This document outlines the deployed specification for two new authenticated endpoints to the Cardigan API.
<aside> ✅ This specification is the current version of the API. Previous versions:
</aside>
The Cardigan API is a REST-based API that uses a simple JSON data format for requests and responses.
Authentication is achieved via a Bearer token provided in the Authorization header. The token in use is scoped to a specific Shopify store and can be retrieved from the Cardigan settings page for each store.
An example token may look like this:
PD32xweQynoAbsi7dZVxRvK1SAMcQjiVa5VncZPVDGiqDGfhTFdNFYqFp7KYGDaNXAQyPo8qT8s76Uq4H1CEy1Rw1wr29wJzKnSvYpNW73v9yRJNvMQCSx3daK8qhUsv
with the corresponding header looking like this:
Authorization: Bearer PD32xweQynoAbsi7dZVxRvK1SAMcQjiVa5VncZPVDGiqDGfhTFdNFYqFp7KYGDaNXAQyPo8qT8s76Uq4H1CEy1Rw1wr29wJzKnSvYpNW73v9yRJNvMQCSx3daK8qhUsv
The base URL for the API is https://app.runcardigan.com/api/v1/:shopify_subdomain, where :shopify_subdomain is the Shopify subdomain for the relevant store — for example, the store my-store.myshopify.com would have an API base URL of https://app.runcardigan.com/api/v1/my-store.
The activate endpoint allows integrators to request the activation of an existing physical card with a specified value.
To activate a card with the number 892302452925087802753 and a value of CAD$100.00, the following request would be made:
POST <https://app.runcardigan.com/api/v1/my-store/activated_cards.json>
Authorization: Bearer PD32xweQynoAbsi7dZVxRvK1SAMcQjiVa5VncZPVDGiqDGfhTFdNFYqFp7KYGDaNXAQyPo8qT8s76Uq4H1CEy1Rw1wr29wJzKnSvYpNW73v9yRJNvMQCSx3daK8qhUsv
Content-Type: application/json
{
"amount": "100.00",
"currency_code": "CAD",
"number": "892302452925087802753",
"source_name": "Return RA45738953"
}