openapi: 3.0.3 info: title: SPOD (Spreadconnect) Fulfillment REST Articles Subscriptions API version: '1.0' description: REST API for SPOD (Spreadshirt Print-On-Demand), now branded Spreadconnect. Create customizable articles from designs, place and manage print-on-demand orders, choose shipping types and track shipments, browse the catalog of product types, check stock, and subscribe to webhook notifications for article, order, and shipment events. All requests are authenticated with a per-account API access token sent in the X-SPOD-ACCESS-TOKEN header. This document is an API Evangelist reference grounded in SPOD's published OpenAPI and developer documentation; verify request/response schemas against the live docs before production use. contact: name: SPOD url: https://www.spod.com email: business@spod.com termsOfService: https://faq.spod.com/hc/en-us/articles/360020630280 servers: - url: https://rest.spod.com description: Production - url: https://rest.spreadconnect-staging.app description: Staging / test environment security: - access_token: [] tags: - name: Subscriptions paths: /subscriptions: get: tags: - Subscriptions operationId: getSubscriptions summary: List subscriptions description: List the account's active webhook subscriptions. responses: '200': description: A list of subscriptions. post: tags: - Subscriptions operationId: createSubscription summary: Create a subscription description: Register a webhook subscription. Notifications are delivered by POST following an at-least-once model and must be acknowledged with a 202 status, a response within 8 seconds, and the payload [accepted]. If a secret is set, notifications carry an X-SPRD-SIGNATURE header (a Base64 SHA256 HMAC over the request body) for authenticity verification. requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/SubscriptionRequest' responses: '201': description: The created subscription. /subscriptions/{subscriptionId}: delete: tags: - Subscriptions operationId: deleteSubscription summary: Delete a subscription parameters: - name: subscriptionId in: path required: true schema: type: integer responses: '204': description: Subscription deleted. /orders/{orderId}/simulate/order-cancelled: post: tags: - Subscriptions operationId: simulateOrderCancelledEvent summary: Simulate an Order.cancelled event description: Trigger a test Order.cancelled webhook notification for the given order (test/staging use). parameters: - $ref: '#/components/parameters/OrderId' responses: '200': description: Simulated event dispatched. /orders/{orderId}/simulate/order-processed: post: tags: - Subscriptions operationId: simulateOrderProcessedEvent summary: Simulate an Order.processed event description: Trigger a test Order.processed webhook notification for the given order (test/staging use). parameters: - $ref: '#/components/parameters/OrderId' responses: '200': description: Simulated event dispatched. /orders/{orderId}/simulate/shipment-sent: post: tags: - Subscriptions operationId: simulateShipmentSentEvent summary: Simulate a Shipment.sent event description: Trigger a test Shipment.sent webhook notification for the given order (test/staging use). parameters: - $ref: '#/components/parameters/OrderId' responses: '200': description: Simulated event dispatched. components: schemas: SubscriptionRequest: type: object description: Webhook subscription payload. properties: eventType: type: string description: The event to subscribe to (for example Article.added, Order.processed, Order.cancelled, Shipment.sent). url: type: string format: uri description: The endpoint that will receive POST notifications. secret: type: string description: Optional secret used to compute the X-SPRD-SIGNATURE HMAC. parameters: OrderId: name: orderId in: path required: true schema: type: integer securitySchemes: access_token: type: apiKey in: header name: X-SPOD-ACCESS-TOKEN description: Per-account API access token generated in the SPOD / Spreadconnect web application. Send it as a header on every request.