Menu
Platform
AI
App store purchases
Database
Flags
Jobs and cron
Localization
Monitoring
Notifications
Payments
Queues
Sandboxes
Webhooks
Getting Started
Authentication
KV Store
Deploy & Infrastructure
Reference
Create a store connection
Creates a store connection; its credential is sealed and never returned.
Creates a store connection; its credential is sealed and never returned.
- Path
POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/store_connections - Scope
billing:write - Effect
write— a successful call changes state. - Collection store_connections
- Query
store_connection_id,validate_only
#Request
| Field | Type | What it is |
|---|---|---|
parent | string | The parent to create in. Required. |
store_connection_id | string | The store connection id, the final name segment. Required. |
store_connection | StoreConnection | The store connection to create; only caller-writable fields are read. Required. |
validate_only | bool | Validate and return the result without writing anything. |
#StoreConnection
| Field | Type | What it is |
|---|---|---|
name | string | orgs/{org}/projects/{project}/envs/{env}/store_connections/{store_connection}; by convention app-store or google-play. |
meta | ResourceMeta | Resource metadata. |
spec | StoreConnectionSpec | Desired state. Required. |
#ResourceMeta
| Field | Type | What it is |
|---|---|---|
labels | map<string, string> | Caller-writable, indexed labels (AIP-122 label rules). |
annotations | map<string, string> | Caller-writable, unindexed annotations. |
display_name | string | Caller-writable human-readable name. |
#StoreConnectionSpec
| Field | Type | What it is |
|---|---|---|
app_store | AppStoreConnection | The App Store. One of the store group. |
google_play | GooglePlayConnection | Google Play. One of the store group. |
allow_sandbox | bool | Accept purchases the store marks as sandbox or license-test. Off in production: a sandbox purchase is then refused. |
require_account_token | bool | Refuse a purchase that does not carry the subject's account token (App Store appAccountToken, Play obfuscatedAccountId). |
#AppStoreConnection
| Field | Type | What it is |
|---|---|---|
bundle_ids | string[] | The apps' bundle ids. Required. |
issuer_id | string | The App Store Connect issuer id. Required. |
key_id | string | The In-App Purchase key id. Required. |
private_key | string | The In-App Purchase key (.p8 PEM). Write-only: sealed on write, never returned; omit it on update to keep the stored key. Never returned again. |
app_apple_id | int64 | The app's Apple id, needed to verify production notifications. |
account_token_prefix | string | An earlier appAccountToken scheme the app's shipped builds use: the token is UUIDv5 in the URL namespace of this prefix followed by the subject id (for example https://accounts.example.com/v2/). Tokens in Money's own scheme are always accepted as well. |
#GooglePlayConnection
| Field | Type | What it is |
|---|---|---|
package_names | string[] | The apps' package names. Required. |
service_account_json | string | The service account's JSON key. Write-only: sealed on write, never returned; omit it on update to keep the stored key. Never returned again. |
notification_audience | string | The audience Play's Pub/Sub push token must carry for real-time developer notifications; unset refuses them. |
notification_service_account | string | The service account Pub/Sub pushes as. |
#Response
| Field | Type | What it is |
|---|---|---|
name | string | orgs/{org}/projects/{project}/envs/{env}/store_connections/{store_connection}; by convention app-store or google-play. |
uid | string | stc_<cell><ulid>; never reused. Store notifications for this connection are sent to a URL that carries it. Output only. |
meta | ResourceMeta | Resource metadata. |
spec | StoreConnectionSpec | Desired state. Required. |
status | StoreConnectionStatus | Observed state. Output only. |
#ResourceMeta
| Field | Type | What it is |
|---|---|---|
generation | int64 | Increases by one on every change to spec. Output only. |
etag | string | Strong ETag (AIP-154): changes on any change to spec, status, or metadata. Send it back as If-Match or etag to make Update and Delete conditional; a mismatch fails with ABORTED / 409 ETAG_MISMATCH. Output only. |
create_time | timestamp | When the Resource was created. Output only. |
update_time | timestamp | When the Resource last changed. Output only. |
delete_time | timestamp | Set while the Resource is being deleted. Output only. |
labels | map<string, string> | Caller-writable, indexed labels (AIP-122 label rules). |
annotations | map<string, string> | Caller-writable, unindexed annotations. |
display_name | string | Caller-writable human-readable name. |
creator | string | The principal that created the Resource. Output only. |
#StoreConnectionSpec
| Field | Type | What it is |
|---|---|---|
app_store | AppStoreConnection | The App Store. One of the store group. |
google_play | GooglePlayConnection | Google Play. One of the store group. |
allow_sandbox | bool | Accept purchases the store marks as sandbox or license-test. Off in production: a sandbox purchase is then refused. |
require_account_token | bool | Refuse a purchase that does not carry the subject's account token (App Store appAccountToken, Play obfuscatedAccountId). |
#StoreConnectionStatus
| Field | Type | What it is |
|---|---|---|
observed_generation | int64 | The generation this status was computed from. Output only. |
conditions | Condition[] | Ready when a credential is stored. Output only. |
credential_set | bool | Whether a credential is stored. Output only. |
notification_url | string | Where the store sends its notifications for this connection. Output only. |
service_account_email | string | The service account's email, read from the stored key (Play only). Output only. |
#AppStoreConnection
| Field | Type | What it is |
|---|---|---|
bundle_ids | string[] | The apps' bundle ids. Required. |
issuer_id | string | The App Store Connect issuer id. Required. |
key_id | string | The In-App Purchase key id. Required. |
private_key | string | The In-App Purchase key (.p8 PEM). Write-only: sealed on write, never returned; omit it on update to keep the stored key. Never returned again. |
app_apple_id | int64 | The app's Apple id, needed to verify production notifications. |
account_token_prefix | string | An earlier appAccountToken scheme the app's shipped builds use: the token is UUIDv5 in the URL namespace of this prefix followed by the subject id (for example https://accounts.example.com/v2/). Tokens in Money's own scheme are always accepted as well. |
#GooglePlayConnection
| Field | Type | What it is |
|---|---|---|
package_names | string[] | The apps' package names. Required. |
service_account_json | string | The service account's JSON key. Write-only: sealed on write, never returned; omit it on update to keep the stored key. Never returned again. |
notification_audience | string | The audience Play's Pub/Sub push token must carry for real-time developer notifications; unset refuses them. |
notification_service_account | string | The service account Pub/Sub pushes as. |
#Condition
| Field | Type | What it is |
|---|---|---|
type | string | The condition type, for example Ready. |
status | ConditionStatus | Whether the condition holds. One of true, false, unknown. |
observed_generation | int64 | The generation this observation was made against. |
reason | string | A machine-readable UpperCamelCase reason. |
message | string | A customer-safe human-readable message. |
severity | Severity | How severe a FALSE condition is. One of info, warning, error. |
transition_time | timestamp | When status last changed. |
#Errors
UNAUTHENTICATED— No valid key or token was presented.PERMISSION_DENIED— The key lacks the method's permission.UNKNOWN_FIELD— The request has a field the schema does not know.INVALID_FIELD— A field failed validation.RESOURCE_ALREADY_EXISTS— A Resource with this name exists.IDEMPOTENCY_KEY_REUSED— An Idempotency-Key was reused with another body.IDEMPOTENCY_IN_PROGRESS— The first call with this Idempotency-Key is still running.
Every error arrives in the body Errors describes.
#Examples
curl -X POST "https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/store_connections" \
-H "Authorization: Bearer $SYLPHX_API_KEY" \
-H "Content-Type: application/json" \
-d '{"spec":{}}'