Appearance
Authentication
External systems authenticate with a merchant API key, not a Chuchu user login.
http
Authorization: Bearer chu_live_...Do not send X-Merchant-Id. The key is bound to one merchant.
Creating a key
An owner or admin with integration-management access creates keys in Settings → Developer / API.
Example create body:
json
{
"name": "ERP production",
"scopes": ["orders:read", "orders:write", "orders:cancel", "products:read", "products:write"],
"expiresAt": null
}The full secret is returned once. Later list responses include only a prefix such as chu_live_abcd1234.
Revoking a key keeps history. It is not deleted.
Scopes
| Scope | Access |
|---|---|
orders:read | List and get orders |
orders:write | Create orders |
orders:cancel | Cancel orders |
products:read | List catalog products |
products:write | Create or update catalog products by SKU |
Missing or invalid keys return 401. A valid key without the required scope returns 403.
Request IDs
Every response includes requestId on errors. Include it when contacting support. Successful responses are identified in Chuchu audit by the same request ID.
Never log the full API key. Treat it like a password.