> ## Documentation Index
> Fetch the complete documentation index at: https://docs.depict.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# The merchant's public Storefront API token and store domain

> What a client needs to call the store's Storefront GraphQL API directly (e.g. to read published products and shop metafields as shoppers see them). Read-only; one config read, no Shopify call.



## OpenAPI

````yaml /api-reference/openapi/lite.json get /shopify/storefront_api_credentials
openapi: 3.1.0
info:
  title: Search & Merchandising API
  version: 1.0.0
  description: >-
    REST API behind Depict: Search & Merchandising, the native Shopify app:
    onboarding, collections, boost & bury, dashboards, A/B testing and
    multi-store management. Endpoints are served under the /api/lite prefix and
    are authenticated with the Shopify session token that App Bridge issues to
    the embedded app.
servers:
  - url: /api/lite
security:
  - ShopifySessionToken: []
paths:
  /shopify/storefront_api_credentials:
    get:
      summary: The merchant's public Storefront API token and store domain
      description: >-
        What a client needs to call the store's Storefront GraphQL API directly
        (e.g. to read published products and shop metafields as shoppers see
        them). Read-only; one config read, no Shopify call.
      operationId: shopifyStorefrontCredentials
      parameters:
        - schema:
            type: string
            description: Lite merchant id, e.g. `shopify-<shop id>`.
          required: true
          description: Lite merchant id, e.g. `shopify-<shop id>`.
          name: merchant_id
          in: query
      responses:
        '200':
          description: The credentials.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ShopifyStorefrontApiCredentials'
        '400':
          description: >-
            merchant_id is missing, or the merchant has no Shopify configuration
            / Storefront token.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
        '401':
          description: Not authenticated.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
        '403':
          description: Authenticated, but this identity may not call the API.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
        '404':
          description: Merchant not found for this caller.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
        '500':
          description: Internal error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
components:
  schemas:
    ShopifyStorefrontApiCredentials:
      type: object
      properties:
        storefront_api_key:
          type: string
          description: The public Storefront API access token (safe to use in the browser).
        store_domain:
          type: string
          description: '`https://<shop>.myshopify.com`.'
      required:
        - storefront_api_key
        - store_domain
    Detail:
      type: object
      properties:
        detail:
          type: string
      required:
        - detail
      description: 'Every 4xx/5xx body: `{detail}`.'
  securitySchemes:
    ShopifySessionToken:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Shopify App Bridge session token of the embedded Depict: Search &
        Merchandising app. The shop in the token determines the merchant;
        merchant_id parameters must belong to that shop.

````