v1.3
Products on the agent surface
Products is now a first-class agent API — the last core commerce
object to reach the agent surface. /api/v1/products accepts X-Agent-Key: sq_agt_*
alongside the dashboard's user JWT, with the same audit log and Idempotency-Key semantics
as the other resource APIs.
Added
- Full product surface — list (paged, searchable, sortable), get, create, partial update,
soft delete, facets, duplicate, images, variants, bulk status/tags/delete, and the dropship
catalog-link bind (
POST/DELETE, previously read-only). - Writable fulfillment routing —
supplier_idandfulfillment_rulesare now settable through the API, so destination-based routing finally has a population path. read_products/write_productsscopes, matching theread_*/write_*naming the other resource APIs use.
Fixed
- Commerce scopes were unmintable.
read_inventory,write_inventory,read_discounts,write_discounts,read_gift_cards,write_gift_cards,read_metafields,write_metafields,read_returns,write_returns,read_draft_ordersandwrite_draft_orderswere enforced by the resource APIs but rejected at key creation, so nosq_agt_*key could hold them and those APIs were reachable only with a user JWT. All twelve are now grantable. Reissue any key that needs them — existing keys are unchanged. offers:read/offers:write/offers:approvewere unmintable too, for the same reason — and this was not theoretical: a key provisioned in production already carried all three and could never use them, because the scopes failed validation and the offers router was not mounted. All three are now grantable.offers:approveis deliberately not a spend scope — offer optimization gates its two dangerous calls in-band, at the call rather than the key.write_gift_cardsandwrite_discountsare now spend scopes. Both mint bearer value that is redeemable at checkout, so they belong behind the human-approval gate alongsideads:writeandmarketing:send.
Changed
catalog:read/catalog:writeare now aliases ofread_products/write_products. Already-issued keys keep working and either name authorizes either surface; no migration is required. New keys should use the*_productsnames.GET /whoamigained aneffective_scopesfield.scopescontinues to report the grant exactly as issued;effective_scopesshows it expanded through the aliases, so an agent debugging a403can see why acatalog:readkey reaches aread_productsroute.- The tool catalog is generated from the MCP toolpack instead of hand-maintained. It had drifted to listing 23 of 78 tools.