Credentials & API Access
For most merchants on industry-standard commerce platforms, you don’t provide API credentials yourself. Firmly’s pre-built platform adapter connects to your store the same way your own website’s front end does — through the standard public storefront APIs the platform already exposes. The “Complete integration” task in the Onboarding Wizard is Firmly-driven and automated. For headless, composable, or custom platforms, there’s a short credential handoff conversation with Firmly’s onboarding team — covered in detail below.
This page covers the cases where merchant input matters.
What you provide, by platform category
| Platform category | What you actually provide |
|---|---|
| Industry-standard cloud commerce platforms | Just the store URL. Firmly’s adapter handles the rest |
| Headless or heavily customized deployments | Storefront API key + deployment-specific details — Firmly confirms during onboarding |
| Composable / API-first platforms | Project key + minimum scope details may be requested if Firmly’s discovery can’t determine them |
| Custom or in-house platforms | Firmly walks you through what’s needed — typically endpoint URLs, authentication shape, and example responses |
For most merchants on industry-standard commerce platforms, the conversation about credentials is short. You provide the store URL during signup, and Firmly’s adapter does the rest.
What Firmly’s adapter does behind the scenes
For pre-built platform adapters, the adapter connects to your store through the same public storefront APIs your own website’s front end calls — the standard read and cart patterns the platform exposes natively. The same patterns power discovery, cart, checkout, payment, and order placement.
You don’t issue Firmly an admin token, an app key, or a long-lived secret. The adapter does what any well-behaved client of your platform’s standard API would do.
When merchant input matters
There are real cases where Firmly will ask for something:
| Case | What Firmly asks for |
|---|---|
| Custom platform | Endpoint URLs, authentication scheme, example responses — Firmly walks you through the spec |
| Headless / heavily customized enterprise deployment | Storefront API key + deployment-specific details |
| OAuth-only access on certain platform scopes | A one-time OAuth consent through your platform’s standard consent screen — you authorize Firmly’s adapter |
| Custom CDN whitelist value | The x-ac-auth header value that your CDN rule uses — see CDN whitelisting |
For all of these, Firmly will walk you through the specifics. There’s no generic API-key handoff form because it varies by platform.
What if my platform requires OAuth instead of long-lived tokens
OAuth is fine — Firmly’s platform adapter handles the OAuth flow, including refresh-token rotation. You authorize Firmly’s adapter through your platform’s standard OAuth consent screen.
If your platform requires OAuth (some platform-specific scopes or enterprise deployments), Firmly will walk you through the authorization step during onboarding.
Custom adapter merchants
If you’re on a fully custom commerce stack, Firmly may provision a custom adapter — JavaScript code that Firmly executes against your backend when none of the pre-built platform adapters fit.
You’ll see a Custom Adapter Editor in the Merchant Portal (Firmly Connect), where you can review, edit, test, and publish the adapter without leaving the portal. Firmly’s solutions team typically pairs with you on the first version before a publish.
This is power-user surface — most merchants never need it.
What gets stored where
| Data | Where it lives |
|---|---|
| Your store URL | Firmly’s tenant record |
| Your platform credentials (when you do provide any) | Stored encrypted in Firmly’s secrets store; accessed only by the platform adapter that needs them |
| Your customer database (existing customers) | Stays in your platform — Firmly doesn’t ingest it |
| Order data on Firmly-originated orders | Both in your platform (primary) and in Firmly’s records (for reconciliation) |
| Card data | JWE-encrypted, transits through Firmly’s vault to your PSP — Firmly never stores cleartext PAN |
Related
- Onboarding walkthrough — the wizard flow
- Going Live — Firmly’s go-live approval step
- Supported platforms — platform-specific notes