Limitra
Supplier Service

Limitra Supplier Service

v1.0

Go microservice that bridges the Limitra marketplace with upstream retailers. It fetches product data from Amazon and eBay, checks availability, places orders via headless browser automation, and signs Quick Buy payloads for the admin Chrome extension.

Every endpoint returns JSON. All non-public endpoints require an internal service secret header. Orders run a two-phase flow — placement, then explicit confirmation — so an operator can review before the purchase commits.

Base URL

http://supplier-service:8082

Endpoints

MethodPathPurpose
POST/import/amazon/:asinImport a product from Amazon by ASIN
POST/import/ebay/:itemIdImport a product from eBay by item ID
GET/searchUnified search across suppliers
GET/search/amazonSearch Amazon via PA API
GET/search/ebaySearch eBay via Browse API
POST/availabilityCheck product availability (cached)
POST/orderPlace an order — returns a session
POST/order/:sessionId/confirmConfirm a pending order session
POST/quick-buy/payloadSign a Quick Buy payload (HMAC-SHA256)
POST/quick-buy/verifyVerify a signed Quick Buy payload
GET/healthHealth check
GET/health/detailedDetailed dependency status

Authentication

Every request except /health must carry an X-Internal-Service-Secret header. The secret is shared between the supplier service and the other Limitra services that call it. Requests missing or with an incorrect secret receive 401 Unauthorized.

Example headers

POST /availability HTTP/1.1
Host: supplier-service:8082
Content-Type: application/json
X-Internal-Service-Secret: <your-secret>

/health skips authentication so upstream probes can check liveness without credentials.

Secret for Try It

Paste the service secret here to use the interactive Try It panels below. It is kept only in this browser (localStorage) and sent as X-Internal-Service-Secret.

Health & Status

Live check against GET /health. Probes the running instance serving this page.

—

Not checked yet

Auto-refresh paused

Dependencies

ComponentStatus
Database (Postgres)Unknown
RedisUnknown
Amazon PA APIUnknown
eBay Browse APIUnknown

Live status from GET /health/detailed. Refreshes every 30 seconds alongside the health check above.

Product Import

Fetch a single product by supplier identifier and persist it to the catalog.

POST/import/amazon/:asin

Fetch and import an Amazon product by ASIN.


Request

ParamInDescription
asinpath10-character Amazon Standard Identification Number (uppercase alphanumeric).

Response

{
  "id": 1024,
  "supplier_id": "B0CXYZ1234",
  "supplier": "amazon",
  "title": "Sony WH-1000XM5 Headphones",
  "price": "349.99",
  "currency": "USD",
  "available": true,
  "fetched_at": "2026-04-18T09:00:00Z"
}
StatusErrorWhen
400invalid ASIN formatASIN is not 10 uppercase alphanumerics.
404product not foundAmazon PA API has no item for that ASIN.
429rate limitedAmazon PA API throttled the request.
—

POST/import/ebay/:itemId

Fetch and import an eBay product by item ID.


Request

ParamInDescription
itemIdpatheBay legacy or Browse API item ID.

Response

{
  "supplier_id": "v1|123456789|0",
  "supplier": "ebay",
  "title": "Apple AirPods Pro 2",
  "price": "189.00",
  "currency": "USD",
  "available": true
}
StatusErrorWhen
400itemId is requiredPath parameter was empty.
404product not foundeBay returned no matching item.
429rate limitedeBay throttled the request.
—

Availability

POST/availability

Check product availability. Results are cached in Redis for 150 seconds.


Request

{
  "supplier": "amazon",
  "supplier_id": "B0CXYZ1234"
}

Response

{
  "supplier": "amazon",
  "supplier_id": "B0CXYZ1234",
  "available": true,
  "price": "349.99",
  "checked_at": "2026-04-18T09:00:00Z"
}
StatusErrorWhen
400supplier must be amazon or ebayUnknown supplier value.
400Key: 'AvailabilityRequest.SupplierID' ...Missing required field.
500unknown supplierSupplier fetcher not registered.
—

Order Placement

Orders run in two phases. POST /order creates a pending session. POST /order/:sessionId/confirm finalizes it.

POST/order

Start a new order session. Returns the session for subsequent confirmation.


Request

{
  "supplier": "amazon",
  "supplier_id": "B0CXYZ1234",
  "variant_id": "black-large",
  "quantity": 1,
  "address": {
    "full_name": "Jane Doe",
    "line1": "1600 Amphitheatre Pkwy",
    "city": "Mountain View",
    "state": "CA",
    "zip_code": "94043"
  }
}

Response

{
  "session_id": "sess_2f9a...",
  "supplier": "amazon",
  "status": "pending_confirmation",
  "created_at": "2026-04-18T09:00:00Z"
}
StatusErrorWhen
400supplier must be amazon or ebayInvalid supplier.
400variant not foundVariant ID does not exist on the product.
409product unavailableAvailability check failed before order.
—

POST/order/:sessionId/confirm

Confirm a pending order. Drives the browser through checkout and returns the supplier order reference.


Request

ParamInDescription
sessionIdpathSession returned by POST /order.

Response

{
  "session_id": "sess_2f9a...",
  "supplier_order_ref": "114-7234056-0123456",
  "status": "confirmed",
  "confirmed_at": "2026-04-18T09:02:14Z"
}
StatusErrorWhen
400sessionId is requiredEmpty path param.
404session not foundNo session matches the ID, or it expired.
500checkout failedBrowser automation errored while confirming.
—

Quick Buy

HMAC-SHA256 signing for payloads consumed by the admin Chrome extension. Payloads expire 15 minutes after signing.

POST/quick-buy/payload

Sign an order payload and return an expiring Quick Buy payload.


Request

Body mirrors POST /order.

Response

{
  "order_payload": { ... },
  "signature": "b6f3...",
  "expires_at": "2026-04-18T09:15:00Z"
}
—

POST/quick-buy/verify

Verify the signature and expiry of a Quick Buy payload. Constant-time comparison.


Response

{ "valid": true }
—

Error Reference

Every error response is a JSON object of the form { "error": "message" }.

StatusErrorEndpointsWhen
400invalid ASIN format/import/amazon/:asinASIN is not 10 uppercase alphanumerics.
400itemId is required/import/ebay/:itemIdEmpty path parameter.
400q is required/search, /search/amazon, /search/ebayMissing query string.
400supplier must be amazon or ebay/availability, /orderInvalid supplier value.
400supplier must be all, amazon, or ebay/searchInvalid supplier filter.
400variant not found/orderVariant ID missing on the product.
400sessionId is required/order/:sessionId/confirmEmpty path parameter.
401missing service secretAll (except /health)No X-Internal-Service-Secret header.
401invalid service secretAll (except /health)Secret header mismatch.
404product not found/import/amazon, /import/ebayNo such product at supplier.
404session not found/order/:sessionId/confirmUnknown or expired session.
409product unavailable/orderAvailability check failed.
429rate limited/import/amazon, /import/ebayUpstream supplier throttled.
500checkout failed/order/:sessionId/confirmBrowser automation errored.
500unknown supplier/availabilitySupplier fetcher not registered.
502all suppliers failed/searchEvery upstream supplier errored.