NewPlatformDTC is in public betaPlatformDTC is in public beta — sign up and finish with a real store, no waitlist.Read the announcement →
← Changelog

v1.3

Products on the agent surface

Products is now a first-class agent API — the last core commerce object to reach the agent surface. /api/v1/products accepts X-Agent-Key: sq_agt_* alongside the dashboard's user JWT, with the same audit log and Idempotency-Key semantics as the other resource APIs.

Added

  • Full product surface — list (paged, searchable, sortable), get, create, partial update, soft delete, facets, duplicate, images, variants, bulk status/tags/delete, and the dropship catalog-link bind (POST/DELETE, previously read-only).
  • Writable fulfillment routing — supplier_id and fulfillment_rules are now settable through the API, so destination-based routing finally has a population path.
  • read_products / write_products scopes, matching the read_* / write_* naming the other resource APIs use.

Fixed

  • Commerce scopes were unmintable. read_inventory, write_inventory, read_discounts, write_discounts, read_gift_cards, write_gift_cards, read_metafields, write_metafields, read_returns, write_returns, read_draft_orders and write_draft_orders were enforced by the resource APIs but rejected at key creation, so no sq_agt_* key could hold them and those APIs were reachable only with a user JWT. All twelve are now grantable. Reissue any key that needs them — existing keys are unchanged.
  • offers:read / offers:write / offers:approve were unmintable too, for the same reason — and this was not theoretical: a key provisioned in production already carried all three and could never use them, because the scopes failed validation and the offers router was not mounted. All three are now grantable. offers:approve is deliberately not a spend scope — offer optimization gates its two dangerous calls in-band, at the call rather than the key.
  • write_gift_cards and write_discounts are now spend scopes. Both mint bearer value that is redeemable at checkout, so they belong behind the human-approval gate alongside ads:write and marketing:send.

Changed

  • catalog:read / catalog:write are now aliases of read_products / write_products. Already-issued keys keep working and either name authorizes either surface; no migration is required. New keys should use the *_products names.
  • GET /whoami gained an effective_scopes field. scopes continues to report the grant exactly as issued; effective_scopes shows it expanded through the aliases, so an agent debugging a 403 can see why a catalog:read key reaches a read_products route.
  • The tool catalog is generated from the MCP toolpack instead of hand-maintained. It had drifted to listing 23 of 78 tools.