xoPort REST API v2.122.6 – JSON Interface

REST · OAuth2 · JSON · v2.122.6

xoPort REST API

The modern JSON interface for automated store integrations. Export, import, and delete data securely via OAuth2 (RFC 6749).

GET  /Export/JSON/{entity}
POST /Import/JSON/{entity}
PUT  /Import/JSON/{entity}
DELETE /Delete/JSON/{entity}
Note: The xoPort REST API is part of the paid add-on module XONIC Premium: xoPort Data Interface.
v2.122.6Current Version
OAuth2RFC 6749 compliant
RESTPOST/PUT/DELETE
JSONRequest & Response

API Sections

The xoPort REST API is divided into four main areas:

Export API

Retrieve data from the store: products, categories, customers, orders, news, and more.

  • GET /Export/JSON/{entity}
  • Scope: entity:read
Export API →

Import API

Create and update data in the store. Since v2.1.0, with RESTful POST/PUT separation.

  • POST /Import/JSON/{entity} = INSERT
  • PUT /Import/JSON/{entity} = UPDATE
  • Scope: entity:write
Import API →

Delete API

Permanently delete records from the store. Security prompt via scope permission.

  • DELETE /Delete/JSON/{entity}/{id}
  • Scope: entity:delete
Delete API →

OAuth2 Authentication

Client Credentials Flow (RFC 6749) with fine-grained scopes per entity and operation.

  • POST /oauth/token
  • Grant Type: client_credentials
OAuth2 Clients →

Quick Start

3 steps to your first API request:

1

Create an OAuth2 client

In the backend, go to Settings → xoPort → OAuth2 Clients and create a new API access with the required scopes.

2

Get an access token

POST /oauth/token Use client_id and client_secret. The token is valid for 1 hour.

3

Send API requests

Authorization: Bearer {token} Include the header in all requests.

Example: Export categories

# 1. Token holen
TOKEN=$(curl -s -X POST "https://shop.de/xpanel/xoport/oauth/token" \
  -d "grant_type=client_credentials" \
  -d "client_id=xoc_xxx" \
  -d "client_secret=xos_xxx" | jq -r '.access_token')

# 2. Kategorien exportieren
curl -s "https://shop.de/xpanel/xoport/Export/JSON/categories" \
  -H "Authorization: Bearer $TOKEN" | jq .

Get started

Create your first OAuth2 client and integrate your systems.

Create an OAuth2 client

xoPort JSON API – The Modern Store Interface

The xoPort JSON API enables developers and system integrators to programmatically access all relevant store data from the XONIC Shop System. With the current version 2.122.6, the API not only offers export, import, and secure DELETE operations, but also OAuth2 Client Credentials Grant according to RFC 6749 for maximum security in server-to-server communication.

Why the xoPort JSON API?

xoPort is based on open standards: RESTful HTTP methods, JSON payloads, and OAuth2 authentication with granular scopes. This ensures maximum compatibility with common programming languages and frameworks—and meets modern security requirements.

Typical Use Cases

  • ERP integration – Automatic product synchronization with inventory management systems
  • Marketplace integration – Synchronization with Amazon, eBay, and Idealo
  • PIM systems – Centralized product data management
  • Business Intelligence – Data export for analytics and reporting
  • Automation – CI/CD pipelines for content updates
  • Newsletter Management – Subscriber and campaign management via API
  • Ticket system – Create, update, and manage support tickets via API

OAuth2 in 3 Steps

  1. Create a client: In the backend under Tools → xoPort OAuth Clients
  2. Request a token: Send a POST request to /xpanel/xoport/oauth/token
  3. Use the API: Include the token in the header Authorization: Bearer TOKEN