SokoGrow

SokoGrow API for developers

Organisations get API keys with scopes and signed webhooks for their members' orders and listings. Test against the sandbox with fc_test_ keys before going live.

Download the OpenAPI 3.1 document · Create an API key in SokoGrow

Org-scoped access to listings, your members' orders and usage, plus signed webhooks. Authenticate with `X-Api-Key: fc_live_…` (production) or `fc_test_…` (the sandbox on staging). Money is always an integer string in minor units. Every key has scopes and a per-minute limit; every call is metered.

Endpoints

Webhooks and signatures

POSTed as JSON `{ id, type, createdAt, data }`. Verify `X-SokoGrow-Signature: t=<unix>,v1=<hex>` as HMAC-SHA256 of `<t>.<raw body>` with your endpoint secret, and reject timestamps older than 5 minutes. Answer 2xx within 10 s; failures are retried after 1 min, 5 min, 30 min, 2 h, 6 h, 12 h and 24 h. Deliveries can repeat: deduplicate by `id`. The same values are also sent under the legacy `X-FarmChat-*` header names for integrations built before the rename.