Queek docs
Merchant endpoint reference

Collections

GET
/collections

Requires scope merchant-collections-read.

Lists the store’s collections.

Authorization

merchantKey
X-Client-Key<token>

The store's private API key (sk_live_…, sk_test_… on a dev store) from Dashboard → Settings → API keys. It is bound to one store and carries the scopes the merchant granted; each operation names the scope it needs. Server-side only — never ship it to a browser or an app bundle.

In: header

Query Parameters

limit?|
Range1 <= value <= 100
starting_after?string|null
collection_mode?string|null
search?|
Lengthlength <= 255
sort_by?string|null
sort_order?|

Value in

  • "asc"
  • "desc"
  • null

Header Parameters

X-Client-Key*string

A private API key (sk_live_…, sk_test_… on a dev store) minted under Dashboard → Settings → API keys. The key is bound to ONE store, so no vendor header or vendor_id is sent; its scopes decide which operations it may call. pk_ public keys never reach this API. Keep it on your server.

X-Request-Id?string

Your own correlation id (8–128 chars, ^[A-Za-z0-9_.:-]+$). Echoed back on the response and on every log line of the request; one is generated when you omit it.

Response Body

application/json

application/json

application/json

application/json

application/json

curl -X GET "https://example.com/collections?limit=2&starting_after=eyJpZCI6MzEwOSwiX3BvaW50c1RvTmV4dEl0ZW1zIjp0cnVlfQ&collection_mode=all" \  -H "X-Client-Key: {{merchantKey}}"
{  "data": [    {      "id": 3108,      "uid": "019a1c10-2b4d-7e8f-9a01-3c5d7e9f1b21",      "name": "Party Packs",      "slug": "party-packs",      "description": "Trays that feed a crowd.",      "image": "https://media.usequeek.com/uploads/stores/1095/collections/party-packs.jpg",      "logo": null,      "featured": true,      "position": 1,      "collection_mode": "manual",      "parent_uid": null,      "products_count": 6,      "children": [],      "created_at": "2026-07-01T12:00:00+01:00",      "updated_at": "2026-09-20T09:15:00+01:00"    },    {      "id": 3109,      "uid": "019a1c10-2b4d-7e8f-9a01-3c5d7e9f1b22",      "name": "Drinks",      "slug": "drinks",      "description": "Chapman, zobo and fresh juices.",      "image": null,      "logo": null,      "featured": false,      "position": 2,      "collection_mode": "smart",      "parent_uid": null,      "products_count": 3,      "children": [],      "created_at": "2026-07-01T12:00:00+01:00",      "updated_at": "2026-09-20T09:15:00+01:00"    }  ],  "has_more": true,  "next_cursor": "eyJpZCI6MzEwOSwiX3BvaW50c1RvTmV4dEl0ZW1zIjp0cnVlfQ"}
POST
/collections/bulk

Requires scope merchant-collections-create.

Creates several collections in one call.

Authorization

merchantKey
X-Client-Key<token>

The store's private API key (sk_live_…, sk_test_… on a dev store) from Dashboard → Settings → API keys. It is bound to one store and carries the scopes the merchant granted; each operation names the scope it needs. Server-side only — never ship it to a browser or an app bundle.

In: header

Header Parameters

X-Client-Key*string

A private API key (sk_live_…, sk_test_… on a dev store) minted under Dashboard → Settings → API keys. The key is bound to ONE store, so no vendor header or vendor_id is sent; its scopes decide which operations it may call. pk_ public keys never reach this API. Keep it on your server.

X-Request-Id?string

Your own correlation id (8–128 chars, ^[A-Za-z0-9_.:-]+$). Echoed back on the response and on every log line of the request; one is generated when you omit it.

Idempotency-Key?string

Retry-safe write key. The same key with the same body replays the stored response for 24h with Idempotent-Replayed: true; with a different body it is 409 idempotency_key_reuse; while the first call is still running it is 409 idempotency_key_in_progress.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/collections/bulk" \  -H "X-Client-Key: {{merchantKey}}" \  -H "Content-Type: application/json" \  -d '{    "collections": [      {        "name": "Drinks",        "description": "Chapman, zobo and fresh juices.",        "collection_mode": "smart"      }    ]  }'
{  "data": [    {      "id": 3109,      "uid": "019a1c10-2b4d-7e8f-9a01-3c5d7e9f1b22",      "name": "Drinks",      "slug": "drinks",      "description": "Chapman, zobo and fresh juices.",      "image": null,      "logo": null,      "featured": false,      "position": 2,      "collection_mode": "smart",      "parent_uid": null,      "products_count": 3,      "children": [],      "created_at": "2026-07-01T12:00:00+01:00",      "updated_at": "2026-07-01T12:00:00+01:00"    }  ],  "success": true,  "message": "Collections created successfully"}
POST
/collections/{collection}/products/pin

Requires scope merchant-collections-update.

Pins a product to the top of a manual collection.

Authorization

merchantKey
X-Client-Key<token>

The store's private API key (sk_live_…, sk_test_… on a dev store) from Dashboard → Settings → API keys. It is bound to one store and carries the scopes the merchant granted; each operation names the scope it needs. Server-side only — never ship it to a browser or an app bundle.

In: header

Path Parameters

collection*string

Header Parameters

X-Client-Key*string

A private API key (sk_live_…, sk_test_… on a dev store) minted under Dashboard → Settings → API keys. The key is bound to ONE store, so no vendor header or vendor_id is sent; its scopes decide which operations it may call. pk_ public keys never reach this API. Keep it on your server.

X-Request-Id?string

Your own correlation id (8–128 chars, ^[A-Za-z0-9_.:-]+$). Echoed back on the response and on every log line of the request; one is generated when you omit it.

Idempotency-Key?string

Retry-safe write key. The same key with the same body replays the stored response for 24h with Idempotent-Replayed: true; with a different body it is 409 idempotency_key_reuse; while the first call is still running it is 409 idempotency_key_in_progress.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/collections/3108/products/pin" \  -H "X-Client-Key: {{merchantKey}}" \  -H "Content-Type: application/json" \  -d '{    "product_id": "019a1d52-3c8e-7f41-b0d2-6a3e9c1f4b21",    "pinned": true  }'
{  "status": "success",  "message": "Product pinned in collection.",  "data": {    "collection_id": "019a1c10-2b4d-7e8f-9a01-3c5d7e9f1b21",    "product_id": "019a1d52-3c8e-7f41-b0d2-6a3e9c1f4b21",    "pinned": true  }}
POST
/collections/{collection}/products/reorder

Requires scope merchant-collections-update.

Reorders the products of a manual collection.

Authorization

merchantKey
X-Client-Key<token>

The store's private API key (sk_live_…, sk_test_… on a dev store) from Dashboard → Settings → API keys. It is bound to one store and carries the scopes the merchant granted; each operation names the scope it needs. Server-side only — never ship it to a browser or an app bundle.

In: header

Path Parameters

collection*string

Header Parameters

X-Client-Key*string

A private API key (sk_live_…, sk_test_… on a dev store) minted under Dashboard → Settings → API keys. The key is bound to ONE store, so no vendor header or vendor_id is sent; its scopes decide which operations it may call. pk_ public keys never reach this API. Keep it on your server.

X-Request-Id?string

Your own correlation id (8–128 chars, ^[A-Za-z0-9_.:-]+$). Echoed back on the response and on every log line of the request; one is generated when you omit it.

Idempotency-Key?string

Retry-safe write key. The same key with the same body replays the stored response for 24h with Idempotent-Replayed: true; with a different body it is 409 idempotency_key_reuse; while the first call is still running it is 409 idempotency_key_in_progress.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/collections/3108/products/reorder" \  -H "X-Client-Key: {{merchantKey}}" \  -H "Content-Type: application/json" \  -d '{    "product_ids": [      "019a1d52-3c8e-7f41-b0d2-6a3e9c1f4b21",      "019a1d52-3c8e-7f41-b0d2-6a3e9c1f4b23"    ]  }'
{  "status": "success",  "message": "Collection products reordered successfully.",  "data": {    "collection_id": "019a1c10-2b4d-7e8f-9a01-3c5d7e9f1b21",    "ordered_count": 2  }}