API Documentation

The One Stop Shop BD REST API lets resellers with API-enabled plans sync product data — names, wholesale prices, stock, and images — into their own website automatically. All endpoints return JSON and require an active plan with API access.

Base URL: https://onestopsbd.shop/api/v1

Generate your key from My Account → API Access.

Authentication

Every request must include two headers:

X-API-KEY: osb_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
X-API-SECRET: your_secret_shown_once_at_generation

The secret is shown exactly once when you generate or regenerate your key — store it securely. Wholesale pricing in every response reflects your plan's product access automatically; products outside your plan return without wholesale fields.

Products

GET /api/v1/products

Returns a paginated product list.

ParamTypeDescription
categorystringFilter by category slug
qstringSearch product name/SKU
pageintPage number (default 1)
per_pageintResults per page, max 50 (default 20)
curl "https://onestopsbd.shop/api/v1/products?page=1" \
  -H "X-API-KEY: osb_xxx" \
  -H "X-API-SECRET: xxx"
{
  "success": true,
  "data": [
    {
      "id": 1,
      "name": "Premium Cotton T-Shirt",
      "slug": "premium-cotton-tshirt",
      "sku": "TSH-001",
      "wholesale_price": "350.00",
      "suggested_selling_price": "650.00",
      "stock_quantity": 500,
      "stock_status": "in_stock",
      "category_name": "Fashion & Apparel",
      "image": "https://onestopsbd.shop/uploads/products/abc123.jpg"
    }
  ],
  "meta": { "page": 1, "per_page": 20, "total": 42, "total_pages": 3 }
}
GET /api/v1/products/{id}

Returns full detail for a single product, including all images.

Categories

GET /api/v1/categories

Returns all active categories.

Stock

GET /api/v1/stock/{id}

Lightweight endpoint for polling stock levels without pulling the full product payload — useful for keeping "in stock" badges on your own site in sync.

Errors

Errors return a non-200 status with a consistent shape:

{ "success": false, "error": { "code": "unauthorized", "message": "Invalid API credentials." } }
StatusCodeMeaning
400bad_requestMissing or invalid parameter
401unauthorizedMissing/invalid API key or secret
403forbiddenPlan lacks API access, account inactive, or domain not allowed
404not_foundResource doesn't exist or isn't published
429rate_limitedDaily request limit reached

Rate Limits

Your daily request limit is set by your plan (see Plans). It resets at midnight server time (Asia/Dhaka). You can optionally restrict a key to specific domains from API Access.