Skip to main content
Every REST API key carries a list of scopes that controls which endpoints it can call. The merchant sets them when creating the key in Shopify admin → Apps → Yuko Loyalty → Integrations → REST API:
  • Full Access Key: the highest access level each scope supports (read and write where available).
  • Read-Only Key: read access for every scope.
  • Custom Key: No Access, Read Access or Read/Write Access per scope.

Scope format

Scopes are stored on the key as read:<scope> or write:<scope>, for example read:rewards or write:transactions.
  • read:<scope> allows the scope’s read endpoints.
  • write:<scope> allows the scope’s write endpoints and its read endpoints. Write implies read.

Available scopes

Endpoints by scope

All paths are relative to https://api.yukoapp.com/api/v1/public.

Missing scope errors

If the key doesn’t have the scope an endpoint needs, the API returns 403 Forbidden:
403
To fix it, create a new key with the scope you need (or ask the merchant to), then revoke the old key. A key’s scopes can’t be changed after it’s created.