Two things we give you
From our dashboard, per reseller:
https://fncrib.com/api/reseller/<your-token>/deliver <shared HMAC secret>We also map each of your product IDs → our product on our side, and you keep a prepaid balance that's debited per fulfilment.
SellAuth
If your shop runs on SellAuth, there's nothing to build:
- 1Open the product → set Delivery type to
Dynamic. - 2Paste the Delivery URL above as the webhook URL.
- 3Paste the Webhook secret into .
- 4Tell us your SellAuth product IDs so we can map them to our products.
SellAuth signs and sends the request; we respond with the deliverable. Done.
Custom integration
Call our endpoint yourself on each paid order. It's one request/response.
Request
https://fncrib.com/api/reseller/<your-token>/deliver Headers
| Header | Value |
|---|---|
Content-Type | application/json |
X-Signature | Hex HMAC-SHA256 of the raw request body, keyed with your webhook secret. |
Idempotency-Key | A stable id for this order-item. Re-send the same key on retries: you'll get the same deliverable back and are never charged twice. |
Body (JSON)
{
"unique_id": "INV-abc123", // your order/invoice id (echoed back in our records)
"email": "[email protected]", // optional
"item": {
"id": 555, // your order-item id (optional)
"product_id": "SA-PROD-1", // YOUR product id — mapped to our product on our side
"variant_id": null, // optional
"quantity": 1 // number of units to deliver
}
}
Signing the request
// Node.js
const crypto = require('crypto');
const raw = JSON.stringify(payload); // sign the EXACT bytes you send
const signature = crypto.createHmac('sha256', WEBHOOK_SECRET).update(raw).digest('hex');
// then POST `raw` with headers: X-Signature: signature, Idempotency-Key: <stable id>
// PHP
$raw = json_encode($payload);
$signature = hash_hmac('sha256', $raw, $webhookSecret);
Response
On success: HTTP 200, body is plain text. Each line is one deliverable: for quantity: 2 you get two lines. Show these to your buyer.
HTTP/1.1 200 OK
Content-Type: text/plain
buyer1login:buyer1pass
buyer2login:buyer2pass
Errors
Any non-200 means we did not deliver. The response body is a short, buyer-safe message you can display.
| Status | Meaning | Retry? |
|---|---|---|
401 | Bad/missing signature | NoFix signing |
402 | Your prepaid balance is exhausted | NoTop up with us |
409 | Out of stock for that product | NoWe restock |
422 | Product not mapped on our side | NoSend us the product id |
500 / 429 / 5xx | Transient error | YesRetry (we're idempotent) |
Idempotency & retries
Always send a stable Idempotency-Key per order-item. If you retry (timeout, 5xx), we return the exact same credentials and never claim a second unit or debit your balance twice. SellAuth does this automatically (3 retries, 5s apart).
Timeouts: we answer from local stock in well under a second. If you build a custom caller, a 5s connect / 10s read timeout is plenty. On a network error, retry with the same idempotency key.
Going live
- 1We create your reseller record → you receive your Delivery URL + secret.
- 2Send us your product IDs; we map them to our products. Each sale debits your prepaid balance by our product's price × quantity.
- 3You top up your prepaid balance with us.
- 4Configure SellAuth (Option A) or your caller (Option B), fire a test order, confirm the deliverable.