Get Active Domains
GET https://api.firmly.work/api/v2/carts/active-domains
Overview
This endpoint retrieves a list of all domain names (store identifiers) that have active cart sessions for the current authenticated device. This is useful for understanding which stores the user has active shopping sessions with.
Authentication
x-firmly-authorization(string, required) — Device access token from Browser Session- Server-to-server (S2S) auth is not accepted — this is a device-scoped session route. It requires a device JWT from Browser Session; the S2S secret is rejected. See Server-to-Server Authentication.
Request
No request body or query parameters required.
Response
domains(array) — Array of domain names (store identifiers) that have active sessions Example:["staging.luma.gift", "demo.luma.gift", "shop.luma.gift"]
Session Behavior
Active Domain Criteria
- Domain must have an active cart session
- Cart must contain at least one item
- Session must not be expired
Use Cases
- Quick check for active shopping sessions
- Pre-flight check before fetching full cart data
- Building domain-specific UI elements
- Analytics and session tracking
Examples
curl -X GET 'https://api.firmly.work/api/v2/carts/active-domains' \-H 'x-firmly-authorization: <your-auth-token>'
const response = await fetch('https://api.firmly.work/api/v2/carts/active-domains', {headers: {'x-firmly-authorization': '<your-auth-token>'}});const { domains } = await response.json();console.log('Active domains:', domains);
import requestsresponse = requests.get('https://api.firmly.work/api/v2/carts/active-domains',headers={'x-firmly-authorization': '<your-auth-token>'})data = response.json()active_domains = data['domains']
Response Examples
Multiple Active Domains
{"domains": ["staging.luma.gift","demo.luma.gift","shop.luma.gift"]}
Single Active Domain
{"domains": ["staging.luma.gift"]}
No Active Domains
{"domains": []}
Related Endpoints
- Get Active Carts — Get full cart data for active sessions
- Get Cart — Get cart for a specific domain
Error Responses
Errors return a JSON body with code, error, and description. Program against the error value — descriptions are human-readable and may change.
400 — MissingAuthHeader
The x-firmly-authorization header is missing or empty.
{ "code": 400, "error": "MissingAuthHeader", "description": "x-firmly-authorization header is missing or invalid." }
400 — InvalidToken
The authorization token is not a valid JWT structure.
{ "code": 400, "error": "InvalidToken", "description": "Jwt token is invalid." }
401 — InvalidJWTToken
The device JWT signature does not verify, or required claims are missing.
{ "code": 401, "error": "InvalidJWTToken", "description": "Jwt token is invalid." }
404 — PartnerNotFound
The appid claim on the device JWT does not map to a known partner / tenant.
{ "code": 404, "error": "PartnerNotFound", "description": "Partner not found." }