[{"data":1,"prerenderedAt":416},["ShallowReactive",2],{"navigation_docs_zh":3,"-zh-storefront-third-party-storefront":228,"-zh-storefront-third-party-storefront-surround":411},[4,22,40,50,64,82,200,214],{"title":5,"icon":6,"path":7,"stem":8,"children":9,"page":21},"快速开始","i-lucide-rocket","\u002Fzh\u002Fgetting-started","zh\u002F1.getting-started",[10,13,17],{"title":5,"path":11,"stem":12},"\u002Fzh\u002Fgetting-started\u002Fquick-start","zh\u002F1.getting-started\u002F1.quick-start",{"title":14,"path":15,"stem":16},"信任模型","\u002Fzh\u002Fgetting-started\u002Ftrust-model","zh\u002F1.getting-started\u002F2.trust-model",{"title":18,"path":19,"stem":20},"大客户端到端接入指南","\u002Fzh\u002Fgetting-started\u002Fenterprise-integration","zh\u002F1.getting-started\u002F3.enterprise-integration",false,{"title":23,"icon":24,"path":25,"stem":26,"children":27,"page":21},"自研 Storefront","i-lucide-store","\u002Fzh\u002Fstorefront","zh\u002F2.storefront",[28,32,36],{"title":29,"path":30,"stem":31},"第三方 Storefront","\u002Fzh\u002Fstorefront\u002Fthird-party-storefront","zh\u002F2.storefront\u002F1.third-party-storefront",{"title":33,"path":34,"stem":35},"Turnstile 的信任边界","\u002Fzh\u002Fstorefront\u002Fchallenge-and-turnstile","zh\u002F2.storefront\u002F2.challenge-and-turnstile",{"title":37,"path":38,"stem":39},"第三方店铺前端公共 API","\u002Fzh\u002Fstorefront\u002Fpublic-api","zh\u002F2.storefront\u002F3.public-api",{"title":41,"icon":42,"path":43,"stem":44,"children":45,"page":21},"OAuth 与身份","i-lucide-key-round","\u002Fzh\u002Foauth","zh\u002F3.oauth",[46],{"title":47,"path":48,"stem":49},"第三方账号授权安全边界","\u002Fzh\u002Foauth\u002Fauthorization-code-pkce","zh\u002F3.oauth\u002F1.authorization-code-pkce",{"title":51,"icon":52,"path":53,"stem":54,"children":55,"page":21},"开发者平台","i-lucide-blocks","\u002Fzh\u002Fplatform","zh\u002F4.platform",[56,60],{"title":57,"path":58,"stem":59},"应用、版本、安装与 Scope","\u002Fzh\u002Fplatform\u002Fapps-installations-scopes","zh\u002F4.platform\u002F1.apps-installations-scopes",{"title":61,"path":62,"stem":63},"Origin、Redirect、反向代理与环境","\u002Fzh\u002Fplatform\u002Fsecurity-and-environments","zh\u002F4.platform\u002F2.security-and-environments",{"title":65,"icon":66,"path":67,"stem":68,"children":69,"page":21},"运行时扩展","i-lucide-workflow","\u002Fzh\u002Fruntime","zh\u002F5.runtime",[70,74,78],{"title":71,"path":72,"stem":73},"安装级 Webhook","\u002Fzh\u002Fruntime\u002Fwebhooks","zh\u002F5.runtime\u002F1.webhooks",{"title":75,"path":76,"stem":77},"库存同步","\u002Fzh\u002Fruntime\u002Finventory-sync","zh\u002F5.runtime\u002F2.inventory-sync",{"title":79,"path":80,"stem":81},"自动发货 Provider","\u002Fzh\u002Fruntime\u002Fauto-fulfillment","zh\u002F5.runtime\u002F3.auto-fulfillment",{"title":83,"icon":84,"path":85,"stem":86,"children":87,"page":21},"API 参考","i-lucide-braces","\u002Fzh\u002Freference","zh\u002F6.reference",[88,91,95],{"title":83,"path":89,"stem":90},"\u002Fzh\u002Freference\u002Fapi","zh\u002F6.reference\u002F1.api",{"title":92,"path":93,"stem":94},"错误、幂等与限流","\u002Fzh\u002Freference\u002Ferrors-and-limits","zh\u002F6.reference\u002F2.errors-and-limits",{"title":96,"path":97,"stem":98,"children":99,"page":21},"Endpoint 目录","\u002Fzh\u002Freference\u002Foperations","zh\u002F6.reference\u002F3.operations",[100,104,108,112,116,120,124,128,132,136,140,144,148,152,156,160,164,168,172,176,180,184,188,192,196],{"title":101,"path":102,"stem":103},"读取公开运行配置","\u002Fzh\u002Freference\u002Foperations\u002Fget-public-runtime-config","zh\u002F6.reference\u002F3.operations\u002F01.get-public-runtime-config",{"title":105,"path":106,"stem":107},"读取公开站点启动配置","\u002Fzh\u002Freference\u002Foperations\u002Fget-public-bootstrap","zh\u002F6.reference\u002F3.operations\u002F02.get-public-bootstrap",{"title":109,"path":110,"stem":111},"读取公开联系渠道","\u002Fzh\u002Freference\u002Foperations\u002Fget-public-contact","zh\u002F6.reference\u002F3.operations\u002F03.get-public-contact",{"title":113,"path":114,"stem":115},"按语言读取当前已发布法律正文","\u002Fzh\u002Freference\u002Foperations\u002Flist-public-legal-documents","zh\u002F6.reference\u002F3.operations\u002F04.list-public-legal-documents",{"title":117,"path":118,"stem":119},"读取店铺已发布装修","\u002Fzh\u002Freference\u002Foperations\u002Fget-public-storefront-decoration","zh\u002F6.reference\u002F3.operations\u002F05.get-public-storefront-decoration",{"title":121,"path":122,"stem":123},"读取店铺公开安全配置","\u002Fzh\u002Freference\u002Foperations\u002Fget-public-store-security-config","zh\u002F6.reference\u002F3.operations\u002F06.get-public-store-security-config",{"title":125,"path":126,"stem":127},"搜索可公开销售商品","\u002Fzh\u002Freference\u002Foperations\u002Fsearch-public-products","zh\u002F6.reference\u002F3.operations\u002F07.search-public-products",{"title":129,"path":130,"stem":131},"读取公开分类","\u002Fzh\u002Freference\u002Foperations\u002Flist-public-categories","zh\u002F6.reference\u002F3.operations\u002F08.list-public-categories",{"title":133,"path":134,"stem":135},"读取安装级凭据绑定身份","\u002Fzh\u002Freference\u002Foperations\u002Fget-installation-credential-identity","zh\u002F6.reference\u002F3.operations\u002F09.get-installation-credential-identity",{"title":137,"path":138,"stem":139},"读取安装级凭据就绪与阻塞事实","\u002Fzh\u002Freference\u002Foperations\u002Fget-installation-credential-readiness","zh\u002F6.reference\u002F3.operations\u002F10.get-installation-credential-readiness",{"title":141,"path":142,"stem":143},"创建官方托管登录流程","\u002Fzh\u002Freference\u002Foperations\u002Finitiate-hosted-login","zh\u002F6.reference\u002F3.operations\u002F11.initiate-hosted-login",{"title":145,"path":146,"stem":147},"以 PKCE 单次消费托管登录返回码","\u002Fzh\u002Freference\u002Foperations\u002Fconsume-hosted-login-return","zh\u002F6.reference\u002F3.operations\u002F12.consume-hosted-login-return",{"title":149,"path":150,"stem":151},"创建服务端重算的托管结账会话","\u002Fzh\u002Freference\u002Foperations\u002Fcreate-hosted-checkout-session","zh\u002F6.reference\u002F3.operations\u002F13.create-hosted-checkout-session",{"title":153,"path":154,"stem":155},"读取绑定安装的托管结账状态","\u002Fzh\u002Freference\u002Foperations\u002Fget-hosted-checkout-session","zh\u002F6.reference\u002F3.operations\u002F14.get-hosted-checkout-session",{"title":157,"path":158,"stem":159},"取消尚未进入不可逆支付阶段的托管结账","\u002Fzh\u002Freference\u002Foperations\u002Fcancel-hosted-checkout-session","zh\u002F6.reference\u002F3.operations\u002F15.cancel-hosted-checkout-session",{"title":161,"path":162,"stem":163},"读取公开商品目录","\u002Fzh\u002Freference\u002Foperations\u002Flist-public-products","zh\u002F6.reference\u002F3.operations\u002F16.list-public-products",{"title":165,"path":166,"stem":167},"按 slug 读取公开商品","\u002Fzh\u002Freference\u002Foperations\u002Fget-public-product","zh\u002F6.reference\u002F3.operations\u002F17.get-public-product",{"title":169,"path":170,"stem":171},"读取公开店铺资料","\u002Fzh\u002Freference\u002Foperations\u002Fget-public-merchant","zh\u002F6.reference\u002F3.operations\u002F18.get-public-merchant",{"title":173,"path":174,"stem":175},"读取店铺公开商品","\u002Fzh\u002Freference\u002Foperations\u002Flist-public-merchant-products","zh\u002F6.reference\u002F3.operations\u002F19.list-public-merchant-products",{"title":177,"path":178,"stem":179},"读取店铺公开分类","\u002Fzh\u002Freference\u002Foperations\u002Flist-public-merchant-categories","zh\u002F6.reference\u002F3.operations\u002F20.list-public-merchant-categories",{"title":181,"path":182,"stem":183},"读取店铺公开商品详情","\u002Fzh\u002Freference\u002Foperations\u002Fget-public-merchant-product","zh\u002F6.reference\u002F3.operations\u002F21.get-public-merchant-product",{"title":185,"path":186,"stem":187},"读取当前 API Key 的标识与 scope","\u002Fzh\u002Freference\u002Foperations\u002Fget-api-key-identity","zh\u002F6.reference\u002F3.operations\u002F22.get-api-key-identity",{"title":189,"path":190,"stem":191},"通过 API Key 读取公开分类","\u002Fzh\u002Freference\u002Foperations\u002Flist-api-key-catalog-categories","zh\u002F6.reference\u002F3.operations\u002F23.list-api-key-catalog-categories",{"title":193,"path":194,"stem":195},"通过 API Key 读取公开商品目录","\u002Fzh\u002Freference\u002Foperations\u002Flist-api-key-catalog-products","zh\u002F6.reference\u002F3.operations\u002F24.list-api-key-catalog-products",{"title":197,"path":198,"stem":199},"通过 API Key 读取公开商品","\u002Fzh\u002Freference\u002Foperations\u002Fget-api-key-catalog-product","zh\u002F6.reference\u002F3.operations\u002F25.get-api-key-catalog-product",{"title":201,"icon":202,"path":203,"stem":204,"children":205,"page":21},"示例","i-lucide-code-xml","\u002Fzh\u002Fexamples","zh\u002F7.examples",[206,210],{"title":207,"path":208,"stem":209},"最小 Nuxt Storefront","\u002Fzh\u002Fexamples\u002Fnuxt-storefront","zh\u002F7.examples\u002F1.nuxt-storefront",{"title":211,"path":212,"stem":213},"Webhook 验签","\u002Fzh\u002Fexamples\u002Fwebhook-verification","zh\u002F7.examples\u002F2.webhook-verification",{"title":215,"icon":216,"path":217,"stem":218,"children":219,"page":21},"版本与支持","i-lucide-life-buoy","\u002Fzh\u002Foperations","zh\u002F8.operations",[220,224],{"title":221,"path":222,"stem":223},"版本、迁移与变更记录","\u002Fzh\u002Foperations\u002Fversions-and-migrations","zh\u002F8.operations\u002F1.versions-and-migrations",{"title":225,"path":226,"stem":227},"支持与安全披露","\u002Fzh\u002Foperations\u002Fsupport-and-security","zh\u002F8.operations\u002F2.support-and-security",{"id":229,"title":29,"body":230,"description":404,"extension":405,"links":406,"meta":407,"navigation":408,"path":30,"seo":409,"stem":31,"__hash__":410},"docs_zh\u002Fzh\u002F2.storefront\u002F1.third-party-storefront.md",{"type":231,"value":232,"toc":401},"minimark",[233,237,241,245,299,332,335,338,368,375,386,397],[234,235,29],"h1",{"id":236},"第三方-storefront",[238,239,240],"p",{},"公开目录读取由 API 决定店铺、市场与发布状态。自定义域不得根据商品 ID、slug、搜索结果、缓存 JSON-LD、sitemap 或 OpenGraph 响应推断准入。",[242,243,244],"h2",{"id":244},"托管跳转模型",[246,247,252],"pre",{"className":248,"code":249,"language":250,"meta":251,"style":251},"language-mermaid shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","flowchart LR\n  A[第三方店铺：读取与展示公开目录] --> B{用户动作}\n  B -->|登录或注册| C[Ayalink 官方授权域：尚未开放]\n  B -->|结账或支付| D[Ayalink 官方托管结账：尚未开放]\n  C --> E[审核通过的精确 return URL]\n  D --> E\n  E --> A\n","mermaid","",[253,254,255,263,269,275,281,287,293],"code",{"__ignoreMap":251},[256,257,260],"span",{"class":258,"line":259},"line",1,[256,261,262],{},"flowchart LR\n",[256,264,266],{"class":258,"line":265},2,[256,267,268],{},"  A[第三方店铺：读取与展示公开目录] --> B{用户动作}\n",[256,270,272],{"class":258,"line":271},3,[256,273,274],{},"  B -->|登录或注册| C[Ayalink 官方授权域：尚未开放]\n",[256,276,278],{"class":258,"line":277},4,[256,279,280],{},"  B -->|结账或支付| D[Ayalink 官方托管结账：尚未开放]\n",[256,282,284],{"class":258,"line":283},5,[256,285,286],{},"  C --> E[审核通过的精确 return URL]\n",[256,288,290],{"class":258,"line":289},6,[256,291,292],{},"  D --> E\n",[256,294,296],{"class":258,"line":295},7,[256,297,298],{},"  E --> A\n",[300,301,302,314,320,326],"ul",{},[303,304,305,309,310,313],"li",{},[306,307,308],"strong",{},"目录读取：已开放。"," 只调用",[311,312,37],"a",{"href":38},"列出的 operation。",[303,315,316,319],{},[306,317,318],{},"Hosted login 后端 session 基础：契约已发布。"," Artifact 包含受 API Key 保护、带 PKCE 相关字段的服务端 initiate 与 return 操作。官方登录 UI、authorization domain 生产配置及浏览器可执行跳转流程尚未完成，因此不提供可执行跳转示例。",[303,321,322,325],{},[306,323,324],{},"Hosted checkout 后端 session 基础：契约已发布。"," Artifact 包含服务端 session create、get、cancel 操作。官方结账 UI、订单最终创建、Provider 支付推进、生产配置与迁移尚未完成；这不代表结账或支付已经可用。",[303,327,328,331],{},[306,329,330],{},"返回：需要平台开通。"," 未来只能返回平台审核通过的精确 HTTPS return URL；不得接受开放重定向或客户端临时覆盖。",[238,333,334],{},"第三方不得收集 Ayalink 邮箱、密码或 MFA，不得接收或转发 Ayalink 全局 Cookie，不得接触卡号、支付 token 或其他支付凭据，也不得 iframe、反代或仿冒 Ayalink 登录、注册、结账或支付页面。第三方站只展示目录并发起未来经公开契约批准的顶层跳转。",[238,336,337],{},"店铺保护页面或资源时，API 必须把同一策略应用于详情、价格、库存、媒体、结构化数据、SSR、搜索、sitemap 与缓存。客户端分别处理：",[300,339,340,346,352,358],{},[303,341,342,345],{},[253,343,344],{},"401","：通过系统授权域登录，并只返回本应用 allowlist 内的路径；",[303,347,348,351],{},[253,349,350],{},"403","：已登录用户缺少会员、角色、客户组、市场或 scope；",[303,353,354,357],{},[253,355,356],{},"404","：店铺对隐藏资源启用了防枚举语义；",[303,359,360,363,364,367],{},[253,361,362],{},"429"," 或 ",[253,365,366],{},"CHALLENGE_REQUIRED","：渲染有范围的挑战，原请求最多安全重试一次。",[238,369,370,371,374],{},"公开响应只能按服务端声明的完整键缓存，包括店铺、市场、语言、策略版本和认证类别。用户态响应必须 ",[253,372,373],{},"private\u002Fno-store","，禁止进入共享 CDN 缓存。",[238,376,377,378,381,382,385],{},"浏览器永远不接收 client secret，也不得保存 access\u002Frefresh token，或代理、共享 Ayalink 全局 session Cookie。未来登录只能发生在平台开通材料确认的官方 authorization domain，并使用 Authorization Code + PKCE S256、精确 redirect URI、",[253,379,380],{},"state"," 与 ",[253,383,384],{},"nonce","。",[238,387,388,389,392,393,396],{},"需要持久会话时采用同源 BFF。BFF 只保存本 app\u002Finstallation\u002Fstore\u002Fresource\u002Faudience 的最小 OAuth grant，并向自己的前端提供安全应用会话 Cookie；它不能转发 Ayalink Cookie。OAuth API 尚待安全审计，因此",[311,390,391],{"href":48},"账号授权安全边界","与",[311,394,395],{"href":208},"最小 Nuxt 示例","不提供登录 endpoint 或 token exchange 代码。",[398,399,400],"style",{},"html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":251,"searchDepth":265,"depth":265,"links":402},[403],{"id":244,"depth":265,"text":244},"在保持 Ayalink 身份、页面准入、缓存和挑战边界的前提下构建独立商城。","md",null,{},true,{"title":29,"description":404},"LDRF-h_JdptA1ao1wT_vHnu0WEAK70G_FZZ_f7WNOLI",[412,414],{"title":18,"path":19,"stem":20,"description":413,"children":-1},"从接入评估、平台开通和安全授权，到 API、Webhook、测试、生产上线与应急撤销的完整路径。",{"title":33,"path":34,"stem":35,"description":415,"children":-1},"将 Turnstile 限定为官方登录与授权端点的 bot 防护，而不是网站真实性或登录证明。",1785961909241]