Two Marketplace API
Download this API's OpenAPI YAML
This API is for creating new merchants as a part of a marketplace setup using Two. The merchants that are onboarded through the markeplace are able to sell products or services with Two as the payment solution.
Note: Only authorised merchants will have access to use this API. Feel free to contact [email protected] if you think this API might be relevant for your marketplace setup.
Specifically:
- Sign up merchants with Two through your own solution
- Get information about the registered Two merchants
- Update information of registered Two merchant
- Use the Two Checkout API with API keys for each inidividual merchant when creating and handling orders
Step 1: Create and onboard merchant with Two
Do a POST /partner/v1/merchant with the required information to sign up a merchant with Two.
Keep note of the merchant's id in the response (hereby referred to as merchant_id) in the response.
You can then add X-Merchant-Id: <merchant_id> to requests that require X-Api-Key header and execute our endpoints on behalf of the merchant. For example:
GET /something
X-Api-Key: <your_api_key>
X-Merchant-Id: <merchant_id>
Step 2: Create order (Checkout API)
Do a POST /v1/order from the Checkout API by using secret_api_key of the specific merchant as authentication.
Other:
- Get all your marketplace merchants
GET /partner/v1/merchant - Get specific marketplace merchant
GET /partner/v1/merchant/<merchant_id> - Update specific marketplace merchant
PATCH /partner/v1/merchant/<merchant_id>
Note: All Checkout API features are available for the merchant onboarded with Two.
Environments
Testing
Note: Read about our sandbox environment specific behaviour.
Production
Authentication
- API Key: X-Api-Key
For instructions on how to obtain API keys, visit this page. You will obtain two different keys, an initial one for testing in our sandbox environment and once ready, for production. Your API keys enables others to act on your behalf if they are able to obtain them, so make sure to keep them safe. Your API key is not to be shared with anyone, including in your version control system, client-side code, in public chatrooms and so on. The API key is applied in the request header. For example:
GET /something
X-Api-Key: secret_test_aabbccddeeff0123456789
API Keys have the following structure: secret_<env>_<key> where:
envis determined by the environment (prodfor production,testfor test environments)keyis a random, URL-safe, 64-bit encoded text string containing 32 random bytes.
Security Scheme Type: | apiKey |
|---|---|
Header parameter name: | X-Api-Key |