API reference / Getting started / Authentication

Authentication

Headers: X-App-Key X-App-Secret X-Shop-Id

Every Kixmon Profit API request is authenticated with an app key and an app secret, sent as HTTP headers. All endpoints except Get Shops are scoped to one shop and also need an X-Shop-Id header. There is no OAuth flow and no token to refresh — the same two credentials work on every request.

Get your API keys

  1. Log in to your Kixmon account and connect your TikTok Shop and ads account.
  2. In the left sidebar, open Setting → REST APIs and click Enable REST APIs. REST APIs must be available on your current plan — if not, upgrading enables them.
  3. Your app key (starts with km_) and app secret are generated there. One pair per account — the same credentials work on all of your shops.
  4. Copy the app secret immediately and store it on your server. It is hidden after you leave the page. If you lose it, click Refresh credentials for a new one — existing integrations stop working until you update them.
  5. Call Get Shops once to get the id of each shop, and send it as X-Shop-Id on all other endpoints.

Headers

Properties Type Description
X-App-KeyRequired string App key created when REST APIs are enabled in Settings. Example: km_your_app_key.
X-App-SecretRequired string App secret created when REST APIs are enabled in Settings. Store it on your server only — never send it from a browser or mobile app.
X-Shop-IdAll except Get Shops string The shop to query. Use the id value returned by Get Shops.

Example

curl 'https://api.kixmon.io/api/v1/shops' \
  -H "X-App-Key: $KIXMON_APP_KEY" \
  -H "X-App-Secret: $KIXMON_APP_SECRET"
const res = await fetch("https://api.kixmon.io/api/v1/shops", {
  headers: {
    "X-App-Key": process.env.KIXMON_APP_KEY,
    "X-App-Secret": process.env.KIXMON_APP_SECRET,
  },
});
const data = await res.json();
import os, requests

resp = requests.get(
    "https://api.kixmon.io/api/v1/shops",
    headers={
        "X-App-Key": os.environ["KIXMON_APP_KEY"],
        "X-App-Secret": os.environ["KIXMON_APP_SECRET"],
    },
    timeout=30,
)
resp.raise_for_status()
data = resp.json()

A successful call returns HTTP 200 with "success": true. To try requests without writing code, use the API Testing Tool — it fills in your credentials and builds the cURL command for you.

Authentication errors

HTTP status Code Description
401 MISSING_CREDENTIALS X-App-Key or X-App-Secret is missing.
401 INVALID_CREDENTIALS App key or app secret is wrong.
403 FEATURE_UNAVAILABLE REST APIs are not on the current plan.

Keeping credentials safe

  • Call the API over HTTPS from your server or a trusted automation tool (Zapier, Make, n8n).
  • Never put the app key or app secret in website code, a mobile app, or a public repository.
  • Store credentials in environment variables or a secrets manager, not in source code.
  • If a secret is exposed, regenerate it in Settings immediately — the old one stops working.


Tiktok Shop Partner

Kixmon makes it so easy to know your numbers. See all hidden costs, track every penny, and avoid profit headaches—it’s all at your fingertips.

Get in Touch

©Kixmon LLC. All Rights Reserved.
Certified TikTok Shop Partner