Client integration

API documentation

Public reference for client partners integrating with our 3PL. To obtain an API key, sign in to your client dashboard and generate one from the Clients page. Keys are never displayed on this public page.

Base URL

https://project--bd9fffb1-568a-43b8-90b7-45614c2078a5.lovable.app/api/public/v1

Use this canonical API hostname exactly. It does not redirect, so authorization headers are preserved.

Authentication

Every request must include an Authorization header with your client's API key. Keys start with pl3pl_live_.

Authorization: Bearer pl3pl_live_YOUR_KEY_HERE

Treat the key like a password. If it's compromised, revoke it from your client dashboard and issue a new one. Keys are not shown on this public documentation page.

GET /inventory

Returns the full product catalog with live quantities and your tier pricing.

Request
curl https://project--bd9fffb1-568a-43b8-90b7-45614c2078a5.lovable.app/api/public/v1/inventory \
  -H "Authorization: Bearer pl3pl_live_YOUR_KEY_HERE"
Query params
  • limit — max items (default 100, max 500)
  • offset — pagination offset
  • category — exact-match filter
Response
{
  "client": {
    "id": "…",
    "name": "Acme Peptides",
    "slug": "acme-peptides",
    "pricing_tier_id": "…",
    "pricing_tier_name": "Gold"
  },
  "count": 2,
  "limit": 100,
  "offset": 0,
  "items": [
    {
      "id": "…",
      "sku": "BPC-157-5",
      "name": "BPC-157 5mg",
      "category": "Healing",
      "lot_number": "L240612-A",
      "quantity_available": 25,
      "your_price": 42.00,
      "wholesale_price": 42.00,
      "list_price": 49.00,
      "msrp": 79.00,
      "price_source": "tier",
      "currency": "USD",
      "has_coa": true
    }
  ]
}

your_price reflects your negotiated wholesale tier and is the price your account will be charged at order time. price_source is "tier" when a tier price applies, or "list" when no tier override exists for that product.

POST /shipping/rates

Live shipping rates from our warehouse to your customer. Use this at checkout to show options.

Request
curl -X POST https://project--bd9fffb1-568a-43b8-90b7-45614c2078a5.lovable.app/api/public/v1/shipping/rates \
  -H "Authorization: Bearer pl3pl_live_YOUR_KEY_HERE" \
  -H "Content-Type: application/json" \
  -d '{
    "ship_to": {
      "city": "Austin",
      "state": "TX",
      "postal_code": "78701",
      "country": "US"
    },
    "items": [
      { "sku": "BPC-157-5", "quantity": 2 }
    ]
  }'
Response
{
  "mocked": false,
  "package": { "weight_oz": 10, "length": 6, "width": 4, "height": 2 },
  "rates": [
    {
      "carrier_code": "stamps_com",
      "carrier_name": "USPS",
      "service_code": "usps_priority_mail_express",
      "service_name": "USPS Priority Mail Express",
      "amount": 42.19,
      "base_cost": 33.75,
      "currency": "USD",
      "estimated_days": 2
    }
  ]
}

amount is the marked-up price you can charge your customer at checkout. Pass the chosen carrier_code, service_code, and amount back into POST /orders as shipping_selection.

POST /orders

Submit an order for fulfillment. Idempotent on client_order_id.

Request
curl -X POST https://project--bd9fffb1-568a-43b8-90b7-45614c2078a5.lovable.app/api/public/v1/orders \
  -H "Authorization: Bearer pl3pl_live_YOUR_KEY_HERE" \
  -H "Content-Type: application/json" \
  -d '{
    "client_order_id": "SO-10245",
    "customer": {
      "name": "Jane Doe",
      "email": "jane@example.com",
      "phone": "+15555550101"
    },
    "ship_to": {
      "name": "Jane Doe",
      "line1": "123 Main St",
      "city": "Austin",
      "state": "TX",
      "postal_code": "78701",
      "country": "US"
    },
    "items": [
      { "sku": "BPC-157-5", "quantity": 2 },
      { "sku": "TB-500-5", "quantity": 1 }
    ],
    "shipping": 9.95,
    "currency": "USD",
    "notes": "Gift wrap please"
  }'
Field rules
  • items[].sku must match a SKU returned by /inventory.
  • Pricing is always set server-side from your client's wholesale tier — unit_price is not accepted on order items and will be ignored.
  • client_order_id makes the call idempotent: re-sending with the same id returns the existing order.
  • On success we deduct the ordered quantities from BioSync inventory and debit the order total from your credit balance.
  • Include shipping_selection to purchase the label immediately. The sender on the label + packing slip uses your Return Address (configure it in your client dashboard). If it's blank, we fall back to our warehouse.
With a chosen shipping option
{
  "client_order_id": "SO-10245",
  "customer": { "name": "Jane Doe", "email": "jane@example.com" },
  "ship_to": {
    "name": "Jane Doe",
    "line1": "123 Main St",
    "city": "Austin", "state": "TX",
    "postal_code": "78701", "country": "US"
  },
  "items": [{ "sku": "BPC-157-5", "quantity": 2 }],
  "shipping_selection": {
    "carrier_code": "stamps_com",
    "service_code": "usps_priority_mail_express",
    "amount_charged": 42.19
  }
}
Response (201)
{
  "order": {
    "id": "…",
    "status": "label_created",
    "subtotal": 153.00,
    "shipping": 42.19,
    "total": 195.19,
    "currency": "USD",
    "created_at": "2026-06-19T..."
  },
  "items": [
    { "sku": "BPC-157-5", "name": "BPC-157 5mg", "quantity": 2, "unit_price": 49.00, "line_total": 98.00 },
    { "sku": "TB-500-5",  "name": "TB-500 5mg",  "quantity": 1, "unit_price": 55.00, "line_total": 55.00 }
  ],
  "shipment": {
    "carrier": "stamps_com",
    "service_code": "usps_priority_mail_express",
    "tracking_number": "9400...",
    "label_url": "data:application/pdf;base64,...",
    "ship_from_source": "brand",
    "mocked": false
  },
  "shipment_error": null
}

If shipment_error is non-null, the order was still created and you can retry the label from your dashboard. ship_from_source is "brand" when your Return Address was used, or "warehouse_fallback" when it wasn't set.

Errors

401 unauthorized       — missing/invalid/revoked API key
422 validation_error   — body failed schema validation (see "issues")
422 unknown_sku        — one or more SKUs are not in our catalog
500 server_error       — unexpected error (safe to retry with backoff)