Docs · HTTP API
REFERENCE

HTTP API

Every endpoint, header, response shape and error code of /api/sdk/v1.

@dakio/sdk wraps this API; you can call it directly from any language.

bash
curl https://dakio-api-production.up.railway.app/api/sdk/v1/products?limit=2 \
  -H "Dakio-Key: dk_pub_test_…"

Basics

Base URLhttps://dakio-api-production.up.railway.app/api/sdk/v1
AuthDakio-Key: dk_… or Authorization: Bearer dk_…
BodyJSON, with Content-Type: application/json
Success{ "data": … } — except GET /products and GET /orders, which answer the page object { data, page, limit, total, totalPages }
Error{ "error": { "code": "OUT_OF_STOCK", "message": "…" } }
WritesIdempotency-Key (8–200 characters) on POST /checkout and /checkout/verify-otp: the same key replays the first success
CORSBrowsers may call it from your allowed websites (client keys); secret keys are refused from browsers
Versioningv1 only adds fields; nothing is renamed or removed. A breaking change would be /api/sdk/v2.

Endpoints

Method & pathKeyWhat it does
GET /storeanyThe store's brand, contact, delivery rates, banner, Pixel/GTM ids
GET /categoriesanyFlat list with parentId and productCount
GET /productsany?category, search, ids (comma-separated), page, limit (≤100), sort
GET /products/:idOrSluganyOne published product, 404 otherwise
GET /shippingany?district → { district, zone, charge, currency }; without it, both zones
POST /cart/quoteany{ items, couponCode?, district? } → the priced bag
POST /coupons/validateany{ code, subtotal } → { valid, reason, discount, coupon }
POST /checkoutany*Place a COD order → 201 PLACED or 202 OTP_REQUIRED
POST /checkout/verify-otpany*{ sessionToken, otp } → 201
POST /leadsany*An abandoned cart
POST /account/otpany*{ phone } → { sessionToken, expiresAt }
POST /account/ordersany*{ sessionToken, otp } → the phone's last 10 orders
GET /orders/trackany?orderNumber & phone → status and timeline, 404 when no match
POST /visitsany{ sessionId, page } — the live-visitors count
GET /orderssecret?page, limit, createdSince, updatedSince, phone
GET /orders/:idOrNumbersecretOne order
GET /webhookslive secretThe store's webhooks
POST /webhookslive secret{ url, events, description? } → with its signing secret, once
DELETE /webhooks/:idlive secretRemove one

* From a server these need a secret key plus Dakio-Buyer-Ip (and ideally Dakio-Buyer-Agent) — see Secret keys. The SDK refuses them on a server with a client key.

Checkout body

json
{
  "customer": { "name": "Rahim", "phone": "01712345678", "address": "House 4, Road 2", "district": "Dhaka", "city": "Mirpur", "email": null },
  "items": [{ "productId": "cm…", "variantId": null, "qty": 2 }],
  "couponCode": "EID10",
  "note": "Call after 5pm",
  "eventId": "pur_…"
}

201 → { "data": { "orderNumber": "#ABC-1234", "orderId": "cm…", "total": 1060 } }. 202 → { "data": { "status": "OTP_REQUIRED", "sessionToken": "…", "maskedPhone": "01*******78", "expiresAt": "…" } }. Test keys add "test": true. Up to 50 lines, quantities 1–999.

Error codes

HTTPcodeMeaning
401KEY_MISSING · INVALID_KEY · KEY_REVOKEDNo key, not a Dakio key, or revoked
403ORIGIN_NOT_ALLOWEDA browser on a website not in the live key's list
403SECRET_KEY_IN_BROWSERA secret key sent from a browser — revoke it
403SECRET_KEY_REQUIRED · LIVE_KEY_REQUIREDThis route needs a (live) secret key
403STORE_CLOSED · STORE_NOT_TAKING_ORDERSStore switched off, or its plan can't take orders now
400INVALID_PARAM · INVALID_INPUT · EMPTY_CARTBad query or body
400BUYER_IP_REQUIRED · INVALID_BUYER_IPServer call without a usable Dakio-Buyer-Ip
400INVALID_PHONE · DISTRICT_REQUIRED · CITY_REQUIREDCheckout address
400OUT_OF_STOCK · OPTION_REQUIRED · NOT_AVAILABLE · PRICE_CHANGED · COUPON_UNAVAILABLEBag problems; productId when it's one product
400OTP_INCORRECT (attemptsLeft) · SESSION_NOT_FOUNDThe code step
404NOT_FOUNDNo such product, order or endpoint
409IDEMPOTENCY_IN_PROGRESS · SESSION_USEDSame Idempotency-Key still running; code already used
410OTP_EXPIREDAsk for a new code
429RATE_LIMITED · TOO_MANY_ATTEMPTSSlow down; see Retry-After
5xxSERVER_ERRORRetry with the same Idempotency-Key

Rate limits are on the Keys page.

Something unclear or wrong? Tell us — or open an issue on GitHub.

CHECKOUT PAYMENTS · VERIFIED BY SSLCOMMERZ
Pay with Visa, Mastercard, bKash, Nagad, Rocket and 40+ methods — verified by SSLCommerzPay with Visa, Mastercard, bKash, Nagad, Rocket and 40+ methods — verified by SSLCommerz
© 2026 Dakio by Digidhaka Communication Limited. All rights reserved.
Trade License No. TRAD/DSCC/041467/2021 · Made for Bangladesh's entrepreneurs