Docs
Firmly Agentic Commerce
Set theme to dark (⇧+D)

Credentials & API Access

For most merchants on industry-standard commerce platforms, you don’t provide API credentials yourself. Firmly’s pre-built platform adapter connects to your store the same way your own website’s front end does — through the standard public storefront APIs the platform already exposes. The “Complete integration” task in the Onboarding Wizard is Firmly-driven and automated. For headless, composable, or custom platforms, there’s a short credential handoff conversation with Firmly’s onboarding team — covered in detail below.

This page covers the cases where merchant input matters.

​​ What you provide, by platform category

Platform category What you actually provide
Industry-standard cloud commerce platforms Just the store URL. Firmly’s adapter handles the rest
Headless or heavily customized deployments Storefront API key + deployment-specific details — Firmly confirms during onboarding
Composable / API-first platforms Project key + minimum scope details may be requested if Firmly’s discovery can’t determine them
Custom or in-house platforms Firmly walks you through what’s needed — typically endpoint URLs, authentication shape, and example responses

For most merchants on industry-standard commerce platforms, the conversation about credentials is short. You provide the store URL during signup, and Firmly’s adapter does the rest.

​​ What Firmly’s adapter does behind the scenes

For pre-built platform adapters, the adapter connects to your store through the same public storefront APIs your own website’s front end calls — the standard read and cart patterns the platform exposes natively. The same patterns power discovery, cart, checkout, payment, and order placement.

You don’t issue Firmly an admin token, an app key, or a long-lived secret. The adapter does what any well-behaved client of your platform’s standard API would do.

​​ When merchant input matters

There are real cases where Firmly will ask for something:

Case What Firmly asks for
Custom platform Endpoint URLs, authentication scheme, example responses — Firmly walks you through the spec
Headless / heavily customized enterprise deployment Storefront API key + deployment-specific details
OAuth-only access on certain platform scopes A one-time OAuth consent through your platform’s standard consent screen — you authorize Firmly’s adapter
Custom CDN whitelist value The x-ac-auth header value that your CDN rule uses — see CDN whitelisting

For all of these, Firmly will walk you through the specifics. There’s no generic API-key handoff form because it varies by platform.

​​ What if my platform requires OAuth instead of long-lived tokens

OAuth is fine — Firmly’s platform adapter handles the OAuth flow, including refresh-token rotation. You authorize Firmly’s adapter through your platform’s standard OAuth consent screen.

If your platform requires OAuth (some platform-specific scopes or enterprise deployments), Firmly will walk you through the authorization step during onboarding.

​​ Custom adapter merchants

If you’re on a fully custom commerce stack, Firmly may provision a custom adapter — JavaScript code that Firmly executes against your backend when none of the pre-built platform adapters fit.

You’ll see a Custom Adapter Editor in the Merchant Portal (Firmly Connect), where you can review, edit, test, and publish the adapter without leaving the portal. Firmly’s solutions team typically pairs with you on the first version before a publish.

This is power-user surface — most merchants never need it.

​​ What gets stored where

Data Where it lives
Your store URL Firmly’s tenant record
Your platform credentials (when you do provide any) Stored encrypted in Firmly’s secrets store; accessed only by the platform adapter that needs them
Your customer database (existing customers) Stays in your platform — Firmly doesn’t ingest it
Order data on Firmly-originated orders Both in your platform (primary) and in Firmly’s records (for reconciliation)
Card data JWE-encrypted, transits through Firmly’s vault to your PSP — Firmly never stores cleartext PAN