Base URL
The Search & Merchandising API is served under the/api/lite prefix of the
Depict portal backend:
Authentication
The Search & Merchandising API is called by the Depict: Search & Merchandising app itself, which runs embedded in the Shopify admin. Every request carries the Shopify session token that App Bridge issues to the app, sent as a bearer token:merchant_id
parameter, it must be the merchant of that shop; multi-store endpoints take
explicit merchant_id parameters for the connected stores. Session tokens are
short-lived and are only issued inside the Shopify admin, so there is no
standalone API key for this API.
AI assistants and other outside callers
The session token above is the Depict: Search & Merchandising app’s own path. Callers outside the app, such as AI assistants, use Depict’s MCP server instead. Each store has its own endpoint:depict:read and
depict:write. A person with access to the store approves each connection in
the Shopify admin. The authorization server is described at
https://platform.depict.ai/.well-known/oauth-authorization-server, and each
store’s endpoint at
https://platform.depict.ai/.well-known/oauth-protected-resource?store_id=<merchant_id>.
Through the MCP server, an assistant calls the operations of this API that are
open to assistants, as the person who approved it.
Connecting an assistant, the approval screen and revoking are described on
the AI assistants page.
What you can do with it
- Collections — list, activate and configure merchandised collections, including the ordering that Depict pushes back to Shopify.
- Boost & bury — manage per-collection and global boost/bury rules.
- Dashboard — read the performance numbers shown on the Depict: Search & Merchandising dashboard.
- A/B testing — configure and read results of collection A/B tests.
- Multi-store — connect several Shopify stores and replicate collection configuration between them.
- Onboarding & Shopify integration — ingestion status, theme compatibility checks and app onboarding state.

