Skip to content
TUMR DOCS
Docsapi referenceDistribution API and webhooks

Distribution API and webhooks

Organization scoped keys, idempotent draft provisioning, domains and webhook delivery.

An owner or admin creates a scoped key at POST /console/distribution/api-keys/; the secret is shown once. Key management itself always requires a signed-in user.

  • GET, POST /console/distribution/domains/: namespace inventory and registration. Verification requires DNS ownership, wildcard routing and certificate delegation.
  • GET /console/distribution/domains/{id}/, POST /console/distribution/domains/{id}/verify/: namespace state.
  • POST /console/distribution/stores/: create a restricted client store. Send a stable idempotency_key per logical request.
  • GET /console/distribution/stores/{id}/: claim, license and publish readiness.
  • POST /console/distribution/licenses/quote/ and POST /console/distribution/licenses/allocate/: preview and allocate eligible client plan capacity through the console user credential.
  • GET, POST /console/distribution/webhooks/: signed webhook destinations.
  • GET /console/distribution/webhooks/deliveries/: delivery history.
{ "namespace_id": "VERIFIED_NAMESPACE_UUID", "slug": "client-shop", "business_name": "Client Shop", "owner_email": "[email protected]", "plan_intent": "starter", "idempotency_key": "client-shop-2026-10-10" }

The store response has a provisioning request ID. Poll GET /console/distribution/stores/{id}/ to inspect claim, license and publication gates. Use a new idempotency key for a different logical store; a replay with changed data returns 409.

Each key has explicit distribution:* scopes and is bound to one organization. A key cannot bypass the merchant claim, paid license or publish gates. Webhook deliveries are at least once: deduplicate by event ID. Verify X-Tumr-Signature against the raw request body using the endpoint secret and timestamp.