Skip to content

Authentication ​

External systems authenticate with a merchant API key, not a Chuchu user login.

http
Authorization: Bearer chu_live_...

Do not send X-Merchant-Id. The key is bound to one merchant.

Creating a key ​

An owner or admin with integration-management access creates keys in Settings → Developer / API.

Example create body:

json
{
  "name": "ERP production",
  "scopes": ["orders:read", "orders:write", "orders:cancel", "products:read", "products:write"],
  "expiresAt": null
}

The full secret is returned once. Later list responses include only a prefix such as chu_live_abcd1234.

Revoking a key keeps history. It is not deleted.

Scopes ​

ScopeAccess
orders:readList and get orders
orders:writeCreate orders
orders:cancelCancel orders
products:readList catalog products
products:writeCreate or update catalog products by SKU

Missing or invalid keys return 401. A valid key without the required scope returns 403.

Request IDs ​

Every response includes requestId on errors. Include it when contacting support. Successful responses are identified in Chuchu audit by the same request ID.

Never log the full API key. Treat it like a password.

Public documentation. No login.