Queek docs
Storefront endpoint reference

Account

POST
/auth/token/refresh

Mints a fresh access token from a refresh token.

Authorization

clientKey
X-Client-Key<token>

The store's API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.

In: header

Header Parameters

X-Client-Key*string

Your store API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.

X-Request-Id?string

Your own correlation id (8–128 chars, ^[A-Za-z0-9_.:-]+$). Echoed back on the response and on every log line of the request; one is generated when you omit it.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/auth/token/refresh" \  -H "X-Client-Key: {{clientKey}}" \  -H "Content-Type: application/json" \  -d '{    "refresh_token": "clr_9a1b2c3d4e5f60718293a4b5c6d7e8f9"  }'
{  "status": "success",  "message": "Token refreshed",  "data": {    "token": "cli_5f2c9b3e8a7d6c1b4a0e9f8d7c6b5a4e3",    "access_token": "cli_5f2c9b3e8a7d6c1b4a0e9f8d7c6b5a4e3",    "refresh_token": "clr_9a1b2c3d4e5f60718293a4b5c6d7e8f9",    "token_type": "Bearer",    "expires_in": 3600,    "expires_at": "2026-09-25T16:58:00+01:00",    "refresh_expires_in": 2592000,    "refresh_expires_at": "2026-10-25T15:58:00+01:00",    "platform": "client_web",    "user": {      "id": "019b0c4d-5e6f-7a8b-9c0d-1e2f3a4b5c51",      "name": "Adaeze Okafor",      "email": "[email protected]",      "phone": "+2348031234567",      "avatar": "https://media.usequeek.com/uploads/avatars/adaeze-okafor.jpg",      "country": "Nigeria",      "state": "Lagos",      "region": null,      "city": "Lekki",      "address": "4B Adebayo Doherty Road, Lekki Phase 1, Lagos",      "map_lat": "6.4474000",      "map_lng": "3.4712000",      "is_rider": false,      "rider_approved": false,      "profile_complete": true    }  }}
GET
/auth/me

Returns the signed-in customer’s account. Needs the customer bearer bound to this store in addition to the key.

Authorization

clientKey customerToken
X-Client-Key<token>

The store's API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.

In: header

AuthorizationBearer <token>

The customer access credential from any sign-in session answer (access_token). Account operations only — send as Authorization: Bearer <access_token> ALONGSIDE X-Client-Key. It is bound to one store: a credential issued for another vendor answers 403 here.

In: header

Header Parameters

X-Client-Key*string

Your store API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.

X-Request-Id?string

Your own correlation id (8–128 chars, ^[A-Za-z0-9_.:-]+$). Echoed back on the response and on every log line of the request; one is generated when you omit it.

Response Body

application/json

application/json

application/json

application/json

curl -X GET "https://example.com/auth/me" \  -H "X-Client-Key: {{clientKey}}"
{  "status": "success",  "message": "Authenticated",  "data": {    "user": {      "id": "019b0c4d-5e6f-7a8b-9c0d-1e2f3a4b5c51",      "name": "Adaeze Okafor",      "email": "[email protected]",      "phone": "+2348031234567",      "avatar": "https://media.usequeek.com/uploads/avatars/adaeze-okafor.jpg",      "country": "Nigeria",      "state": "Lagos",      "region": null,      "city": "Lekki",      "address": "4B Adebayo Doherty Road, Lekki Phase 1, Lagos",      "map_lat": "6.4474000",      "map_lng": "3.4712000",      "is_rider": false,      "rider_approved": false,      "profile_complete": true    }  }}
PATCH
/auth/me

Updates the signed-in customer’s profile.

Authorization

clientKey customerToken
X-Client-Key<token>

The store's API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.

In: header

AuthorizationBearer <token>

The customer access credential from any sign-in session answer (access_token). Account operations only — send as Authorization: Bearer <access_token> ALONGSIDE X-Client-Key. It is bound to one store: a credential issued for another vendor answers 403 here.

In: header

Header Parameters

X-Client-Key*string

Your store API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.

X-Request-Id?string

Your own correlation id (8–128 chars, ^[A-Za-z0-9_.:-]+$). Echoed back on the response and on every log line of the request; one is generated when you omit it.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

curl -X PATCH "https://example.com/auth/me" \  -H "X-Client-Key: {{clientKey}}" \  -H "Content-Type: application/json" \  -d '{    "name": "Adaeze Okafor",    "phone": "+2348031234567",    "city": "Lekki",    "address": "4B Adebayo Doherty Road, Lekki Phase 1, Lagos"  }'
{  "status": "success",  "message": "Profile updated",  "data": {    "user": {      "id": "019b0c4d-5e6f-7a8b-9c0d-1e2f3a4b5c51",      "name": "Adaeze Okafor",      "email": "[email protected]",      "phone": "+2348031234567",      "avatar": "https://media.usequeek.com/uploads/avatars/adaeze-okafor.jpg",      "country": "Nigeria",      "state": "Lagos",      "region": null,      "city": "Lekki",      "address": "4B Adebayo Doherty Road, Lekki Phase 1, Lagos",      "map_lat": "6.4474000",      "map_lng": "3.4712000",      "is_rider": false,      "rider_approved": false,      "profile_complete": true    }  }}
POST
/auth/logout

Signs out the customer on this device. Answers {status, message} (Logged out) with no data.

Authorization

clientKey customerToken
X-Client-Key<token>

The store's API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.

In: header

AuthorizationBearer <token>

The customer access credential from any sign-in session answer (access_token). Account operations only — send as Authorization: Bearer <access_token> ALONGSIDE X-Client-Key. It is bound to one store: a credential issued for another vendor answers 403 here.

In: header

Header Parameters

X-Client-Key*string

Your store API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.

X-Request-Id?string

Your own correlation id (8–128 chars, ^[A-Za-z0-9_.:-]+$). Echoed back on the response and on every log line of the request; one is generated when you omit it.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/auth/logout" \  -H "X-Client-Key: {{clientKey}}" \  -H "Content-Type: application/json" \  -d '{    "refresh_token": "clr_9a1b2c3d4e5f60718293a4b5c6d7e8f9"  }'
{  "status": "success",  "message": "Logged out"}