Export API: Retrieve Store Data Using GET

GET · Export · Read · v2.1.0

Export API

Export data from the store. Starting with v2.1.0, using RESTful URL paths: /categories/{id} returns the category itself.

GET /Export/JSON/categories      # All
GET /Export/JSON/categories/128  # ID 128
GET /Export/JSON/categories?id=128

RESTful URL paths (v2.1.0)

Intuitive resource addressing:

/categories/{id} = Single Resource

The category with this ID

GET /Export/JSON/categories/128
→ Category 128 ("xoPort REST API")

?parent_id={id} = Children

Children of the parent category

GET /Export/JSON/categories?parent_id=128
→ Subcategories of 128
Breaking Change v2.1.0: /categories/{id} previously returned the children. Now use ?parent_id={id} for children.

Categories Export

EndpointDescriptionExample
GET /categoriesAll CategoriesComplete category tree
GET /categories/{id}Single category/categories/128 → ID 128
GET /categories?id={id}Alternative to URL path?id=128
GET /categories?parent_id={id}Direct children?parent_id=128
GET /categories?parent_id={id}&recursive=1Complete subtreeAll descendants
GET /categories?status=1Active onlyFiltering
GET /categories?language=deGerman onlyLanguage filter
GET /categories/productlistLightweight: Category→Product Mapping NEW v2.12.0Per Category: IDs + Models
GET /categories/productlist?categories_id={id}Products in a Category?categories_id=73
Media NEW v2.16.0GET /Export/JSON/mediasmedia:read

Additional export endpoints

EntityAllSingleScope
Products SQL Pagination v2.12.0GET /productsGET /product/{id}products:read
CustomersGET /customersGET /customer/{id}customers:read
ManufacturersGET /manufacturersGET /manufacturer/{id}manufacturers:read
OrdersGET /ordersGET /order/{id}orders:read
Documentation NEW v2.61.0
PDF as content_base64 – can be used directly as a ticket attachment
–GET /order_document/{id}?type=rgorders:read
NewsGET /newsdesksGET /newsdesk/{id}news:read
News CategoriesGET /newsdeskcatsGET /newsdeskcat/{id}newscategories:read
FAQGET /faqsGET /faq/{id}faq:read
FAQ CategoriesGET /faqcatsGET /faqcat/{id}faqcategories:read
SEO HistoryGET /seohistorysGET /seohistory/{id}seohistory:read
ContractsGET /contractsGET /contracts/{id}contracts:read
Newsletter SubscribersGET /newsletter_subscribersGET /newsletter_subscriber/{id}newsletter:read
Newsletter CampaignsGET /newslettersGET /newsletter/{id}newsletters:read
Tickets CRUD v2.11.0
With claim and edit_lock (v2.118.0)
GET /ticketsGET /ticket/{id}tickets:read
Ticket Attachments
Write: attachments[] toPOST/PUT /Import/JSON/tickets (v2.60.0)
GET /ticket_attachments/{id}GET /ticket_attachment/{id}?file=nametickets:read
Slider NEW v2.22.0GET /slidersGET /slider/{id}slider:read
Projects (xoCRM) NEW v2.35.0GET /projectsGET /project/{id}projects:read
Project Tasks NEW v2.35.0GET /project_tasksGET /project_task/{id}project_tasks:read
Appointments (xoCRM) NEW v2.44.0GET /appointmentsGET /appointment/{id}appointments:read
Attributes & Option Values NEW v2.96.0GET /products_options
GET /products_options_values
GET /products_option/{id}products:read
Shipping Time Profiles NEW v2.94.0GET /shipping_profilesGET /shipping_profile/{id}products:read
Tax Classes NEW v2.90.0GET /tax_classesGET /tax_class/{id}products:read
Category Page Filters NEW v2.100.0GET /products_filtersGET /products_filter/{fid}products:read
Gift Cards & Coupons NEW v2.102.0GET /couponsGET /coupon/{id}orders:read
Ticket Departments NEW v2.103.0GET /ticket_departmentsGET /ticket_department/{id}tickets:read
Settings NEW v2.108.0GET /configuration–configuration:read
CSV/XLS Porter NEW v2.109.0GET /portersGET /porter/{id}porters:read
Reviews NEW v2.122.6GET /reviewsGET /review/{id}products:read

Product Reviews v2.122.6

The individual reviews on the product page, including star rating, title, text, and the store’s response for each language. Without a filter, the list shows only approved reviews—the same ones displayed on the product page. The individual query /review/{id} returns a review even before it has been approved.

ParametersEffectExample
products_idReviews for one or more items?products_id=104648,104650
status1 approved (default), 0 pending approval, all both?status=all
sinceCreated or last modified on or after?since=2026-10-05

Example – daily comparison, including withdrawn approvals:
GET /reviews?status=all&since=2026-10-05&limit=250&page=1

No customer data. "author " is the name displayed on the product page. The endpoint does not return the customer ID, email, or order number—only "verified_purchase " (a review associated with an order). Therefore, the "products:read" scope is sufficient. Deleted reviews no longer appear in the list. Anyone mirroring an inventory should therefore periodically synchronize all IDs.

Response Format

{
  "success": true,
  "api_version": "2.1.0",
  "type": "categories",
  "count": 1,
  "data": [
    {
      "categories_id": 128,
      "parent_id": 97,
      "status": 1,
      "languages": {
        "de": {
          "categories_name": "xoPort REST API",
          "categories_description": "..."
        }
      }
    }
  ],
  "timestamp": "2026-01-27 14:00:00"
}

Start Export

Create an OAuth2 client with :read scopes.

Create an OAuth2 client

Pagination v2.10.0

All export endpoints support pagination via query parameters:

ParameterDefaultMaxDescription
limit50250Maximum number of records per request
offset0—Starting position in the results

Example: GET /products?limit=50&offset=100

The response contains the following in the stats object:

  • count — Number of returned records
  • limit — Applied limit
  • offset — Applied offset
  • has_more — true if more records are available

Defaults can be configured via XOPORT_API_MAX_LIMIT and XOPORT_API_DEFAULT_LIMIT.


Product Filter v2.65.0

The product export can be limited on the server side instead of retrieving the entire catalog page by page. A comma separates an inclusion list (maximum of 100 values); multiple filters are combined with an "AND" operator.

ParametersEffectExample
statusItem status?status=1
tax_class_idTax Class?tax_class_id=0,1
categories_idItem is in one of the categories?categories_id=10039,10104
ean_prefixEAN starts with …?ean_prefix=978,979,977
model_prefixItem number starts with …?model_prefix=166-
last_modifiedLast modified on …?last_modified=2026-08-19

Example – all purchasable items with a book EAN that are not subject to the reduced tax rate:
GET /products?ean_prefix=978,979,977&tax_class_id=0,1&status=1&limit=250

stats.total refers to the number of results returned by the filter, not the total catalog size.

There is intentionally no “not equal to” operator. “Everything except tax class 2” is written as an inclusive list of the remaining classes (?tax_class_id=0,1). An invalid filter value is rejected with an HTTP 400 response and is not silently discarded—otherwise, the unfiltered catalog would be returned. Filters applied to a single resource (/products/{id}) or to an ID range are rejected for the same reason.

Secure API Authentication

The xoPort API uses a multi-layered security approach that supports both simple and highly secure authentication methods—ranging from an IP-based whitelist for internal servers to scope-restricted API keys for third-party integrations.

Best Practices

  • Use a separate API key for each integration
  • Limit scopes to the absolute minimum (Principle of Least Privilege)
  • Set expiration dates for temporary integrations
  • Monitor usage logs regularly
  • Rotate API keys periodically