Integration and API
Catalogue, orders, codes, balance and events — by request, not by email. Here is what is built and open externally, and what is worth knowing about automatic delivery on a marketplace.
What our API can do today
Catalogue with prices and stock
Items, wholesale prices, stock and — once the grid is filled — volume tiers come in one response. The entire price list is exported as a file from the same snapshot: by construction there is no discrepancy between the file and the API.
An order that will not be executed twice
Repeating a request with the same idempotency key returns the response of the first order rather than creating a second one. The network dropped midway — just repeat: there will still be one charge.
Codes are retrieved by request
Issued codes are kept with the order and can be re-read any number of times. The response survives our restart word for word — a code is not “shown only once”.
Events via webhooks
Subscription to order and balance events, request signing, retries and event replay on demand. No need to poll us in a loop.
Balance and transaction log
The balance and every movement — top-up, charge for an order, refund — are visible by request and match what the account shows.
What is open externally TODAY, and what is not yet
The production API address is https://kodrio.com: you issue a production key in the account after company verification, and it already reads the catalogue, prices and balance; order intake with a production key is not open yet. The API has no test environment: your first order will be a production one.
We say this on the very first integration page rather than in small print at the bottom, because for you it is a planning question: code for our API can be written today, and put on production traffic — after our announcement. Promising “everything works” and then getting the question “why does the production key return an error” is the worst way to start.
How to connect
You set the production key, its permissions and the list of addresses it is accepted from yourself, in the account, section «Access keys»; the addresses and everything else are in the API documentation. After that no login is needed — the whole path is covered by the documentation.
Automatic delivery on Yandex.Market: what you need to know
We do not provide a ready-made Market integration — you build delivery with your own code. But the Market contract is designed so that one wrong line costs a stream of orders, and it is better to know about it in advance than afterwards.
Mechanism
The DBS model: Market sends you a webhook about the order, you pass the code via the deliverDigitalGoods method, and Market delivers the key to the buyer itself. The EMAIL and ACTIVATION_CODE subtypes are delivered this way; STEAM_GIFT and CHAT are not delivered by this method — for them the order status is changed.
Deadlines you are obliged to meet
Response to the webhook — 200 no later than 10 seconds, to the verification PING — within one second. The code itself must be passed within 30 minutes after the order moves to processing. This means that receiving the webhook and issuing the code must be done by different parts of your system.
The most expensive mistake
A 400 response from you — and Market stops retries for this order FOREVER. Any temporary failure must be answered with 500, never 400. Orders then stop arriving silently: there will be no errors in your log.
One order — one set
Market may send a webhook about the same order twice. The Market order ID must be a unique key on your side, otherwise the buyer gets a second code for the same money — which is now yours.
Frequently asked
Can I already run production traffic through you?
Not yet. The production API address is https://kodrio.com, and after company verification a production key already reads the catalogue, prices and balance, but order intake with a production key is not open yet. We will announce the opening with a separate line in the changelog. You can write the code today.
What do I need to start connecting?
An access key from us and our public documentation. Login and correspondence with a manager play no part in this path: catalogue, order and codes are covered by the documentation. The key's permissions and the list of allowed addresses come with it — there is no machine “what are my permissions” endpoint to check them, so keep them next to the key.
Can I test everything without spending money?
No: the API has no test environment, and your first order will be a production one. Before it, check your integration against the catalogue, prices and balance — those requests move no money — and against the documentation: order fields, error codes, idempotency and events are described there.
What happens if my request was cut off and I do not know whether the order went through?
Repeat it with the same idempotency key. We will return the response of the first order rather than create a second one, and there will still be one charge. You can also check the order state separately by requesting it by its number — the issued codes are kept there too.
How will I know an order has been fulfilled without polling you in a loop?
By subscribing to events: we send them via webhook, sign the request and retry delivery on failure. A missed event can be requested again.
Do you have a ready-made connector to Yandex.Market or another marketplace?
No. We provide the catalogue, orders and codes via the API, and you build the integration with a specific marketplace with your own code. What exactly to take into account in the Market contract is described above on this page.
FAQ
How batches, delivery, balance and key-based connection work — short answers without negotiations.
FAQ