Skip to content
Integrations

A documented API, signed webhooks, and a database of your own.

Vendor Loyalty is a standalone API. It connects natively to Vendor Standard, and any till, web shop, app or ERP that can make an HTTPS request can earn, redeem and react to changes.

Loyalty breaks at the seams between systems.

The points engine is rarely the problem. The trouble is the shop that missed an update, the retry that awarded twice, the key that could do too much. Integration needs to be designed in, not added later.

  • REST API with an OpenAPI 3.1 specificationEvery endpoint is documented and browsable, with Postman collections and a TypeScript SDK. Every response has the same shape and a request ID for support.
  • Signed webhooksPoints, tier, member, membership and programme events are delivered with an HMAC-SHA256 signature. Failed deliveries are retried with increasing delays and can be replayed from the dashboard.
  • Secret rotation without downtimeRoll a webhook secret and both the old and new signatures are sent for 24 hours while you update your receiver.
  • Keys that do only what they needCreate API keys with exactly the permissions a system needs, such as read-only for an app or points-only for a till, with an optional expiry date. Keys are shown once.
  • Built to be retriedIdempotency keys on every points write, clear error codes, rate-limit headers and a Retry-After on 429.
  • Programme config with cachingShops download tiers, memberships, campaigns and branding once and refresh only when told, using ETags and a program.updated webhook.
  • Your brand, your domainEach brand gets its own database, its own credentials and its own domain with TLS. Members only see your name.
  • Move from WooCommerce Points & RewardsExisting balances and history are imported as they are, and a tested playbook covers the switch-over. Bebe Home moved this way, online and in stores.

Connected, and safe to retry.

Signed webhooks with replay.

See every delivery, retry failures and roll secrets without downtime.

A key per system.

Each key carries only the permissions that system needs.

What your team sees.

  • Webhooks: endpoints, chosen events, failure counts, recent deliveries and replay
  • Roll a signing secret and reactivate a disabled endpoint
  • API keys with permissions, last used and expiry
  • Team admins invited by email, each with their own permissions
For developers

After 50 consecutive failures an endpoint is paused so it does not flood your logs; reactivate it from the dashboard. Webhook URLs pointing at private networks are refused.

request.httpHTTP
1points.awarded points.deducted points.adjusted
2points.expired points.promoted points.reversed
3tier.changed
4member.created member.updated member.merged
5member.anonymized member.segments_changed
6membership.granted membership.revoked
7program.updated

Who it helps.

  • DevelopersA predictable API with a spec, an SDK and no surprises on retry.
  • SecurityPer-brand databases, scoped keys, signed events and audit trails.
  • IT leadsNo lock-in to our shop. Use it with what you already run.

At a glance.

API
REST /api/v1, OpenAPI 3.1, TypeScript SDK, Postman
Auth
API keys with 12 permissions; Cognito sign-in for staff
Rate limit
300 requests per minute per key
Webhooks
HMAC-SHA256, retries at 30 s, 2 min, 5 min, 15 min, replay
Hosting
AWS eu-central-1, one PostgreSQL database per brand
Native
Vendor Standard checkout

Integrations questions.

No. Any system that can call an HTTPS API can use Vendor Loyalty.

See it with your own programme.

Tell us about your members, your tills and your shop, and we’ll show you where Vendor Loyalty fits.

Ready to get started?

Launch a store yourself, or talk to us about connecting ecommerce to the systems you already run.

  • Vendor Standard

    Everything you need to launch, manage and grow an online store. From €39/month.

    Explore Commerce
  • Vendor Pro

    Larger catalogs, advanced pricing, complex operations and deeper integrations.

    Explore Scale