Queek docs
Storefront endpoint reference

Phone

POST
/auth/phone/request-otp

Sends a one-time code to the shopper’s phone for sign-in or registration.

Authorization

clientKey
X-Client-Key<token>

The store's API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.

In: header

Header Parameters

X-Client-Key*string

Your store API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.

X-Request-Id?string

Your own correlation id (8–128 chars, ^[A-Za-z0-9_.:-]+$). Echoed back on the response and on every log line of the request; one is generated when you omit it.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/auth/phone/request-otp" \  -H "X-Client-Key: {{clientKey}}" \  -H "Content-Type: application/json" \  -d '{    "phone": "+2348031234567",    "country_code": "NG",    "channel": "whatsapp"  }'
{  "status": "success",  "message": "OTP requested",  "data": {    "phone": "+2348031234567",    "next_action": "verify_otp",    "user_exists": true,    "expires_in": 300,    "resend_in": 60  }}
POST
/auth/phone/verify-otp

Verifies the phone code and signs the customer in, returning the session tokens.

Authorization

clientKey
X-Client-Key<token>

The store's API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.

In: header

Header Parameters

X-Client-Key*string

Your store API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.

X-Request-Id?string

Your own correlation id (8–128 chars, ^[A-Za-z0-9_.:-]+$). Echoed back on the response and on every log line of the request; one is generated when you omit it.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/auth/phone/verify-otp" \  -H "X-Client-Key: {{clientKey}}" \  -H "Content-Type: application/json" \  -d '{    "phone": "+2348031234567",    "country_code": "NG",    "otp_code": "482917"  }'
{  "status": "success",  "message": "Phone verified",  "data": {    "token": "cli_5f2c9b3e8a7d6c1b4a0e9f8d7c6b5a4e3",    "access_token": "cli_5f2c9b3e8a7d6c1b4a0e9f8d7c6b5a4e3",    "refresh_token": "clr_9a1b2c3d4e5f60718293a4b5c6d7e8f9",    "token_type": "Bearer",    "expires_in": 3600,    "expires_at": "2026-09-25T16:58:00+01:00",    "refresh_expires_in": 2592000,    "refresh_expires_at": "2026-10-25T15:58:00+01:00",    "platform": "client_web",    "user": {      "id": "019b0c4d-5e6f-7a8b-9c0d-1e2f3a4b5c51",      "name": "Adaeze Okafor",      "email": "[email protected]",      "phone": "+2348031234567",      "avatar": "https://media.usequeek.com/uploads/avatars/adaeze-okafor.jpg",      "country": "Nigeria",      "state": "Lagos",      "region": null,      "city": "Lekki",      "address": "4B Adebayo Doherty Road, Lekki Phase 1, Lagos",      "map_lat": "6.4474000",      "map_lng": "3.4712000",      "is_rider": false,      "rider_approved": false,      "profile_complete": true    }  }}
POST
/auth/register

Registers a new customer with a verified phone number.

Authorization

clientKey
X-Client-Key<token>

The store's API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.

In: header

Header Parameters

X-Client-Key*string

Your store API key (Dashboard → Settings → API keys). pk_live_… public keys are for browser code and only work from an origin on the key's allowlist; sk_live_… private keys are for servers and native apps and need no Origin.

X-Request-Id?string

Your own correlation id (8–128 chars, ^[A-Za-z0-9_.:-]+$). Echoed back on the response and on every log line of the request; one is generated when you omit it.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/auth/register" \  -H "X-Client-Key: {{clientKey}}" \  -H "Content-Type: application/json" \  -d '{    "first_name": "Adaeze",    "last_name": "Okafor",    "email": "[email protected]",    "phone": "+2348031234567",    "country_code": "NG",    "otp_code": "482917"  }'
{  "status": "success",  "message": "Account created",  "data": {    "token": "cli_5f2c9b3e8a7d6c1b4a0e9f8d7c6b5a4e3",    "access_token": "cli_5f2c9b3e8a7d6c1b4a0e9f8d7c6b5a4e3",    "refresh_token": "clr_9a1b2c3d4e5f60718293a4b5c6d7e8f9",    "token_type": "Bearer",    "expires_in": 3600,    "expires_at": "2026-09-25T16:58:00+01:00",    "refresh_expires_in": 2592000,    "refresh_expires_at": "2026-10-25T15:58:00+01:00",    "platform": "client_web",    "user": {      "id": "019b0c4d-5e6f-7a8b-9c0d-1e2f3a4b5c51",      "name": "Adaeze Okafor",      "email": "[email protected]",      "phone": "+2348031234567",      "avatar": "https://media.usequeek.com/uploads/avatars/adaeze-okafor.jpg",      "country": "Nigeria",      "state": "Lagos",      "region": null,      "city": "Lekki",      "address": "4B Adebayo Doherty Road, Lekki Phase 1, Lagos",      "map_lat": "6.4474000",      "map_lng": "3.4712000",      "is_rider": false,      "rider_approved": false,      "profile_complete": true    }  }}