Sign up
Developers

Reseller Fulfilment API

Auto-fulfil your shop's orders from fncrib stock. On each sale, your platform sends us the order and we return the product (account credentials / keys) to hand to your buyer, in real time.

POST/deliver HMAC-SHA256 signed Idempotent retries Plain-text response
On this page
  1. Your credentials
  2. Option A · SellAuth
  3. Option B · Custom
  4. POST/deliver
  5. Signing
  6. Response
  7. Errors
  8. Idempotency & retries
  9. Going live
Before you start

Two things we give you

From our dashboard, per reseller:

Delivery URL
https://fncrib.com/api/reseller/<your-token>/deliver
Webhook secret
<shared HMAC secret>
Used to sign/verify every request.

We also map each of your product IDs → our product on our side, and you keep a prepaid balance that's debited per fulfilment.

Option A No code

SellAuth

If your shop runs on SellAuth, there's nothing to build:

  1. 1Open the product → set Delivery type to Dynamic.
  2. 2Paste the Delivery URL above as the webhook URL.
  3. 3Paste the Webhook secret into Storefront → Configure → Miscellaneous.
  4. 4Tell us your SellAuth product IDs so we can map them to our products.

SellAuth signs and sends the request; we respond with the deliverable. Done.

Option B Any platform

Custom integration

Call our endpoint yourself on each paid order. It's one request/response.

Request

POSThttps://fncrib.com/api/reseller/<your-token>/deliver

Headers

HeaderValue
Content-Typeapplication/json
X-SignatureHex HMAC-SHA256 of the raw request body, keyed with your webhook secret.
Idempotency-KeyA stable id for this order-item. Re-send the same key on retries: you'll get the same deliverable back and are never charged twice.

Body (JSON)

JSONRequest body
{
  "unique_id": "INV-abc123",           // your order/invoice id (echoed back in our records)
  "email": "[email protected]",         // optional
  "item": {
    "id": 555,                          // your order-item id (optional)
    "product_id": "SA-PROD-1",          // YOUR product id — mapped to our product on our side
    "variant_id": null,                 // optional
    "quantity": 1                       // number of units to deliver
  }
}

Signing the request

Node.jsSign the exact bytes you send
// Node.js
const crypto = require('crypto');
const raw = JSON.stringify(payload);                    // sign the EXACT bytes you send
const signature = crypto.createHmac('sha256', WEBHOOK_SECRET).update(raw).digest('hex');
// then POST `raw` with headers: X-Signature: signature, Idempotency-Key: <stable id>
PHPSame signature in PHP
// PHP
$raw = json_encode($payload);
$signature = hash_hmac('sha256', $raw, $webhookSecret);

Response

On success: HTTP 200, body is plain text. Each line is one deliverable: for quantity: 2 you get two lines. Show these to your buyer.

HTTPSuccess, one line per deliverable
HTTP/1.1 200 OK
Content-Type: text/plain

buyer1login:buyer1pass
buyer2login:buyer2pass

Errors

Any non-200 means we did not deliver. The response body is a short, buyer-safe message you can display.

StatusMeaningRetry?
401Bad/missing signatureNoFix signing
402Your prepaid balance is exhaustedNoTop up with us
409Out of stock for that productNoWe restock
422Product not mapped on our sideNoSend us the product id
500 / 429 / 5xxTransient errorYesRetry (we're idempotent)
Reliability

Idempotency & retries

Always send a stable Idempotency-Key per order-item. If you retry (timeout, 5xx), we return the exact same credentials and never claim a second unit or debit your balance twice. SellAuth does this automatically (3 retries, 5s apart).

Timeouts: we answer from local stock in well under a second. If you build a custom caller, a 5s connect / 10s read timeout is plenty. On a network error, retry with the same idempotency key.

Checklist

Going live

  1. 1We create your reseller record → you receive your Delivery URL + secret.
  2. 2Send us your product IDs; we map them to our products. Each sale debits your prepaid balance by our product's price × quantity.
  3. 3You top up your prepaid balance with us.
  4. 4Configure SellAuth (Option A) or your caller (Option B), fire a test order, confirm the deliverable.
Support

Questions or a test token?

Contact fncrib support.