Limitra Supplier Service
v1.0Go microservice that bridges the Limitra marketplace with upstream retailers. It fetches product data from Amazon and eBay, checks availability, places orders via headless browser automation, and signs Quick Buy payloads for the admin Chrome extension.
Every endpoint returns JSON. All non-public endpoints require an internal service secret header. Orders run a two-phase flow — placement, then explicit confirmation — so an operator can review before the purchase commits.
Base URL
http://supplier-service:8082
Endpoints
| Method | Path | Purpose |
|---|---|---|
| POST | /import/amazon/:asin | Import a product from Amazon by ASIN |
| POST | /import/ebay/:itemId | Import a product from eBay by item ID |
| GET | /search | Unified search across suppliers |
| GET | /search/amazon | Search Amazon via PA API |
| GET | /search/ebay | Search eBay via Browse API |
| POST | /availability | Check product availability (cached) |
| POST | /order | Place an order — returns a session |
| POST | /order/:sessionId/confirm | Confirm a pending order session |
| POST | /quick-buy/payload | Sign a Quick Buy payload (HMAC-SHA256) |
| POST | /quick-buy/verify | Verify a signed Quick Buy payload |
| GET | /health | Health check |
| GET | /health/detailed | Detailed dependency status |
Authentication
Every request except /health must carry an X-Internal-Service-Secret header. The secret is shared between the supplier service and the other Limitra services that call it. Requests missing or with an incorrect secret receive 401 Unauthorized.
Example headers
POST /availability HTTP/1.1 Host: supplier-service:8082 Content-Type: application/json X-Internal-Service-Secret: <your-secret>
/health skips authentication so upstream probes can check liveness without credentials.
Secret for Try It
Paste the service secret here to use the interactive Try It panels below. It is kept only in this browser (localStorage) and sent as X-Internal-Service-Secret.
Health & Status
Live check against GET /health. Probes the running instance serving this page.
Dependencies
| Component | Status |
|---|---|
| Database (Postgres) | Unknown |
| Redis | Unknown |
| Amazon PA API | Unknown |
| eBay Browse API | Unknown |
Live status from GET /health/detailed. Refreshes every 30 seconds alongside the health check above.
Product Import
Fetch a single product by supplier identifier and persist it to the catalog.
Fetch and import an Amazon product by ASIN.
Request
| Param | In | Description |
|---|---|---|
asin | path | 10-character Amazon Standard Identification Number (uppercase alphanumeric). |
Response
{ "id": 1024, "supplier_id": "B0CXYZ1234", "supplier": "amazon", "title": "Sony WH-1000XM5 Headphones", "price": "349.99", "currency": "USD", "available": true, "fetched_at": "2026-04-18T09:00:00Z" }
| Status | Error | When |
|---|---|---|
| 400 | invalid ASIN format | ASIN is not 10 uppercase alphanumerics. |
| 404 | product not found | Amazon PA API has no item for that ASIN. |
| 429 | rate limited | Amazon PA API throttled the request. |
—
Fetch and import an eBay product by item ID.
Request
| Param | In | Description |
|---|---|---|
itemId | path | eBay legacy or Browse API item ID. |
Response
{ "supplier_id": "v1|123456789|0", "supplier": "ebay", "title": "Apple AirPods Pro 2", "price": "189.00", "currency": "USD", "available": true }
| Status | Error | When |
|---|---|---|
| 400 | itemId is required | Path parameter was empty. |
| 404 | product not found | eBay returned no matching item. |
| 429 | rate limited | eBay throttled the request. |
—
Product Search
Keyword search against one supplier or all suppliers in parallel.
Search all suppliers concurrently and merge the results.
Request
| Param | In | Description |
|---|---|---|
q | query | Search keywords. Required. |
page | query | Page number, defaults to 1. |
supplier | query | all (default), amazon, or ebay. |
Response
{ "products": [ ... ], "total": 42, "page": 1, "supplier": "all", "warnings": ["ebay: timeout"] }
| Status | Error | When |
|---|---|---|
| 400 | q is required | Missing query parameter. |
| 400 | supplier must be all, amazon, or ebay | Unknown supplier value. |
| 502 | all suppliers failed | Every supplier errored simultaneously. |
—
Search Amazon via PA API v5.
Request
| Param | In | Description |
|---|---|---|
q | query | Required keyword search. |
page | query | Page number, defaults to 1. |
Response
{ "products": [ ... ], "total": 120, "page": 1 }
—
Search eBay via Browse API.
Request
| Param | In | Description |
|---|---|---|
q | query | Required keyword search. |
page | query | Page number, defaults to 1. |
—
Availability
Check product availability. Results are cached in Redis for 150 seconds.
Request
{ "supplier": "amazon", "supplier_id": "B0CXYZ1234" }
Response
{ "supplier": "amazon", "supplier_id": "B0CXYZ1234", "available": true, "price": "349.99", "checked_at": "2026-04-18T09:00:00Z" }
| Status | Error | When |
|---|---|---|
| 400 | supplier must be amazon or ebay | Unknown supplier value. |
| 400 | Key: 'AvailabilityRequest.SupplierID' ... | Missing required field. |
| 500 | unknown supplier | Supplier fetcher not registered. |
—
Order Placement
Orders run in two phases. POST /order creates a pending session. POST /order/:sessionId/confirm finalizes it.
Start a new order session. Returns the session for subsequent confirmation.
Request
{ "supplier": "amazon", "supplier_id": "B0CXYZ1234", "variant_id": "black-large", "quantity": 1, "address": { "full_name": "Jane Doe", "line1": "1600 Amphitheatre Pkwy", "city": "Mountain View", "state": "CA", "zip_code": "94043" } }
Response
{ "session_id": "sess_2f9a...", "supplier": "amazon", "status": "pending_confirmation", "created_at": "2026-04-18T09:00:00Z" }
| Status | Error | When |
|---|---|---|
| 400 | supplier must be amazon or ebay | Invalid supplier. |
| 400 | variant not found | Variant ID does not exist on the product. |
| 409 | product unavailable | Availability check failed before order. |
—
Confirm a pending order. Drives the browser through checkout and returns the supplier order reference.
Request
| Param | In | Description |
|---|---|---|
sessionId | path | Session returned by POST /order. |
Response
{ "session_id": "sess_2f9a...", "supplier_order_ref": "114-7234056-0123456", "status": "confirmed", "confirmed_at": "2026-04-18T09:02:14Z" }
| Status | Error | When |
|---|---|---|
| 400 | sessionId is required | Empty path param. |
| 404 | session not found | No session matches the ID, or it expired. |
| 500 | checkout failed | Browser automation errored while confirming. |
—
Quick Buy
HMAC-SHA256 signing for payloads consumed by the admin Chrome extension. Payloads expire 15 minutes after signing.
Sign an order payload and return an expiring Quick Buy payload.
Request
Body mirrors POST /order.
Response
{ "order_payload": { ... }, "signature": "b6f3...", "expires_at": "2026-04-18T09:15:00Z" }
—
Verify the signature and expiry of a Quick Buy payload. Constant-time comparison.
Response
{ "valid": true }
—
Error Reference
Every error response is a JSON object of the form { "error": "message" }.
| Status | Error | Endpoints | When |
|---|---|---|---|
| 400 | invalid ASIN format | /import/amazon/:asin | ASIN is not 10 uppercase alphanumerics. |
| 400 | itemId is required | /import/ebay/:itemId | Empty path parameter. |
| 400 | q is required | /search, /search/amazon, /search/ebay | Missing query string. |
| 400 | supplier must be amazon or ebay | /availability, /order | Invalid supplier value. |
| 400 | supplier must be all, amazon, or ebay | /search | Invalid supplier filter. |
| 400 | variant not found | /order | Variant ID missing on the product. |
| 400 | sessionId is required | /order/:sessionId/confirm | Empty path parameter. |
| 401 | missing service secret | All (except /health) | No X-Internal-Service-Secret header. |
| 401 | invalid service secret | All (except /health) | Secret header mismatch. |
| 404 | product not found | /import/amazon, /import/ebay | No such product at supplier. |
| 404 | session not found | /order/:sessionId/confirm | Unknown or expired session. |
| 409 | product unavailable | /order | Availability check failed. |
| 429 | rate limited | /import/amazon, /import/ebay | Upstream supplier throttled. |
| 500 | checkout failed | /order/:sessionId/confirm | Browser automation errored. |
| 500 | unknown supplier | /availability | Supplier fetcher not registered. |
| 502 | all suppliers failed | /search | Every upstream supplier errored. |