API reference / Getting started / Authentication
Authentication
Headers: X-App-Key X-App-Secret X-Shop-Id
Every Kixmon Profit API request is authenticated with an app key and an app secret, sent as HTTP headers. All endpoints except Get Shops are scoped to one shop and also need an X-Shop-Id header. There is no OAuth flow and no token to refresh — the same two credentials work on every request.
Get your API keys
- Log in to your Kixmon account and connect your TikTok Shop and ads account.
- In the left sidebar, open Setting → REST APIs and click Enable REST APIs. REST APIs must be available on your current plan — if not, upgrading enables them.
- Your app key (starts with
km_) and app secret are generated there. One pair per account — the same credentials work on all of your shops. - Copy the app secret immediately and store it on your server. It is hidden after you leave the page. If you lose it, click Refresh credentials for a new one — existing integrations stop working until you update them.
- Call Get Shops once to get the
idof each shop, and send it asX-Shop-Idon all other endpoints.
Headers
| Properties | Type | Description |
|---|---|---|
X-App-KeyRequired |
string | App key created when REST APIs are enabled in Settings. Example: km_your_app_key. |
X-App-SecretRequired |
string | App secret created when REST APIs are enabled in Settings. Store it on your server only — never send it from a browser or mobile app. |
X-Shop-IdAll except Get Shops |
string | The shop to query. Use the id value returned by Get Shops. |
Example
curl 'https://api.kixmon.io/api/v1/shops' \
-H "X-App-Key: $KIXMON_APP_KEY" \
-H "X-App-Secret: $KIXMON_APP_SECRET"
const res = await fetch("https://api.kixmon.io/api/v1/shops", {
headers: {
"X-App-Key": process.env.KIXMON_APP_KEY,
"X-App-Secret": process.env.KIXMON_APP_SECRET,
},
});
const data = await res.json();
import os, requests
resp = requests.get(
"https://api.kixmon.io/api/v1/shops",
headers={
"X-App-Key": os.environ["KIXMON_APP_KEY"],
"X-App-Secret": os.environ["KIXMON_APP_SECRET"],
},
timeout=30,
)
resp.raise_for_status()
data = resp.json()
A successful call returns HTTP 200 with "success": true. To try requests without writing code, use the API Testing Tool — it fills in your credentials and builds the cURL command for you.
Authentication errors
| HTTP status | Code | Description |
|---|---|---|
401 |
MISSING_CREDENTIALS |
X-App-Key or X-App-Secret is missing. |
401 |
INVALID_CREDENTIALS |
App key or app secret is wrong. |
403 |
FEATURE_UNAVAILABLE |
REST APIs are not on the current plan. |
Keeping credentials safe
- Call the API over HTTPS from your server or a trusted automation tool (Zapier, Make, n8n).
- Never put the app key or app secret in website code, a mobile app, or a public repository.
- Store credentials in environment variables or a secrets manager, not in source code.
- If a secret is exposed, regenerate it in Settings immediately — the old one stops working.
Tiktok Shop Partner
Kixmon makes it so easy to know your numbers. See all hidden costs, track every penny, and avoid profit headaches—it’s all at your fingertips.
Resources
Features
Get in Touch
Emailanna@kixmonapp.com
Phone+1 3472959050
START YOUR 7 DAY FREE TRIAL