# OZON.ru > OZON is one of Russia's largest e-commerce marketplaces. Its public developer surface is the OZON Seller API, a POST-based RPC-over-HTTP JSON API that lets marketplace sellers manage products, prices, stock, warehouses, orders (FBO/FBS), returns, analytics, and finances programmatically. This file was generated by the API Evangelist enrichment pipeline from verified live probes of the OZON Seller API host and the provider's public developer documentation. Values marked verified were observed directly against https://api-seller.ozon.ru. ## API - OZON Seller API base URL: https://api-seller.ozon.ru (verified live) - Documentation: https://docs.ozon.ru/api/seller/ - Style: RPC-over-HTTP, POST-only JSON endpoints, path pattern /v{n}/{resource}/{action} (e.g. /v1/warehouse/list, /v3/product/list) - Content type: application/json ## Authentication - Two required HTTP headers on every request: Client-Id (numeric seller id) and Api-Key (secret key from the seller cabinet). Verified live. - No OAuth2 / OpenID Connect. Transport is HTTPS/TLS 1.3. - Malformed Client-Id -> HTTP 400 {"code":3,"message":"Client-Id header value should be positive integer"} (verified) - Invalid Api-Key -> HTTP 404 {"code":5,"message":"Invalid Api-Key, please check the key and try again"} (verified) ## Errors - grpc-status JSON envelope: {code, message, details} where code is a gRPC canonical integer status. Not RFC 9457 problem+json. - See errors/ozonru-problem-types.yml ## Security - security.txt: https://ozon.ru/.well-known/security.txt (verified 200) - Bug bounty: Standoff365 (https://bugbounty.standoff365.com/programs/ozon/) and BI.ZONE (https://bugbounty.bi.zone/companies/ozon/main) - Security contact: security-report@ozon.ru - Domain: TLS 1.3, SPF + DMARC (quarantine) present, CAA present, DNSSEC absent ## Notes - Endpoints are POST-only; GET returns HTTP 405. - The documentation host applies edge bot-protection; some pages require a browser.