's main currency and last order date for the customers in ids (200 at most) |
/gestion/desistimientos | GET | panel session | Lists withdrawal requests (right of withdrawal) sent by buyers |
/gestion/desistimientos/{id}/atender | POST | panel session | Marks a withdrawal request as handled, with an optional note |
/gestion/envios | GET | panel session | The shipping setup: zones, rates, shipping classes and the carriers available |
/gestion/envios/clases | POST | panel session | Creates a shipping class; 422 if it is not valid |
/gestion/envios/clases/{id} | DELETE, PATCH | panel session | PATCH: update a shipping class (422 if not valid); DELETE: remove it (404 if it does not exist) |
/gestion/envios/clases/{id}/productos | GET, POST | panel session | GET: products in this shipping class; POST: assign the class to the given productos |
/gestion/envios/tarifas | POST | panel session | Creates a shipping rate in a zone, with its conditions; 422 if it is not valid |
/gestion/envios/tarifas/{id} | DELETE, PATCH | panel session | PATCH: update a shipping rate (422 if not valid); DELETE: remove it (404 if it does not exist) |
/gestion/envios/zonas | POST | panel session | Creates a shipping zone; 422 if it is not valid |
/gestion/envios/zonas/{id} | DELETE, PATCH | panel session | PATCH: update a shipping zone (422 if not valid); DELETE: remove it (404 if it does not exist) |
/gestion/facturas-manuales | GET, POST | panel session | GET: list manual invoices; POST: create a draft manual invoice (422 if it cannot be created) |
/gestion/facturas-manuales/{id} | DELETE, GET, PATCH | panel session | GET: one manual invoice; PATCH: edit the draft or mark it paid (pagada); DELETE: delete the draft; 409 when no longer editable |
/gestion/facturas-manuales/{id}/emitir | POST | panel session | Issues a manual invoice: gives it its number and freezes it with the store's tax ID; 409 if it cannot be issued |
/gestion/facturas-manuales/{id}/rectificar | POST | panel session | Creates a corrective invoice for an issued manual invoice, with a reason; 409 if not allowed |
/gestion/idiomas | DELETE, GET, POST | panel session | GET: store languages and translation progress; POST: add a language (codigo, e.g. fr or pt-BR); DELETE: remove one (?codigo=, not the base) |
/gestion/idiomas/traducir | POST | panel session | Translates with AI whatever is missing for one entity type (tipo) into a language; rehacer redoes existing translations |
/gestion/impuestos | GET | panel session | Tax regions and rates, which currencies have tax-inclusive prices and how the storefront shows prices |
/gestion/impuestos/csv | GET, POST | panel session | GET: export every tax rate as CSV; POST: import rates from CSV text (reemplazar replaces them); 422 with per-row errors |
/gestion/impuestos/oss | GET | panel session | EU OSS VAT report between desde and hasta (YYYY-MM-DD), as JSON or as CSV with formato=csv |
/gestion/impuestos/precios-con-impuesto | POST | panel session | Sets whether the prices in a currency already include tax (moneda, dentro) |
/gestion/impuestos/precios-escaparate | POST | panel session | Sets whether the storefront shows prices with or without tax (muestra) |
/gestion/impuestos/referencias | GET | panel session | Product types and shipping options to choose from when writing tax rules |
/gestion/impuestos/regiones/{id} | DELETE | panel session | Deletes a tax region |
/gestion/impuestos/tasas | POST | panel session | Creates a tax rate; 422 if it is not valid |
/gestion/impuestos/tasas/{id} | DELETE, PATCH | panel session | PATCH: update a tax rate (422 if not valid); DELETE: remove it |
/gestion/impuestos/ue | GET, POST | panel session | GET: the store's EU VAT settings; POST: save them (422 if not valid) |
/gestion/impuestos/ue/tipos | POST | panel session | Loads the EU member states' VAT rates; only the missing ones unless reemplazar: true |
/gestion/inventario | POST | panel session | Sets a variant's stock at a location (variant_id, location_id, stocked_quantity), recording who and why |
/gestion/inventario/{id}/niveles | GET, POST | panel session | GET: an inventory item's stock at each location; POST: set its level at a location, creating it if missing |
/gestion/legal | GET, POST | panel session | GET: legal settings, countries with a legal profile and what applies; POST: save country, custom-item and digital-consent rules |
/gestion/marketplace/mi-cuenta | GET | seller session | A seller's own view: profile, balances, ledger, sub-orders and products; 403 unless the seller is active |
/gestion/marketplace/vendedores | GET, POST | panel session | GET: sellers with their balances; POST: register a seller and email them a link to set a password (409 if duplicate) |
/gestion/marketplace/vendedores/{id} | GET, POST | panel session | GET: a seller's profile, balances, ledger and sub-orders; POST: change their details, status or commission (the slug cannot change) |
/gestion/marketplace/vendedores/{id}/envios | GET, POST | panel session | GET: the seller's own shipping options and the store's ones they inherit; POST: set their options (option_ids) |
/gestion/marketplace/vendedores/{id}/liquidar | POST | panel session | Records a settlement paid to a seller (amount in cents, bank reference required); cannot exceed what is owed |
/gestion/mercado/cobros | GET, POST | seller session | GET: the author's payout profile, balance on hold and available, and payout history; POST: save their payout profile |
/gestion/mercado/cobros/alta | POST | seller session | Registers the author with the payout provider and returns the identity verification (KYC) link |
/gestion/mercado/cobros/cancelar | POST | seller session | POST: the author calls off their own withdrawal while it has not left yet (pago). Only theirs, only while previsto |
/gestion/mercado/cobros/informe | GET | seller session | The author's statement between desde and hasta: every ledger line on the day the money moved, so a refund lands in the month it was refunded. CSV with formato=csv (para=excel for Excel) |
/gestion/mercado/cobros/refrescar | POST | seller session | Asks the payout provider again how the author's verification is going |
/gestion/mercado/cobros/retirar | POST | seller session | The author withdraws their available balance (or importe); same checks as a scheduled payout, a double click cannot pay twice |
/gestion/mercado/cola | GET | panel session | Review queue: authors' items waiting for the store to review them |
/gestion/mercado/licencias | GET | seller session | Licences sold for the author's items, searchable with busca |
/gestion/mercado/licencias/soltar | POST | seller session | POST: the author frees one activation of a licence for one of THEIR items (clave, instancia), so the buyer can move domain. Rate limited per licence and per author |
/gestion/mercado/operador/licencias | GET | panel session | Every licence in the marketplace, for whoever runs it; filter with autor and search with busca. The buyer's address comes masked: searching by the whole address still finds it |
/gestion/mercado/operador/piezas/{id} | GET | panel session | An item in full for whoever runs the marketplace, without being its author: details, versions, review history and screenshots. Of the author only what is already public (name and slug), never their address or payout details |
/gestion/mercado/perfil | GET, POST | seller session | GET: the author's public profile and support reputation; POST: save the profile |
/gestion/mercado/piezas | GET, POST | seller session | GET: the author's own items (themes and extensions); POST: create a new item |
/gestion/mercado/piezas/{id} | GET, POST | seller session | GET: one of the author's items; POST: save changes, or accion revisar to submit it for review or retirar to withdraw it |
/gestion/mercado/piezas/{id}/capturas | POST | seller session | Uploads screenshots for an item (multipart); files are checked by content and SVGs with scripts are rejected |
/gestion/mercado/piezas/{id}/capturas/{captura} | DELETE | seller session | Removes a screenshot from an item |
/gestion/mercado/piezas/{id}/capturas/orden | POST | seller session | Reorders an item's screenshots (ids in the new order) |
/gestion/mercado/piezas/{id}/revision | POST | panel session | The store's review decision on an item: publicada, cambios or rechazada, with notes |
/gestion/mercado/piezas/{id}/version | POST | seller session | Uploads a new version package of an item (multipart: the file, version and notas) |
/gestion/mercado/resumen | GET | seller session | The author's dashboard summary: figures for their items, their balance split into available and on hold, and how many support threads are waiting for their reply |
/gestion/mercado/soporte | GET | seller session | The author's support inbox, filterable by estado |
/gestion/mercado/soporte/{id} | GET, POST | seller session | GET: a support thread of the author; POST: reply (texto) or close it (cerrar) |
/gestion/mercado/ventas | GET | seller session | The author's sales, one by one and by item, between desde and hasta. Each sale carries what was refunded from it, whenever that happened, and the buyer's billing country (nothing else about the buyer). CSV with formato=csv (para=excel for Excel) |
/gestion/migracion/analizar | POST | panel session | Dry run of a CSV import (products or customers, source detected): reports what would happen and changes nothing |
/gestion/migracion/importar | POST | panel session | Imports products or customers from a CSV; 422 if the analysis finds errors, unless forzar |
/gestion/migracion/redirecciones | POST | panel session | Builds old-to-new URL redirects from a CSV export, as nginx, apache, json or csv (?formato=) |
/gestion/mudanzas | GET, POST | panel session | GET: the latest 20 store migrations; POST: start one from Shopify or WooCommerce by API, checking the credentials first (422) |
/gestion/mudanzas/{id} | GET, POST | panel session | GET: a migration's progress by stage and its problems; POST: accion pausar, seguir or deshacer |
/gestion/order-origin | GET | panel session | Where each of the given orders came from (ids): the storefront's sales channel, the dashboard or the migration that brought it over |
/gestion/orders/{id}/notify-confirmed | POST | panel session | Emails the customer their order confirmation, with the invoice PDF attached when there is one |
/gestion/paginas | GET, POST | panel session | GET: every content page, drafts included; POST: create one (422 without titulo) |
/gestion/paginas/{id} | DELETE, POST | panel session | POST: update a page; DELETE: soft-delete it (it can be recovered) |
/gestion/paginas/{id}/traducciones | DELETE, GET, PUT | panel session | GET: what is written in each language; PUT: save one language (idioma plus titulo, extracto, contenido, seo; a blank field falls back to the base language); DELETE ?idioma=: back to the base language |
/gestion/pagos-ajustes | GET, POST | panel session | GET: payment providers, regions with their providers and method texts; POST: set a region's providers and/or method texts and surcharges |
/gestion/pasarelas | GET | panel session | Payment gateways configured from the panel, their state and webhook URLs; 404 if gateways are managed outside the panel |
/gestion/pasarelas/{nombre} | DELETE, POST | panel session | POST: save a gateway's credentials, turn it on or off or switch test mode; DELETE: forget its configuration; both return the list |
/gestion/pedidos | GET, POST | panel session | GET: lists orders, with text search (q) and pagination; POST: creates a draft order by hand with a customer, its lines (prices in cents) and its totals |
/gestion/pedidos/{id} | GET | panel session | One order with everything the panel shows about it |
/gestion/pedidos/{id}/cancelar | POST | panel session | Cancels an order with a reason; 409 if it cannot be cancelled, e.g. already charged unless permitir_con_cobro |
/gestion/pedidos/{id}/cobrar | POST | panel session | Captures the order's authorised payments and marks them as charged |
/gestion/pedidos/{id}/completar | POST | panel session | Marks an order as completed; 409 if it is not ready yet, which forzar overrides |
/gestion/pedidos/{id}/envios/{envio}/entregado | POST | panel session | Marks one of the order's shipments as delivered; 409 if that is not possible |
/gestion/pedidos/{id}/envios/{envio}/enviado | POST | panel session | Marks one of the order's shipments as shipped and emails the customer that it is on its way; the tracking numbers go in seguimiento; doing it twice sends nothing |
/gestion/pedidos/{id}/preparar | POST | panel session | Creates a fulfilment, taking all or the given items out of stock at a location; 200 if it was already done, 201 if new |
/gestion/pedidos/{id}/rectificar | POST | panel session | Issues a corrective invoice for an order, with a reason; 409 if not allowed |
/gestion/pedidos/{id}/reembolsos | GET, POST | panel session | GET: what can still be refunded and what already has been; POST: refund (amount, payment, restock); send Idempotency-Key, 409 if invalid |
/gestion/plugins | GET, POST | panel session | GET: installed plugins with their state, permissions, routes and last error; POST: reload every plugin |
/gestion/plugins/{id} | GET | panel session | The last 200 log lines of a plugin |
/gestion/plugins/{id}/ajustes | GET, PUT | panel session | GET: a plugin's settings fields and values, secrets hidden; PUT: validate and save them (422 if invalid; needs a reload) |
/gestion/posts | GET, POST | panel session | GET: blog posts, drafts included; POST: create a post (the handle comes from the title if missing) |
/gestion/posts/{id} | DELETE, GET, POST | panel session | GET: one blog post; POST: update it; DELETE: delete it |
/gestion/productos | GET, POST | panel session | GET: products with search, status filter and pagination; POST: create a product (Idempotency-Key supported, 200 on repeat) |
/gestion/productos/{id} | DELETE, GET, POST | panel session | GET: the full product; POST: update it with If-Match (412 on conflict); DELETE: delete it |
/gestion/productos/{id}/editor-variantes | GET | panel session | Data for the variant editor: the product's options, values and variants |
/gestion/productos/{id}/historial | GET | panel session | The product's change history: who changed what and when |
/gestion/productos/{id}/historial-stock | GET | panel session | The stock movements of the product's variants: who changed them, when, in which warehouse and from what to what |
/gestion/productos/{id}/opciones | POST | panel session | Saves the product's options and, unless generar: false, creates the variants that are missing |
/gestion/productos/{id}/opciones/vista-previa | POST | panel session | Previews which variants the given options would create or remove, without saving anything |
/gestion/productos/{id}/personalizacion | GET, POST | panel session | GET: the customisation fields buyers fill in; POST: save them (400 naming the faulty field) |
/gestion/productos/{id}/precios-por-cantidad | DELETE, GET, POST | panel session | GET: the product's quantity pricing rule; POST: save it; DELETE: remove it |
/gestion/productos/{id}/variantes | POST | panel session | Creates one variant from its option valores |
/gestion/productos/{id}/variantes-lote | POST | panel session | Applies the same cambios to several variants (ids) |
/gestion/productos/{id}/variantes-orden | POST | panel session | Sets the order in which the variants are shown (ids) |
/gestion/productos/{id}/variantes/{variante} | POST | panel session | Updates a variant and its price with If-Match (412 on conflict) |
/gestion/productos/{id}/variantes/{variante}/codigos | GET, POST | panel session | GET: the variant's key batches with free and delivered counts, plus its settings; POST: import keys from text as a new batch |
/gestion/productos/{id}/variantes/{variante}/codigos/ajustes | POST | panel session | Saves the variant's digital key settings and recalculates its stock from the free keys |
/gestion/productos/{id}/variantes/{variante}/detalle | POST | panel session | Updates a variant's details from the variant editor |
/gestion/productos/{id}/variantes/{variante}/digital | GET, POST | panel session | GET: the variant's downloadable files and settings; POST: upload one file (multipart) |
/gestion/productos/{id}/variantes/{variante}/digital/{fichero} | DELETE | panel session | Deletes one of the variant's downloadable files |
/gestion/productos/{id}/variantes/{variante}/digital/ajustes | POST | panel session | Saves the variant's download settings and marks it as digital |
/gestion/productos/{id}/variantes/{variante}/pack | DELETE, GET, POST | panel session | GET: what the bundle variant is made of; POST: save its contents; DELETE: stop it being a bundle |
/gestion/products/visibility | POST | panel session | Bulk visibility (action): show-all publishes all, hide-all drafts all, limit publishes only the first count products |
/gestion/promociones | GET, POST | panel session | GET: the store's promotions and coupons with their rules; POST: creates one |
/gestion/promociones/{id} | DELETE, GET, POST | panel session | GET: the full promotion with its conditions, targets and buy rules; POST: rewrites it whole; DELETE: takes it down without touching the orders that already used it |
/gestion/proveedores-pago | GET | panel session | Lists the payment providers |
/gestion/puntos | GET | panel session | Loyalty programme overview: settings, liability, breakage, movements over dias days and customers by balance |
/gestion/puntos/ajustes | GET, POST | panel session | GET: the points programme settings and their defaults; POST: change them (only known keys; 400 if nothing to change) |
/gestion/puntos/clientes/{id} | GET, POST | panel session | GET: a customer's points ledger with their live batches; POST: manual adjustment with a mandatory note |
/gestion/quien-soy | GET | panel session | The signed-in panel user; 403 if the session is not a panel one |
/gestion/regiones | GET | panel session | Lists the regions |
/gestion/regiones/{id} | PATCH | panel session | Updates a region with If-Match (412 on conflict); 409 if the currency changes while orders use it |
/gestion/reviews | GET | panel session | Reviews to moderate, filterable by status (200 at most) |
/gestion/reviews/{id} | DELETE, POST | panel session | POST: set a review's status (pending, approved or rejected); DELETE: delete it |
/gestion/saldo | GET | panel session | Store credit owed and the list of balances (gift cards and customer credit), filterable by tipo, paginated |
/gestion/saldo/{id} | DELETE, GET | panel session | GET: a balance with its movements; DELETE: deactivate it |
/gestion/saldo/clientes | POST | panel session | Adds or removes store credit for a customer (amount in units, note required); 409 if it would go negative |
/gestion/saldo/tarjetas | POST | panel session | Issues a gift card by hand; the code is returned only once and emailed to the recipient if one is given |
/gestion/scan | GET | panel session | Finds a variant by exact barcode, or searches by SKU, barcode or title (q), with its stock at location_id (the first warehouse if none is given) and the total across warehouses in stock_all_locations; 404 if that warehouse does not exist |
/gestion/scan/adjust | POST | panel session | Adds, subtracts or sets a variant's stock at location_id (mode: add, sub or set); without it, the first warehouse. 404 if that warehouse does not exist, 409 if there is none and 400 if the variant does not track inventory there |
/gestion/scan/bind | POST | panel session | Assigns a barcode to a variant; 409 if another variant already has it |
/gestion/scan/count-apply | POST | panel session | Applies a full stock count: sets each listed variant to its counted quantity and reports the ones skipped |
/gestion/send-invoice | POST | panel session | Emails an invoice PDF through the normal mail queue. Say which invoice it is (pedido or factura); the recipient must be its customer or an address in PCC_FACTURA_DESTINOS, and the send is rate limited and audited |
/gestion/soporte | GET | panel session | The store's support inbox (100 at most), longest-waiting first, filterable by estado |
/gestion/soporte/{id} | DELETE, GET, POST | panel session | GET: the whole conversation; POST: set its status (abierta, esperando or resuelta); DELETE: delete it with its messages |
/gestion/soporte/{id}/borrador | POST | panel session | Drafts a reply with AI from the conversation and the customer's orders; saves it as a draft and does not send it |
/gestion/soporte/{id}/responder | POST | panel session | Emails the reply to the customer, discards any draft and marks the conversation as waiting |
/gestion/soporte/borrar | GET, POST | panel session | GET: the retention period in months; POST: delete now, either what is past the period or everything from one email |
/gestion/tema-activo | GET, POST | panel session | GET: the active theme, installed themes and which have settings; POST: switch to another theme (tema) |
/gestion/temas-ajustes | GET, POST | panel session | GET: a theme's design settings (?tema=); POST: save them, merged or replaced with reemplazar |
/gestion/temas-demo | GET, POST | panel session | GET: what a theme's demo content includes, without importing it; POST: import it (409 unless the store is freshly installed) |
/gestion/tienda | GET, PATCH | panel session | GET: the store and its settings, with ETag; PATCH: merge settings into metadata (and name) with If-Match (412) |
/gestion/tokens | GET, POST | panel session | GET: the store's service tokens and the catalogue of areas they can be given; POST: mints one and returns it the only time it is ever shown |
/gestion/tokens/{id} | DELETE | panel session | Revokes a service token; it stops working on its next request and the row is kept so it is still known what it could reach |
/gestion/ubicaciones | GET | panel session | Lists the stock locations (warehouses) |
/gestion/uploads | POST | panel session | Uploads images (multipart, 16 MB) and returns their URLs; files are checked by content and rejected ones are listed |
/gestion/usuarios | GET | panel session | Lists the store's staff, with search and pagination |
/gestion/usuarios/{id} | DELETE, GET, PATCH | panel session | GET: one staff user; PATCH: update with If-Match (412); DELETE: remove them and close their sessions (409 if last admin) |
/gestion/wishlist | GET | panel session | The most wished-for products across customers' wishlists, with totals |
Store (/tienda)
| Route | Methods | Access | What it does |
|---|---|---|---|
/tienda/autores/{slug} | GET | public, with publishable key | An author's public profile with their items for sale in this store, at catalogue prices, and their support reputation |
/tienda/autores/solicitudes | POST | public, with publishable key | Sends an application to become an author in the store's marketplace |
/tienda/boletin | POST | public, with publishable key | Newsletter sign-up recording the consent given; emails a confirmation link (double opt-in) |
/tienda/boletin/baja | POST | public, with publishable key | Unsubscribes from the newsletter with the token from the email |
/tienda/boletin/confirmar | POST | public, with publishable key | Confirms a newsletter subscription with the emailed token (single use, expires) |
/tienda/buscar | GET | public, with publishable key | Store search (q), semantic when available; cached 10 minutes, falls back to keyword search when rate-limited |
/tienda/carritos | POST | public, with publishable key | Creates a cart (currency, region, language) and returns it with 201 |
/tienda/carritos/{id} | GET | public, with publishable key | A cart with its lines and totals |
/tienda/carritos/{id}/completar | POST | public, with publishable key | Turns the cart into an order after checking the payment; idempotent (201 new, 200 already done); 409 if payment unconfirmed |
/tienda/carritos/{id}/consentimiento-digital | POST | public, with publishable key | Records the buyer's consent to immediate digital delivery, with the legal text and version they saw |
/tienda/carritos/{id}/cupon | POST | public, with publishable key | Applies a discount code; returns whether it applied and, if not, why |
/tienda/carritos/{id}/cupon/{codigo} | DELETE | public, with publishable key | Removes a discount code from the cart |
/tienda/carritos/{id}/datos | POST | public, with publishable key | Sets the cart's email and shipping and billing addresses |
/tienda/carritos/{id}/envios | GET, POST | public, with publishable key | GET: shipping options for the cart; POST: choose them, one per group in marketplace carts |
/tienda/carritos/{id}/lineas | POST | public, with publishable key | Adds a variant with quantity, customisation and bundle choices; 400 with a code when quantity rules are broken |
/tienda/carritos/{id}/lineas/{linea} | DELETE, POST | public, with publishable key | POST: change a line's quantity; DELETE: remove the line |
/tienda/carritos/{id}/nif-iva | POST | public, with publishable key | Sets or clears the buyer's EU VAT number for business purchases |
/tienda/carritos/{id}/pago | POST | public, with publishable key | Chooses the payment method among those available for the cart |
/tienda/carritos/{id}/pagos | GET | public, with publishable key | Payment methods available for the cart |
/tienda/carritos/{id}/puntos | DELETE, POST | customer session | POST: redeem the customer's points on their own cart; DELETE: take the redeemed points off |
/tienda/carritos/{id}/saldo | POST | public, with publishable key | Applies a gift card by codigo, or the signed-in customer's credit when no code is sent |
/tienda/carritos/{id}/saldo/{saldoId} | DELETE | public, with publishable key | Removes an applied gift card or credit from the cart |
/tienda/categorias | GET | public, with publishable key | The store's navigation categories, optionally one by handle |
/tienda/contact | POST | public, with publishable key | Contact form: emails the message to the store; rate-limited per IP, 503 if no recipient is configured |
/tienda/cuenta | GET, POST | customer session | GET: the signed-in customer's profile; POST: update it |
/tienda/cuenta/confirmar | POST | customer session | Confirms the customer's email with the token and adopts their earlier guest orders |
/tienda/cuenta/entrar | POST | public, with publishable key | Customer sign-in returning a session token; rate-limited per account and IP; links the cart_id cart if sent |
/tienda/cuenta/licencias | GET | customer session | The signed-in customer's licences, each with the sites it is active on right now |
/tienda/cuenta/licencias/soltar | POST | customer session | Deactivates one of the customer's own sites so the slot goes back to them; capped per licence and per customer |
/tienda/cuenta/pedidos | GET | customer session | The signed-in customer's orders, paginated |
/tienda/cuenta/pedidos/{id} | GET | customer session | One of the signed-in customer's orders; 404 if it is not theirs |
/tienda/cuenta/registrar | POST | public, with publishable key | Registers a customer account; rate-limited per IP; says how many guest orders await email confirmation |
/tienda/cuenta/salir | POST | public | Closes the customer's current session |
/tienda/descargas/{id} | GET | public | Downloads a purchased file with its signed link (firma); 403 if the link expired, 410 if it is no longer available |
/tienda/idiomas | GET | public | The store's languages, the default one and the one chosen from locale or Accept-Language |
/tienda/marketplace/envios | GET, POST | public, with publishable key | GET: shipping options per seller package for cart_id; POST: choose one option for each package |
/tienda/mi-saldo | GET | customer session | The signed-in customer's store credit and its movements |
/tienda/mis-puntos | GET | customer session | The customer's points, programme rules, next expiry and last 50 movements |
/tienda/paginas | GET | public, with publishable key | Published content pages (handle, title and order), without their content |
/tienda/paginas/{handle} | GET | public, with publishable key | A published page with its sanitised content and SEO fields |
/tienda/pagos/recargo | POST | public, with publishable key | Adds the surcharge of the chosen payment method to the cart (cart_id, provider_id) |
/tienda/pedidos/{id} | GET | public, with publishable key | An order as the storefront shows it. Without the access proof (header x-pcc-pedido) it comes back without the email or the address; PCC_PEDIDO_ABIERTO=1 restores the old full answer |
/tienda/pedidos/{id}/acceso | POST | public, with publishable key | Exchanges the order id plus the buyer's email (POST, never in the URL) for a signed, time-limited proof of access to that order; rate limited per order and per IP |
/tienda/pedidos/{id}/codigos | GET | public, with publishable key | The digital keys of an order with their status, without the key itself; needs the access proof of that order |
/tienda/pedidos/{id}/codigos/{codigo}/revelar | POST | public, with publishable key | Reveals a delivered key and records it as proof of delivery; needs the access proof of that order. 409 if not delivered, revoked or from another order |
/tienda/pedidos/{id}/descargas | GET | public, with publishable key | The downloadable files of an order, with signed links; needs the access proof of that order |
/tienda/pedidos/{id}/desistimiento | GET, POST | public, with publishable key | GET: which lines of the order can be withdrawn and until when; POST: request withdrawal of lines, with reason and email |
/tienda/pedidos/{id}/factura | GET | public, with publishable key | The invoice of one of the signed-in customer's orders, as a PDF |
/tienda/pedidos/{id}/licencias | GET | public, with publishable key | The licences issued for an order, with their full keys; needs the access proof of that order |
/tienda/personalizacion/ficheros | POST | public, with publishable key | Uploads the file a buyer attaches to customise a product (multipart, one file) |
/tienda/personalizacion/ficheros/{id} | GET | public | Downloads a customisation file with its signed link; 403 if the signature is wrong |
/tienda/posts | GET | public, with publishable key | Published blog posts with sanitised HTML, or one by handle |
/tienda/producto-extras | GET | public, with publishable key | AI extras for a product page (product_id): similar products and a summary of its reviews |
/tienda/productos | GET | public, with publishable key | Catalogue listing, translated, filterable by category, text, type or ids, with sorting and pagination |
/tienda/productos/{handle} | GET | public, with publishable key | A product page by handle; marketplace items also bring screenshots, demo and version history |
/tienda/products-by-price | GET | public, with publishable key | Product ids sorted by lowest base price, filterable by text and category, paginated |
/tienda/provincias | GET | public, with publishable key | Provinces or states of a country (pais) for address forms |
/tienda/regiones | GET | public, with publishable key | Regions with their currency and taxes per country |
/tienda/reviews | GET, POST | public, with publishable key | GET: approved reviews of a product with the average rating; POST: leave a review, pending moderation |
/tienda/soporte | POST | public, with publishable key | Opens a support thread with an item's author using the licence key; the author is emailed |
/tienda/soporte/{id} | POST | public, with publishable key | Buyer side of an author support thread, identified by the thread's email: read it, reply (texto) or rate it (resuelto) |
/tienda/soporte/chat | POST | public, with publishable key | AI assistant that answers from the catalogue only; rate-limited, says when a person is needed, logs to support if email is sent |
/tienda/stock-map | GET | public, with publishable key | Available stock per variant capped at 10 (9999 when not tracked or backorders allowed); cached for a minute |
/tienda/tienda | GET | public, with publishable key | Public store details: legal name, tax ID, address, contact, country, how prices are shown and legal notices |
/tienda/wishlist | DELETE, GET, POST | public, with publishable key | GET: the signed-in customer's wishlist; POST: add a product or merge a list; DELETE: remove a product (?product_id=) |
Other
| Route | Methods | Access | What it does |
|---|---|---|---|
/auth-propia/entrar | POST | public | Panel sign-in returning a session token; rate-limited per account and per IP |
/auth-propia/restablecer/confirmar | POST | public | Sets a new password with the reset token and closes the user's open sessions |
/auth-propia/restablecer/pedir | POST | public | Requests a password reset email; always gives the same answer so accounts cannot be probed; rate-limited |
/auth-propia/salir | POST | public | Closes the current panel session |
/auth-propia/yo | DELETE, GET | seller session | GET: who the session belongs to (the user's details and their open sessions); DELETE: close every session of that user |
/carriles/{carril}/avisos | GET, POST | public | Webhook for the author payout provider (POST for Stripe, GET for Mangopay); verified before updating the payout |
/hooks/boletin/{servicio} | GET, POST | public | POST: unsubscribe, hard bounce and spam complaint notices from the email service; the address carries its own key and, where the service signs, the signature is verified. GET: answers so the service accepts the address |
/hooks/sendcloud | POST | public | Sendcloud webhook verified by HMAC signature; for now it only logs parcel status changes |
/licencias/activar | POST | public | Activates a licence key on a site, called by the installed theme or extension; 409 if it cannot be activated |
/licencias/comprobar | POST | public | Checks whether a licence key (and optionally an activation) is valid; 404 if unknown |
/licencias/soltar | POST | public | Releases one activation of a licence key so it can be used on another site |
/listo | GET | public | Readiness check: 503 while shutting down or when a plugin failed to load |
/mcp | GET, POST | public | MCP server (JSON-RPC 2.0) for AI agents: search products, product detail and store info; GET: server summary and tools |
/pagos/aviso/{proveedor} | POST | public | Payment gateway webhook, verified by each provider; 401 if not valid, repeated notices are acknowledged (idempotent) |
/payment-config | GET | public | Payment methods to show at checkout with their texts and surcharges, filtered by plugins (optional cart_id) |
/salud | GET | public | Liveness check: the process answers |
/setup | GET | public | Installation status and the checks the wizard shows; 409 once the store is installed or when it installs itself from its configuration, 503 if that cannot be checked |
/setup/database | GET | public | Database connection and migration status; 409 once the store is installed, 503 if that cannot be checked |
/setup/database/migrate | POST | public | Runs the migrations and streams the output as server-sent events; 409 if already installed or already running |
/setup/demo | POST | public | Imports the active theme's demo content, streaming progress as server-sent events; 409 if already installed or running |
/setup/finish | POST | public | Creates the first admin, names the store and closes the installation; 409 if already installed or an admin exists |
/site-status | GET | public | Whether the store is in maintenance mode and which message to show |
/static/{fichero} | GET | public | Serves a static image file with long caching; SVGs get a restrictive content security policy |
/telegram/webhook | POST | public | Telegram bot: answers questions about the store from authorised chats with AI, read-only; always replies 200 |