The One Stop Shop BD REST API lets resellers with API-enabled plans sync product data — names, wholesale prices, stock, and images — into their own website automatically. All endpoints return JSON and require an active plan with API access.
Base URL: https://onestopsbd.shop/api/v1
Generate your key from My Account → API Access.
Every request must include two headers:
X-API-KEY: osb_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx X-API-SECRET: your_secret_shown_once_at_generation
The secret is shown exactly once when you generate or regenerate your key — store it securely. Wholesale pricing in every response reflects your plan's product access automatically; products outside your plan return without wholesale fields.
Returns a paginated product list.
| Param | Type | Description |
|---|---|---|
| category | string | Filter by category slug |
| q | string | Search product name/SKU |
| page | int | Page number (default 1) |
| per_page | int | Results per page, max 50 (default 20) |
curl "https://onestopsbd.shop/api/v1/products?page=1" \ -H "X-API-KEY: osb_xxx" \ -H "X-API-SECRET: xxx"
{
"success": true,
"data": [
{
"id": 1,
"name": "Premium Cotton T-Shirt",
"slug": "premium-cotton-tshirt",
"sku": "TSH-001",
"wholesale_price": "350.00",
"suggested_selling_price": "650.00",
"stock_quantity": 500,
"stock_status": "in_stock",
"category_name": "Fashion & Apparel",
"image": "https://onestopsbd.shop/uploads/products/abc123.jpg"
}
],
"meta": { "page": 1, "per_page": 20, "total": 42, "total_pages": 3 }
}
Returns full detail for a single product, including all images.
Returns all active categories.
Full-text search across product name and short description. Supports the same pagination params as Products.
Lightweight endpoint for polling stock levels without pulling the full product payload — useful for keeping "in stock" badges on your own site in sync.
List endpoints return a meta object alongside data: page, per_page, total, and total_pages. Request the next page with ?page=2.
Errors return a non-200 status with a consistent shape:
{ "success": false, "error": { "code": "unauthorized", "message": "Invalid API credentials." } }
| Status | Code | Meaning |
|---|---|---|
| 400 | bad_request | Missing or invalid parameter |
| 401 | unauthorized | Missing/invalid API key or secret |
| 403 | forbidden | Plan lacks API access, account inactive, or domain not allowed |
| 404 | not_found | Resource doesn't exist or isn't published |
| 429 | rate_limited | Daily request limit reached |
Your daily request limit is set by your plan (see Plans). It resets at midnight server time (Asia/Dhaka). You can optionally restrict a key to specific domains from API Access.