openapi: 3.0.0 info: title: BigCommerce Abandoned Cart Emails API Token API version: 3.0.0 termsOfService: https://www.bigcommerce.com/terms description: Abandoned Cart Emails V3 API managing Handlebars-based emails. contact: name: BigCommerce url: https://www.bigcommerce.com email: support@bigcommerce.com servers: - url: https://api.bigcommerce.com/stores/{store_hash}/v3 variables: store_hash: default: store_hash description: Permanent ID of the BigCommerce store. description: BigCommerce API Gateway security: - X-Auth-Token: [] tags: - name: API Token paths: /storefront/api-token: parameters: - $ref: '#/components/parameters/Accept' post: tags: - API Token summary: BigCommerce Create a Token description: 'Creates a Storefront API token. **Required Scopes** * `Manage` `Storefront API Tokens`' operationId: createToken parameters: - $ref: '#/components/parameters/ContentType' requestBody: content: application/json: schema: allOf: - $ref: '#/components/schemas/TokenPostSimple' - $ref: '#/components/schemas/TokenPostImpersonation' required: false responses: '200': description: '' content: application/json: schema: $ref: '#/components/schemas/Token_Full' '401': description: Unauthorized - the v3 Auth client ID or token in the request are not a valid combination for this store. content: {} '403': description: Missing scope - the v3 Auth token is valid but does not have proper permissions to access this endpoint. content: {} '422': description: Invalid JSON request body - missing or invalid data. content: {} x-codegen-request-body-name: body delete: tags: - API Token summary: BigCommerce Revoke a Token description: Revoke access for a Storefront API token. Only revoke compromised tokens under emergency situations. Let uncompromised short-lived tokens expire naturally, as you do not need to revoke these. operationId: revokeToken parameters: - name: Sf-Api-Token in: header description: An existing JWT token that you want to revoke. required: true schema: type: string responses: '200': description: A storefront API token revocation has been scheduled. content: {} '401': description: Unauthorized - the v3 Auth client ID or token in the request are not a valid combination for this store. content: {} '403': description: Missing scope - the v3 Auth token is valid but does not have proper permissions to access this endpoint. content: {} '422': description: Invalid JWT Token provided or missing JWT token header content: {} components: parameters: Accept: name: Accept in: header required: true description: The [MIME type](https://developer.mozilla.org/en-US/docs/Web/HTTP/Basics_of_HTTP/MIME_types) of the response body. schema: type: string default: application/json ContentType: name: Content-Type in: header required: true description: The [MIME type](https://developer.mozilla.org/en-US/docs/Web/HTTP/Basics_of_HTTP/MIME_types) of the request body. schema: type: string default: application/json schemas: Token_Base: type: object properties: token: type: string description: JWT Token for accessing the Storefront API x-internal: false Token_Full: type: object properties: data: $ref: '#/components/schemas/Token_Base' meta: type: object properties: {} additionalProperties: true description: Response metadata. TokenPostSimple: type: object properties: allowed_cors_origins: maxItems: 1 minItems: 1 type: array description: List of allowed domains for Cross-Origin Request Sharing. Currently only accepts a single element. items: maxLength: 1 minLength: 1 pattern: /^https?:\/\/(?=.{1,254}(?::|$))(?:(?!\d|-)(?![a-z0-9\-]{1,62}-(?:\.|:|$))[a-z0-9\-]{1,63}\b(?!\.$)\.?)+(:\d+)?$/i; type: string x-internal: false x-examples: example-1: allowed_cors_origins: - https://www.yourstorefront.com/ TokenPostImpersonation: type: object x-internal: false x-examples: {} properties: channel_id: type: integer minimum: 1 description: Channel ID for requested token example: 1 expires_at: type: integer description: Unix timestamp (UTC time) defining when the token should expire. Supports seconds, but does not support milliseconds, microseconds, or nanoseconds. example: 1885635176 minimum: 0 required: - channel_id - expires_at securitySchemes: X-Auth-Token: name: X-Auth-Token description: '### OAuth scopes | UI Name | Permission | Parameter | |:--|:--|:-| | Information & Settings | read-only | `store_v2_information_read_only`| | Information & Settings | modify | `store_v2_information` | ### Authentication header | Header | Argument | Description | |:-|:|:| | `X-Auth-Token` | `access_token` | For more about API accounts that generate `access_token`s, see our [Guide to API Accounts](/docs/start/authentication/api-accounts). | ### Further reading For example requests and more information about authenticating BigCommerce APIs, see [Authentication and Example Requests](/docs/start/authentication#x-auth-token-header-example-requests). For more about BigCommerce OAuth scopes, see our [Guide to API Accounts](/docs/start/authentication/api-accounts#oauth-scopes). For a list of API status codes, see [API Status Codes](/docs/start/about/status-codes).' type: apiKey in: header