API DOCS
Connect Picklo to your own systems.
The Picklo API runs at https://app.picklo.io/api/v1. Access uses a short-lived token obtained with an API key you create in the panel.
QUICK START
Your first order in four steps.
- 1
Create an API key
Create a new key on the API keys screen in the panel and choose the scopes you need. The key is shown only once.
- 2
Get an access token
Send the key in the X-API-Key header; a short-lived access token is returned.
curl -X POST https://app.picklo.io/api/v1/token \ -H "X-API-Key: <your-api-key>" - 3
Send an order
source and external_ref together identify the order: an order arriving again with the same pair is not processed twice. A successful request returns 201.
curl -X POST https://app.picklo.io/api/v1/orders \ -H "Authorization: Bearer <token>" \ -H "Content-Type: application/json" \ -d '{"source": "mystore", "external_ref": "ORD-1001", "payload": { ... }}' - 4
Read shipped orders
The response contains items and next_cursor; pass next_cursor back as-is to get the next page.
curl "https://app.picklo.io/api/v1/fulfillments?since=2026-10-01T00:00:00Z&limit=50" \ -H "Authorization: Bearer <token>"
SCOPES
A key can only do what you allow.
| Scope | Permission |
|---|---|
| orders:write | Send orders |
| orders:read | Read orders and shipped orders |
| inventory:read | Read inventory |
| products:read | Read products |
| warehouses:read | Read warehouse details |
WEBHOOKS
Get notified when an order ships.
When an order ships (order.fulfilled), a notification is sent to the address you set. The HMAC-SHA256 signature of the request body comes in the X-WMS-Signature header; verify it with your webhook secret. An unreachable notification is retried up to 5 times.
- order.fulfilled event
- HMAC-SHA256 signature
- Delivery history in the panel
GET STARTED
Ready to digitize your
warehouse operations?
Digitize your e-commerce and retail operations with Picklo and grow faster.