Headers
All the Shopfront APIs return and accept JSON data (with the exception of the Embedded API which passes literal JavaScript Objects).
Therefore we would highly suggest setting the Content-Type and Accept headers to application/json.
For additional assistance and easier tracking, we'd highly recommend specifying the User-Agent header.
To be properly authenticated we require the use of the Authorization header. To set the header you must use the
term Bearer followed by your access_token.
Here's an example using these headers:
Authorization: Bearer abcde
Content-Type: application/json
Accept: application/json
User-Agent: MyShopfrontClient/1.0
Special Headers
In addition to the above headers, Shopfront supports some additional headers which can change the functionality of the API.
Idempotent Headers
Shopfront supports request idempotency using the X-Idempotent-Id header. For details on how to use this header,
please see the Idempotency Guide.
Feature Flag Headers
From time-to-time, Shopfront may introduce new features or functionality which changes the overall behaviour of an API. These let you opt-in or opt-out of functionality, typically these are used to test functionality before it becomes the default.
Field-Level Validation
We're introducing field-level validation to our GraphQL API which occurs before the request is processed (during the parsing stage of the query).
To opt in to the field-level validation, please set the X-GraphQL-Validate-Variables header to true.
For more information about field-level validation, please check out the details on the GraphQL getting started page.