# Flipp (Wishabi) > Flipp, operated by Wishabi, is a Toronto-based retail media and digital merchandising company. Its consumer app aggregates weekly digital flyers, coupons and shopping lists from more than 2,000 retailers; its platform side distributes shoppable merchandising experiences to retailers and brands. For retail partners Flipp publishes the FlyerKit API — a versioned, read-only HTTPS/JSON API at api.flipp.com exposing publications (circulars), pages, highlights, categories, products, store locators and geo lookup — alongside native rendering SDKs for iOS and Android. Generated by API Evangelist on 2026-08-12. Flipp does not publish an llms.txt of its own: `/llms.txt` returns 404 on api.flipp.com, corp.flipp.com and help.flipp.com, and a single-page-app shell on www.flipp.com. This file is generated from the provider's own published Swagger document and public repositories; every artifact linked below records its own provenance. ## Access model The FlyerKit API is a **partner API, not a public one**. There is no developer portal (developer.flipp.com does not resolve), no self-service signup, no free tier and no published pricing. Access tokens are issued out of band by a Flipp technical contact, and the `merchant_identifier` every read is scoped to comes from the same place. An agent cannot bootstrap access to this API on its own. - Auth: `access_token` as a **URL query parameter** on 10 of 11 operations. No OAuth, no OIDC, no header option. - All operations are `GET`. The API is read-only. - Errors: one status only — `422` — with a `{"message": string, "code": number}` envelope. Not RFC 9457. - Rate limits: none published, no `RateLimit-*` or `Retry-After` headers observed. - Events: none. No webhooks, no AsyncAPI, no streaming. Poll-only. - Agent surfaces: no MCP server, no A2A agent card, no `/.well-known/` documents on any host. ## APIs - [Flipp FlyerKit API v4.0](https://api.flipp.com/flyerkit/v4.0/documentation): 11 read operations over publications, products, stores and geo lookup. Base URL `https://api.flipp.com/flyerkit/v4.0`. - [FlyerKit v4.0 Swagger document](https://api.flipp.com/flyerkit/apidocs_v4): the machine-readable contract, Swagger 2.0. Note it declares no `operationId`, no `securityDefinitions` and no `tags`. ## Specs - [openapi/flipp-wishabi-flyerkit-openapi.yml](openapi/flipp-wishabi-flyerkit-openapi.yml): refined FlyerKit v4.0 specification. - [openapi/_original/flipp-wishabi-flyerkit-v4-openapi-original.json](openapi/_original/flipp-wishabi-flyerkit-v4-openapi-original.json): the document as Flipp serves it, byte-identical to the live fetch. - [overlays/flipp-wishabi-flyerkit-overlay.yaml](overlays/flipp-wishabi-flyerkit-overlay.yaml): OpenAPI Overlay 1.0.0 of API Evangelist's additions — operationIds, a securityDefinitions block and observed contract drift — applied on top of the original, never into it. ## Semantics - [authentication/flipp-wishabi-authentication.yml](authentication/flipp-wishabi-authentication.yml): the query-parameter token model, out-of-band issuance, and the v4.0 multi-token permission change. - [conventions/flipp-wishabi-conventions.yml](conventions/flipp-wishabi-conventions.yml): pagination, filtering, sorting, localization, caching, CORS, tracing headers and identifier semantics. - [errors/flipp-wishabi-problem-types.yml](errors/flipp-wishabi-problem-types.yml): the 422-only error catalog, including the observed drift where `code` is declared a string and returned as a number. - [data-model/flipp-wishabi-data-model.yml](data-model/flipp-wishabi-data-model.yml): the 20-entity graph and the id-reference relationships between publications, products, sub-items, coupons and stores. - [rate-limits/flipp-wishabi-rate-limits.yml](rate-limits/flipp-wishabi-rate-limits.yml): a measured zero — no documented limits and no runtime headers. - [conformance/flipp-wishabi-conformance.yml](conformance/flipp-wishabi-conformance.yml): standards assertions with evidence for each. ## Lifecycle - [lifecycle/flipp-wishabi-lifecycle.yml](lifecycle/flipp-wishabi-lifecycle.yml): the published semantic-versioning policy, v2.0 and v3.0 retirement, and the absence of any deprecation policy or status page. - [changelog/flipp-wishabi-changelog.yml](changelog/flipp-wishabi-changelog.yml): the undated v4.0 change list embedded in the spec, plus dated SDK releases. - [plans/flipp-wishabi-plans-pricing.yml](plans/flipp-wishabi-plans-pricing.yml): no public plans; the Storefronts rate card exists on Flipp's own domain but is password-protected. ## SDKs and components - [packages/flipp-wishabi-packages.yml](packages/flipp-wishabi-packages.yml): five first-party SDKs, zero on any public package registry. Distribution is a SwiftPM binaryTarget from GitHub releases and a credentialed JFrog Artifactory Maven repo. - [components/flipp-wishabi-components.yml](components/flipp-wishabi-components.yml): the native rendering components — DVMRendererView (iOS), FlippPublication (Android Compose), SFMLView/StorefrontSFMLView, WFKFlyerView and com.flipp.flyerkit.FlyerView. - [github.com/wishabi](https://github.com/wishabi): the public GitHub organization carrying the SDK binaries and sample apps. ## Agent skills - [skills/_index.yml](skills/_index.yml): index of the three packaged skills below. - [skills/flipp-wishabi-browse-retailer-circular.md](skills/flipp-wishabi-browse-retailer-circular.md): find a retailer's circular for a location and walk its pages, highlights and categories. - [skills/flipp-wishabi-pull-circular-offers.md](skills/flipp-wishabi-pull-circular-offers.md): pull filtered, paginated offers and expand one to its full detail record. - [skills/flipp-wishabi-locate-store-and-inventory.md](skills/flipp-wishabi-locate-store-and-inventory.md): resolve a shopper to a store, then read live store-level inventory and cart affordances. - [mcp/flipp-wishabi-mcp.yml](mcp/flipp-wishabi-mcp.yml): a candidate tool list derived from the 11 operations. Flipp publishes **no** MCP server — this describes what one would expose, and nothing here is offered by Flipp. ## Security - [security/flipp-wishabi-domain-security.yml](security/flipp-wishabi-domain-security.yml): TLS 1.3 across hosts, HSTS present on some upstreams and absent on others, no DNSSEC, no CAA, SPF and DMARC at `p=quarantine`. - [well-known/flipp-wishabi-well-known.yml](well-known/flipp-wishabi-well-known.yml): every `/.well-known/` path missed on every host. The 200s on www.flipp.com are single-page-app catch-all shells, not documents. - No security.txt, no vulnerability disclosure policy, no bug bounty, no trust center and no published compliance certification were found on any Flipp host. ## Company - [Flipp](https://www.flipp.com/): consumer app. - [Flipp Platform](https://corp.flipp.com/): retail media and merchandising platform for retailers and brands. - [Blog](https://blog.flipp.com/) - [Help Center](https://help.flipp.com/hc/en-ca): consumer support. There is no developer support channel. - [Terms of Use](https://corp.flipp.com/legal/terms_of_use/) · [Privacy Policy](https://corp.flipp.com/legal/privacy/) ## Licensing notice `GET https://api.flipp.com/flyerkit/v4.0/copyright` returns, verbatim: "Copyright 2011-2016 Flipp Corp. & Suppliers. All rights reserved. This API cannot be accessed and the content and any results may not be used, reproduced or transmitted in any manner without express written permission from Flipp Corp." Any use of FlyerKit data — including by an agent — is subject to that written permission.