Loading WardrobeIt

Merchant credentials

Merchant API keys and storefront plugin keys

Store-scoped keys authenticate the widget and plugin API against one Shopify catalog. Create, copy, and rotate keys in the Merchant Portal — this public page never issues or displays live secrets.

  • Storefrontss_live_… plugin key
  • Serversk_live_… merchant API
  • ScopeOne store per key

Key types

Two keys, two surfaces — same store tenant

Each Shopify store gets its own catalog, meters, and keys. Search, outfits, and try-on never read another merchant’s products.

Public storefront

Plugin key · ss_live_…

Authenticates the deferred widget script and every plugin API call from the shopper browser.

  • Passed as data-api-key on the theme embed or Liquid snippet
  • Sent as X-API-Key on plugin routes (with hashed visitor header)
  • Scoped to one store — rate limits apply per key and visitor
  • Safe for storefront use; still treat as sensitive and rotate if leaked

Used by: wardrobeit-widget.js · headless custom storefronts

Server only

Merchant API key · sk_live_…

Tighter-scoped credentials for approved backend integrations — not for theme Liquid or client-side JavaScript.

  • Keep on your server; never commit to public repos
  • Do not embed in Shopify theme files or browser bundles
  • Rotate from the portal if exposure is suspected
  • Full OpenAPI reference ships with merchant onboarding

Used by: server-side catalog sync helpers, custom integrations

PropertyPlugin keyMerchant API key
Prefixss_live_sk_live_
Where it runsStorefront widget · plugin APIYour backend only
Shown at creationOnce — copy immediatelyOnce — copy immediately
Portal pathConnections & Catalog → plugin keysDeveloper credentials (when enabled)
Auth headerX-API-Key + X-WardrobeIt-VisitorPer onboarding doc

Lifecycle

Create, embed, rotate, revoke

Keys follow a simple lifecycle: generate after store connect, copy once, embed in theme, validate on storefront, rotate if compromised, revoke when decommissioning.

  1. 01
    Connect Shopify

    OAuth from Portal → Connections & Catalog, or custom app token with read_products + read_content. Catalog sync runs in the background.

  2. 02
    Create plugin key

    Portal generates ss_live_… for the connected store. The full value displays once — copy to your password manager before closing the panel.

  3. 03
    Embed in theme

    Theme Editor → App embeds → WardrobeIt stylist. Paste widget key, API base URL (…/api/v1), and script URL. Or use the documented Liquid fallback.

  4. 04
    Validate on storefront

    Send a test message on homepage, collection, and PDP. Confirm product cards render and try-on appears only on eligible SKUs.

  5. 05
    Rotate or revoke

    If a key leaks, rotate immediately from the portal and update the theme embed. Revoke unused keys. Keep development and production stores on separate keys.

Portal & embed

Where keys live and how the theme uses them

After OAuth connect, copy the widget key from Connections & Catalog and paste it into the theme app embed or Liquid snippet — along with your API base URL and script URL.

Theme app embed settings

SettingExampleNotes
Widget API keyss_live_…From portal after connect
API base URLhttps://api.wardrobeit.com/api/v1Must match your WardrobeIt host
Widget script URL…/wardrobeit-widget.jsCDN or API static path
Widget titleStylistPanel header label

Liquid fallback

<script src="https://YOUR_HOST/static/wardrobeit-widget.js"
  data-api-key="ss_live_…"
  data-api-base="https://YOUR_HOST/api/v1"
  data-page-type="product"
  data-product-id="{{ product.metafields.wardrobeit.id }}"
  defer></script>

Security & FAQ

Protect credentials and know the boundaries

Plugin keys are store-scoped and designed for storefront traffic — still rotate if leaked. CORS restricts origins. Visitor identity uses a hashed header, not email, on plugin routes.

  • Do not log full keysMask in application logs and error reports.
  • No PII on plugin routesDo not send shopper email, name, or payment data with plugin API calls.
  • CORS allow listStore origin must be approved on the API host before the widget can call plugin endpoints.
  • Separate environmentsUse different keys for development shops and production stores.
  • Shopify Admin tokensCustom app tokens stay in portal secure fields — never in theme code.
  • Rate limitsTreat HTTP 429 as back off; limits apply per key and visitor.

Frequently asked

Can I retrieve a key after closing the creation panel?

No — full values display once. Rotate to generate a new key if you did not save the original.

Is the plugin key safe in theme Liquid?

Yes for ss_live_… storefront keys — that is the intended embed model. Never put sk_live_… merchant API keys in Liquid or client-side JavaScript.

What headers does the plugin API expect?

X-API-Key: ss_live_… plus X-WardrobeIt-Visitor (hashed visitor id). See the developer API section for endpoint reference.

Who do I contact for onboarding help?

Commercial questions: Contact. Technical onboarding (API host, CORS, metafields): your WardrobeIt counterpart or Book a Demo.

Next steps

Connect Shopify, copy your widget key, embed the stylist, and validate on a development store before go-live.