Shipping: creates or replaces the merchant's binding for one provider.
PUT
/api/merchants/{id}/shipping-bindings/{providerName}
deprecated
Requires: Merchants.Merchants.Update, merchant scope.
Example body for a merchant on its own carrier account: ``` { "isEnabled": true, "credentialSource": "Merchant", "fieldValues": [ { "key": "WinkPG.ShippingRates.Shippo.ApiToken", "value": "…" }, { "key": "WinkPG.ShippingRates.Shippo.CarrierAccountFilter", "value": "ca_abc123" } ] } ``` For a provider the gateway holds the account for, send `"credentialSource": "Gateway"` and no field values at all: the gateway's own credentials are resolved at quote time and are never copied onto the merchant. Omitting a secret keeps the value already stored, which is what a caller that read the binding first will naturally send, because reads never return one. Optionally send `If-Match: "<concurrencyStamp>"` for optimistic concurrency (409 on a stale stamp).
Example request
Every block below sends the same request. Replace {{BASE_URL}} with the address of the API you are calling and {{API_KEY}} with your own key.
The request body is a MerchantShippingBinding. See the Request body section below for its fields.
Parameters
| Name | In | Type | Description |
|---|---|---|---|
id
required |
path | string (uuid) | The merchant id. |
providerName
required |
path | string | The provider to bind (authoritative; any provider on the body is ignored). |
suppressNulls
required |
query | boolean | If true, omit properties with null values. |
Request body
application/json
, required
| Field | Type | Description |
|---|---|---|
providerName
required |
string | Which shipping provider this entry binds the merchant to, by the provider's registered name. Compared case-insensitively. A null or blank provider is treated as no binding at all, so an incompletely boarded row cannot silently become a live selection. Required: When IsEnabled is true. nullablemax length 64 |
isEnabled
required |
boolean | Master enable flag for this provider on this merchant. When `false` or null, the selector must not return this binding even though the row exists. nullable |
credentialSource
required |
all of ProviderCredentialSource | Whose provider account the quotes are billed to. Null reads as `Gateway`. nullable |
fieldValues
required |
array of ShippingBindingFieldValue | The provider-declared configuration values for this merchant, keyed by the setting names the provider declares. For a provider whose gateway credentials are platform-wide settings, the keys are those same setting names, so one name identifies a credential whoever holds it. <b>Secret values are stored encrypted</b> and are stripped, not decrypted, on every read that leaves the server: the admin UI and the API both see null and re-send a secret only when the operator changes it. Only the server-side call to the provider ever uses the plaintext. Empty for a `Gateway` binding, whose values are filled in at read time from the host-scoped provider settings instead. A gateway-sourced row that carried values would be a copy of the gateway's token living on a merchant document. Conditional: When FieldValues is not null. nullable |
This request body has no documented fields.
Responses
200 OK
Body: MerchantShippingBinding
Each item has these fields.
| Field | Type | Description |
|---|---|---|
providerName
required |
string | Which shipping provider this entry binds the merchant to, by the provider's registered name. Compared case-insensitively. A null or blank provider is treated as no binding at all, so an incompletely boarded row cannot silently become a live selection. Required: When IsEnabled is true. nullablemax length 64 |
isEnabled
required |
boolean | Master enable flag for this provider on this merchant. When `false` or null, the selector must not return this binding even though the row exists. nullable |
credentialSource
required |
all of ProviderCredentialSource | Whose provider account the quotes are billed to. Null reads as `Gateway`. nullable |
fieldValues
required |
array of ShippingBindingFieldValue | The provider-declared configuration values for this merchant, keyed by the setting names the provider declares. For a provider whose gateway credentials are platform-wide settings, the keys are those same setting names, so one name identifies a credential whoever holds it. <b>Secret values are stored encrypted</b> and are stripped, not decrypted, on every read that leaves the server: the admin UI and the API both see null and re-send a secret only when the operator changes it. Only the server-side call to the provider ever uses the plaintext. Empty for a `Gateway` binding, whose values are filled in at read time from the host-scoped provider settings instead. A gateway-sourced row that carried values would be a copy of the gateway's token living on a merchant document. Conditional: When FieldValues is not null. nullable |
This response has no documented body fields.
403 Forbidden
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
401 Unauthorized
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
400 Bad Request
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
404 Not Found
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
501 Not Implemented
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
500 Internal Server Error
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
default The request failed. The body carries the standard error envelope: a machine-readable `error.code`, a human-readable `error.message`, and `error.validationErrors` when the failure was a validation rejection. See the error-code reference in this document's description for the values `error.code` can take.
Body: RemoteServiceErrorResponse
Each item has these fields.
| Field | Type | Description |
|---|---|---|
error
required |
RemoteServiceErrorInfo |
This response has no documented body fields.
429 The request was refused because a rate limit was exceeded. Wait at least the interval `Retry-After` names before retrying, then back off. Limits are tuned per deployment, so read the allowance from the response headers rather than assuming a fixed ceiling.
Body: RateLimitProblemDetails
Each item has these fields.
| Field | Type | Description |
|---|---|---|
type
required |
string | The problem type identifier. Always the same value: the failure is the status code itself, so there is no sub-type for a caller to branch on. nullable |
title
required |
string | A short, human-readable summary of the problem type. nullable |
status
required |
integer (int32) | The HTTP status code, repeated in the body as the problem-details format defines. |
detail
required |
string | A human-readable explanation of this occurrence of the problem. nullable |
retryAfterSeconds
required |
integer (int32) | How long to wait before retrying, in whole seconds, carrying the same figure as the `Retry-After` header. Always at least one: a value of zero would invite an immediate retry that is certain to be rejected again. |
This response has no documented body fields.
Errors
A failed request returns the platform error envelope. The
error reference lists every value
error.code can carry and shows the four response shapes.