[{"data":1,"prerenderedAt":280},["ShallowReactive",2],{"navigation_docs_en":3,"-en-getting-started-trust-model":230,"-en-getting-started-trust-model-surround":275},[4,23,41,51,65,83,202,216],{"title":5,"icon":6,"path":7,"stem":8,"children":9,"page":22},"Getting started","i-lucide-rocket","\u002Fen\u002Fgetting-started","en\u002F1.getting-started",[10,14,18],{"title":11,"path":12,"stem":13},"Quick start","\u002Fen\u002Fgetting-started\u002Fquick-start","en\u002F1.getting-started\u002F1.quick-start",{"title":15,"path":16,"stem":17},"Trust model","\u002Fen\u002Fgetting-started\u002Ftrust-model","en\u002F1.getting-started\u002F2.trust-model",{"title":19,"path":20,"stem":21},"Enterprise integration journey","\u002Fen\u002Fgetting-started\u002Fenterprise-integration","en\u002F1.getting-started\u002F3.enterprise-integration",false,{"title":24,"icon":25,"path":26,"stem":27,"children":28,"page":22},"Storefront","i-lucide-store","\u002Fen\u002Fstorefront","en\u002F2.storefront",[29,33,37],{"title":30,"path":31,"stem":32},"Third-party Storefront","\u002Fen\u002Fstorefront\u002Fthird-party-storefront","en\u002F2.storefront\u002F1.third-party-storefront",{"title":34,"path":35,"stem":36},"Turnstile trust boundary","\u002Fen\u002Fstorefront\u002Fchallenge-and-turnstile","en\u002F2.storefront\u002F2.challenge-and-turnstile",{"title":38,"path":39,"stem":40},"Third-party Storefront public API","\u002Fen\u002Fstorefront\u002Fpublic-api","en\u002F2.storefront\u002F3.public-api",{"title":42,"icon":43,"path":44,"stem":45,"children":46,"page":22},"OAuth and identity","i-lucide-key-round","\u002Fen\u002Foauth","en\u002F3.oauth",[47],{"title":48,"path":49,"stem":50},"Third-party account authorization boundary","\u002Fen\u002Foauth\u002Fauthorization-code-pkce","en\u002F3.oauth\u002F1.authorization-code-pkce",{"title":52,"icon":53,"path":54,"stem":55,"children":56,"page":22},"Developer platform","i-lucide-blocks","\u002Fen\u002Fplatform","en\u002F4.platform",[57,61],{"title":58,"path":59,"stem":60},"Apps, versions, installations, and scopes","\u002Fen\u002Fplatform\u002Fapps-installations-scopes","en\u002F4.platform\u002F1.apps-installations-scopes",{"title":62,"path":63,"stem":64},"Origins, redirects, proxies, and environments","\u002Fen\u002Fplatform\u002Fsecurity-and-environments","en\u002F4.platform\u002F2.security-and-environments",{"title":66,"icon":67,"path":68,"stem":69,"children":70,"page":22},"Runtime extensions","i-lucide-workflow","\u002Fen\u002Fruntime","en\u002F5.runtime",[71,75,79],{"title":72,"path":73,"stem":74},"Installation Webhooks","\u002Fen\u002Fruntime\u002Fwebhooks","en\u002F5.runtime\u002F1.webhooks",{"title":76,"path":77,"stem":78},"Inventory synchronization","\u002Fen\u002Fruntime\u002Finventory-sync","en\u002F5.runtime\u002F2.inventory-sync",{"title":80,"path":81,"stem":82},"Automatic fulfillment providers","\u002Fen\u002Fruntime\u002Fauto-fulfillment","en\u002F5.runtime\u002F3.auto-fulfillment",{"title":84,"icon":85,"path":86,"stem":87,"children":88,"page":22},"API reference","i-lucide-braces","\u002Fen\u002Freference","en\u002F6.reference",[89,93,97],{"title":90,"path":91,"stem":92},"API Reference","\u002Fen\u002Freference\u002Fapi","en\u002F6.reference\u002F1.api",{"title":94,"path":95,"stem":96},"Errors, idempotency, and rate limits","\u002Fen\u002Freference\u002Ferrors-and-limits","en\u002F6.reference\u002F2.errors-and-limits",{"title":98,"path":99,"stem":100,"children":101,"page":22},"Endpoint catalog","\u002Fen\u002Freference\u002Foperations","en\u002F6.reference\u002F3.operations",[102,106,110,114,118,122,126,130,134,138,142,146,150,154,158,162,166,170,174,178,182,186,190,194,198],{"title":103,"path":104,"stem":105},"Get the public runtime configuration","\u002Fen\u002Freference\u002Foperations\u002Fget-public-runtime-config","en\u002F6.reference\u002F3.operations\u002F01.get-public-runtime-config",{"title":107,"path":108,"stem":109},"Get the public site bootstrap configuration","\u002Fen\u002Freference\u002Foperations\u002Fget-public-bootstrap","en\u002F6.reference\u002F3.operations\u002F02.get-public-bootstrap",{"title":111,"path":112,"stem":113},"Get public contact channels","\u002Fen\u002Freference\u002Foperations\u002Fget-public-contact","en\u002F6.reference\u002F3.operations\u002F03.get-public-contact",{"title":115,"path":116,"stem":117},"List current published legal documents by locale","\u002Fen\u002Freference\u002Foperations\u002Flist-public-legal-documents","en\u002F6.reference\u002F3.operations\u002F04.list-public-legal-documents",{"title":119,"path":120,"stem":121},"Get the published Storefront decoration","\u002Fen\u002Freference\u002Foperations\u002Fget-public-storefront-decoration","en\u002F6.reference\u002F3.operations\u002F05.get-public-storefront-decoration",{"title":123,"path":124,"stem":125},"Get the public store security configuration","\u002Fen\u002Freference\u002Foperations\u002Fget-public-store-security-config","en\u002F6.reference\u002F3.operations\u002F06.get-public-store-security-config",{"title":127,"path":128,"stem":129},"Search public products","\u002Fen\u002Freference\u002Foperations\u002Fsearch-public-products","en\u002F6.reference\u002F3.operations\u002F07.search-public-products",{"title":131,"path":132,"stem":133},"List public categories","\u002Fen\u002Freference\u002Foperations\u002Flist-public-categories","en\u002F6.reference\u002F3.operations\u002F08.list-public-categories",{"title":135,"path":136,"stem":137},"Get the installation credential identity","\u002Fen\u002Freference\u002Foperations\u002Fget-installation-credential-identity","en\u002F6.reference\u002F3.operations\u002F09.get-installation-credential-identity",{"title":139,"path":140,"stem":141},"Get the installation credential readiness","\u002Fen\u002Freference\u002Foperations\u002Fget-installation-credential-readiness","en\u002F6.reference\u002F3.operations\u002F10.get-installation-credential-readiness",{"title":143,"path":144,"stem":145},"Initiate a hosted login session","\u002Fen\u002Freference\u002Foperations\u002Finitiate-hosted-login","en\u002F6.reference\u002F3.operations\u002F11.initiate-hosted-login",{"title":147,"path":148,"stem":149},"Consume a hosted login return","\u002Fen\u002Freference\u002Foperations\u002Fconsume-hosted-login-return","en\u002F6.reference\u002F3.operations\u002F12.consume-hosted-login-return",{"title":151,"path":152,"stem":153},"Create a hosted checkout session","\u002Fen\u002Freference\u002Foperations\u002Fcreate-hosted-checkout-session","en\u002F6.reference\u002F3.operations\u002F13.create-hosted-checkout-session",{"title":155,"path":156,"stem":157},"Get a hosted checkout session","\u002Fen\u002Freference\u002Foperations\u002Fget-hosted-checkout-session","en\u002F6.reference\u002F3.operations\u002F14.get-hosted-checkout-session",{"title":159,"path":160,"stem":161},"Cancel a hosted checkout session","\u002Fen\u002Freference\u002Foperations\u002Fcancel-hosted-checkout-session","en\u002F6.reference\u002F3.operations\u002F15.cancel-hosted-checkout-session",{"title":163,"path":164,"stem":165},"List the public product catalog","\u002Fen\u002Freference\u002Foperations\u002Flist-public-products","en\u002F6.reference\u002F3.operations\u002F16.list-public-products",{"title":167,"path":168,"stem":169},"Get a public product by slug","\u002Fen\u002Freference\u002Foperations\u002Fget-public-product","en\u002F6.reference\u002F3.operations\u002F17.get-public-product",{"title":171,"path":172,"stem":173},"Get a public store profile","\u002Fen\u002Freference\u002Foperations\u002Fget-public-merchant","en\u002F6.reference\u002F3.operations\u002F18.get-public-merchant",{"title":175,"path":176,"stem":177},"List public products for a store","\u002Fen\u002Freference\u002Foperations\u002Flist-public-merchant-products","en\u002F6.reference\u002F3.operations\u002F19.list-public-merchant-products",{"title":179,"path":180,"stem":181},"List public categories for a store","\u002Fen\u002Freference\u002Foperations\u002Flist-public-merchant-categories","en\u002F6.reference\u002F3.operations\u002F20.list-public-merchant-categories",{"title":183,"path":184,"stem":185},"Get a public product for a store","\u002Fen\u002Freference\u002Foperations\u002Fget-public-merchant-product","en\u002F6.reference\u002F3.operations\u002F21.get-public-merchant-product",{"title":187,"path":188,"stem":189},"Get the current API Key identity and scopes","\u002Fen\u002Freference\u002Foperations\u002Fget-api-key-identity","en\u002F6.reference\u002F3.operations\u002F22.get-api-key-identity",{"title":191,"path":192,"stem":193},"List public categories with an API Key","\u002Fen\u002Freference\u002Foperations\u002Flist-api-key-catalog-categories","en\u002F6.reference\u002F3.operations\u002F23.list-api-key-catalog-categories",{"title":195,"path":196,"stem":197},"List public products with an API Key","\u002Fen\u002Freference\u002Foperations\u002Flist-api-key-catalog-products","en\u002F6.reference\u002F3.operations\u002F24.list-api-key-catalog-products",{"title":199,"path":200,"stem":201},"Get a public product with an API Key","\u002Fen\u002Freference\u002Foperations\u002Fget-api-key-catalog-product","en\u002F6.reference\u002F3.operations\u002F25.get-api-key-catalog-product",{"title":203,"icon":204,"path":205,"stem":206,"children":207,"page":22},"Examples","i-lucide-code-xml","\u002Fen\u002Fexamples","en\u002F7.examples",[208,212],{"title":209,"path":210,"stem":211},"Minimal Nuxt Storefront","\u002Fen\u002Fexamples\u002Fnuxt-storefront","en\u002F7.examples\u002F1.nuxt-storefront",{"title":213,"path":214,"stem":215},"Webhook verification","\u002Fen\u002Fexamples\u002Fwebhook-verification","en\u002F7.examples\u002F2.webhook-verification",{"title":217,"icon":218,"path":219,"stem":220,"children":221,"page":22},"Versions and support","i-lucide-life-buoy","\u002Fen\u002Foperations","en\u002F8.operations",[222,226],{"title":223,"path":224,"stem":225},"Versions, migrations, and changelog","\u002Fen\u002Foperations\u002Fversions-and-migrations","en\u002F8.operations\u002F1.versions-and-migrations",{"title":227,"path":228,"stem":229},"Support and security disclosure","\u002Fen\u002Foperations\u002Fsupport-and-security","en\u002F8.operations\u002F2.support-and-security",{"id":231,"title":15,"body":232,"description":268,"extension":269,"links":270,"meta":271,"navigation":272,"path":16,"seo":273,"stem":17,"__hash__":274},"docs_en\u002Fen\u002F1.getting-started\u002F2.trust-model.md",{"type":233,"value":234,"toc":264},"minimark",[235,239,243,246],[236,237,15],"h1",{"id":238},"trust-model",[240,241,242],"p",{},"Authorization is the intersection of platform capability, app approval, immutable app version, active installation, store and market binding, granted OAuth scopes, current user or service role, legal consent, and rate\u002Frisk policy. A permissive Origin or successful CORS preflight grants none of these.",[240,244,245],{},"Sandbox and production have separate installations, credentials, events, quotas, mappings, and fulfillment intents. Sandbox requests cannot change production inventory, orders, or delivery state.",[240,247,248,249,253,254,253,257,253,260,263],{},"All resource identifiers remain server-authoritative. A client-supplied ",[250,251,252],"code",{},"tenantId",", ",[250,255,256],{},"storeId",[250,258,259],{},"userId",[250,261,262],{},"scope",", product ID, or provider reference is only a lookup key and never proof of ownership.",{"title":265,"searchDepth":266,"depth":266,"links":267},"",2,[],"Understand the public documentation, platform, store, installation, user, and provider trust boundaries.","md",null,{},true,{"title":15,"description":268},"95t7kAFyBrZfwUmitVljTOgEmp_koY7DWoQDFlXnGoo",[276,278],{"title":11,"path":12,"stem":13,"description":277,"children":-1},"Choose an integration environment and make the first public API request without storing secrets in a browser.",{"title":19,"path":20,"stem":21,"description":279,"children":-1},"An end-to-end path from readiness and platform enablement through authorization, API use, Webhooks, testing, production, and emergency revocation.",1785961911126]