Etsy API Integration Service: Scope, Access and How to Hire
What an Etsy API integration service covers, which Etsy API access tier you need, plus OAuth, webhooks, rate limits and what to ask before you hire.
Long Nguyen
Lập trình viên Fullstack · Kỹ sư AI · Nhà nghiên cứu
What an Etsy API integration service covers
An Etsy API integration service connects a shop's Etsy data (listings, inventory, orders and tracking) to the systems you already run, through Etsy's Open API v3, and keeps both sides in sync. The other side is usually a storefront, an ERP or Odoo instance, a shipping tool or a multichannel platform.
Scope it by workstream, not as "connect Etsy". Each row below is separate work with its own failure modes, and each maps to a specific permission scope in Etsy's OAuth model.
| Workstream | What it does | Scope it needs |
|---|---|---|
| Listing publishing | Creates drafts, uploads images or digital files, activates listings | listings_w (listings_d to delete) |
| Inventory and price sync | Pushes stock, SKU and price changes, including variations | listings_w |
| Order import | Pulls paid orders (receipts) into your system | transactions_r |
| Fulfillment push | Sends carrier and tracking code back to Etsy | transactions_w |
| Shop setup data | Creates shipping and processing profiles | shops_w |
| Monitoring and recovery | Retries, alerts, reconciliation runs | None (operational work) |
Two things are outside any legitimate integration. Scraping Etsy pages to get data the API doesn't give you is prohibited under Etsy's commercial-access criteria, and Open API v3 has no endpoint for buying shipping labels, so the seller still buys and prints labels themselves.
Which Etsy API access tier you need: Seller App, Personal App or Commercial Access
Etsy gates the API by app type. The choice decides who can connect, how fast you get approved, and whether the integration can ever serve more than one shop. As of , the developer documentation defines three levels.
| Seller App | Personal App | Commercial Access | |
|---|---|---|---|
| Built for | A seller's tools for their own shop | Developers building beyond one shop at limited scale | Apps that many sellers connect to |
| Shop access | Your registered shop only | Limited, based on the approved use case | Any seller who grants OAuth consent |
| Commercial use | Not permitted | Limited to the approved use case | Permitted after approval |
| Approval | Automated, minutes for eligible sellers | Deeper manual review | Manual commercial review, needs an approved Personal App first |
The rule we apply in practice: if the integration serves one shop, the shop owner registers a Seller App under their own Etsy account and the developer builds against that key. Etsy only approves a Seller App for a seller with no other active app, and the app can authenticate only with the shop that registered it. An agency therefore cannot reuse one agency-owned key across several client shops, and should not try. The side benefit is clean ownership: credentials and integration stay with the client if the contract ends.
If you are building a product other sellers will connect to, you start with a Personal App and then request Commercial Access. The documented review criteria include compliance with the API Terms of Use and caching policy, no screen-scraping, OAuth for anything touching private member data, app names and artwork that follow Etsy's trademark policy, and a prominent notice that Etsy does not endorse or certify the app. Commercial apps that use transactions_r must also request the buyer_email field separately. Etsy publishes no review timeline, only that it varies by use case, so treat approval as a dependency on your critical path. The full criteria sit on Etsy's Open API v3 introduction.
Build it yourself, use an app, or hire an Etsy API integration service
There are three realistic routes. The right one depends on how far your Etsy workflow departs from the standard listing-and-order flow.
| Route | Fits when | Trade-off |
|---|---|---|
| Existing multichannel app | Standard listing and order flow across several marketplaces, no custom rules | You accept its field mapping and sync schedule; edge cases wait on the vendor |
| Build in-house | You have engineers and a single shop | You own OAuth refresh, rate limits, variation mapping and on-call for failures |
| Hire an integration service | Etsy must talk to your own store, ERP or Odoo with custom rules: SKU mapping, stock reservation, tracking from your own carrier | Priced to scope; the key should still live in your own Seller App |
Etsy is rarely the only channel. Netalith's marketplace integration service for Etsy, Amazon SP-API, eBay, Walmart and Temu covers Etsy next to those channels, so stock and order logic can be designed once for all of them instead of once per marketplace.
A quick test for whether custom work pays off: list the places where a standard app would force you to fix data by hand, such as overselling after a variant change or late tracking uploads. If that list is short, buy an app. If it is long, the integration is the product and it deserves a written scope.
How Etsy API authentication works and what breaks it
Etsy Open API v3 uses two credentials together: an API key on every request, and an OAuth 2.0 token for anything private or any write. The facts a developer needs are below.
| Item | What Etsy specifies |
|---|---|
| API key header | x-api-key: keystring:shared_secret on every request |
| Grant type | Authorization code with PKCE (S256), required on every authorization flow |
| Access token | Valid for 1 hour, sent as a Bearer token; the value starts with the numeric user id, so send the whole string |
| Refresh token | Valid for 90 days; a refresh grant returns a new access token and refresh token without asking the seller again |
| Scope changes | Require the seller to re-authorize |
| Redirect URI | Must use https and match the registered URL exactly, including case and trailing slash |
Three failures account for most "the integration just stopped" tickets. First, the refresh response is not persisted, so the next refresh uses a stale token and the seller has to reconnect. Persist whatever the latest response returns, and alert well before the 90-day mark on any shop that hasn't refreshed. Second, the granted scope can be a subset of the requested one, so check the scope field in the token response instead of assuming write access. Third, a scope missing for one workstream usually shows up as failures on specific calls only, which looks like a random bug until someone compares scopes.
One documentation trap: a few tutorial examples send only the keystring in x-api-key, while the authentication page specifies keystring and shared secret joined by a colon. Follow the authentication page.
What you can sync through the Etsy API: endpoints and scopes
Every path below sits under https://api.etsy.com/v3/application. Confirm each endpoint's exact scope in Etsy's API reference before you request permissions from a seller, because asking for more scopes than the app needs lowers the chance the seller approves.
| Task | Endpoint | Scope |
|---|---|---|
| Create a draft listing | POST /shops/{shop_id}/listings |
listings_w |
| Upload a listing image | POST /shops/{shop_id}/listings/{listing_id}/images |
listings_w |
| Upload a digital file | POST /shops/{shop_id}/listings/{listing_id}/files |
listings_w |
| Publish or deactivate | PATCH /shops/{shop_id}/listings/{listing_id} with state |
listings_w |
| Read or replace inventory | GET and PUT /listings/{listing_id}/inventory |
listings_r, listings_w |
| Create a shipping profile | POST /shops/{shop_id}/shipping-profiles |
shops_w |
| Create a processing profile | POST /shops/{shop_id}/readiness-state-definitions |
shops_w |
| Read orders (receipts) | GET /shops/{shop_id}/receipts |
transactions_r |
| Add tracking to an order | POST /shops/{shop_id}/receipts/{receipt_id}/tracking |
transactions_w |
The minimum body for a physical draft listing is quantity, title, description, price, who_made, when_made and taxonomy_id, plus shipping_profile_id and readiness_state_id. image_ids is required before the listing can go active. That dependency chain (shipping profile, processing profile, taxonomy, images) is why a first listing takes longer to automate than the request body suggests.
Webhooks or polling for Etsy orders
Etsy now offers webhooks, so an integration no longer has to poll for every new order. Etsy's webhook documentation lists four events, all order-related.
| Event | Delivered when |
|---|---|
order.paid |
An order receives payment |
order.canceled |
A seller initiates a cancelation |
order.shipped |
Shipping information is created for a receipt |
order.delivered |
An order is marked as delivered |
The payload is a pointer, not the order: it carries event_type, resource_url and shop_id, and your code calls resource_url to fetch the receipt. The docs say webhooks are available for commercial and personal apps. They do not mention Seller Apps, so confirm in your developer portal before designing a Seller App integration around them.
Every delivery is signed. The signed content is the webhook-id, the webhook-timestamp and the raw body joined with dots; the key is your signing secret with the whsec_ prefix removed and the rest base64-decoded; the signature is a base64 HMAC-SHA256. A working verifier in Python:
import base64, hashlib, hmac, time
def verify_etsy_webhook(secret, headers, raw_body, tolerance=300):
msg_id = headers["webhook-id"]
ts = headers["webhook-timestamp"]
if abs(time.time() - int(ts)) > tolerance:
return False # stale or replayed
key = base64.b64decode(secret.removeprefix("whsec_"))
signed = f"{msg_id}.{ts}.".encode() + raw_body
expected = base64.b64encode(
hmac.new(key, signed, hashlib.sha256).digest()
).decode()
# header may hold several signatures; drop a version prefix if present
return any(
hmac.compare_digest(expected, part.split(",", 1)[-1])
for part in headers["webhook-signature"].split()
)
Verify against the raw bytes before any JSON parsing, and use webhook-id as your idempotency key, since Etsy keeps the same id across retries. If your endpoint fails, Etsy retries on a schedule of immediately, then 5 seconds, 5 minutes, 30 minutes, 2 hours, 5 hours and 10 hours twice, roughly 27.5 hours from first attempt to last.
Do not drop polling entirely. The documented events cover orders only, so listing and inventory changes still need scheduled reads, and a reconciliation pass that compares your order list against Etsy's catches anything a failed endpoint missed.
Etsy API rate limits and how a good integration stays under them
Etsy enforces limits per application, meaning per API key, as queries per second (QPS) and queries per day (QPD). The daily limit is a sliding 24-hour window, not a midnight reset, so quota frees up continuously as old requests age out. Your app's actual numbers are shown in the Etsy Developer Portal.
The design consequence that matters most: the budget belongs to the key, not the shop. Every shop connected through one app draws from the same pool, so a single seller running a bulk relist can starve the others. A multi-shop integration needs a shared request queue with fair scheduling, and order and tracking calls should outrank catalog refreshes.
- Every successful response reports
x-limit-per-dayandx-remaining-today(plus per-second equivalents), so log them and alert before you hit zero. - Etsy checks QPS first, then QPD. Exceeding either returns
429with aretry-afterheader. - Treat
retry-afteras an estimate and add exponential backoff with jitter, so a batch of workers does not retry in lockstep. - Cache reads that rarely change, such as taxonomy nodes and shipping profiles.
- Need more? Email [email protected] with a description of the app and a QPD/QPS estimate. Etsy's process asks for both.
Etsy API gotchas that break listing and order sync
These come from Etsy's own tutorials and reflect where integrations fail after the first successful test. One item is date-sensitive: video handling changes on .
| Gotcha | What happens | Handle it by |
|---|---|---|
| Variations at creation | They cannot be added when a listing is created | Create the draft first, then send variations through the inventory endpoint |
| Partial inventory updates | The inventory PUT expects the entire set of products, not a diff |
Read the current inventory, modify it, send it back whole; the docs cap products per listing (70 with one variation, 4,900 with two) |
| Processing time fields | Physical listings need a readiness_state_id; the older min and max processing time fields were flagged for removal by Q1 2026 |
Audit older code and use readiness states (ready_to_ship or made_to_order) |
| Digital listings | Files upload separately from the draft, and buyers who already purchased keep the old file version | Plan file versioning; converting a physical listing that has variations to digital returns a 409 until inventory is reset to one product |
| Publishing without an image | A listing without at least one image stays inactive | Upload images before setting state to active |
| Tracking upload | A successful call emails the buyer, and a malformed ship_date is silently ignored |
Test on a test shop, send ISO 8601 UTC dates |
| Carrier names | The carrier_name must match Etsy's list, and some carriers are accepted without tracking updates |
Map carriers explicitly; Etsy's table lists Vietnam Post as vnpost and vnpost-ems, both with tracking updates |
| Listing videos | From October 21, 2026 a listing can hold up to 2 active videos; a third upload returns 409 | Read and display up to two videos, and send is_multi_video to opt in during the transition |
What to ask before you hire an Etsy API integration provider
These questions separate a provider who has run Etsy integrations in production from one who has read the docs once.
- Whose Etsy developer account will own the app and key? For a single shop it should be yours, through a Seller App.
- Which access tier do you plan to use, and what happens if Etsy declines Commercial Access?
- Where are refresh tokens stored, and what alerts you before a shop needs to reconnect?
- How do you allocate the per-key rate budget, and what happens on a
429? - Do you use webhooks, scheduled reconciliation, or both?
- How do you map variations, SKUs and quantity across Etsy and my system?
- What happens to a failed sync: retry, dead-letter queue, human alert?
- What do I receive at handover: source code, environment notes, runbook?
If you already know which systems Etsy has to connect to, describe them in Netalith's free quote form. Etsy work is priced to scope, so the more specific the request, the more accurate the quote.
CÂU HỎI THƯỜNG GẶP
Câu hỏi thường gặp
What is an Etsy API integration service?
It is a build-and-maintain service that connects an Etsy shop's listings, inventory, orders and tracking to another system, such as your store, ERP or shipping tool, using Etsy Open API v3. It typically covers OAuth setup, sync logic, rate-limit handling, and monitoring.
Do I need Commercial Access to integrate my own Etsy shop?
No. A seller building tools for their own shop can register a Seller App, which Etsy approves automatically for eligible sellers. Commercial Access is for apps that other sellers connect to, and it requires an approved Personal App first plus a manual review.
How long do Etsy API OAuth tokens last?
Access tokens are valid for 1 hour and refresh tokens for 90 days. A refresh grant returns a new access token and refresh token without asking the seller to approve again, as long as the scope stays the same.
Does the Etsy API support webhooks?
Yes. Etsy's documentation lists four order events: order.paid, order.canceled, order.shipped and order.delivered. Deliveries are signed and retried on a schedule. The documented events cover orders only, so listing and inventory changes still need polling.
What happens when an integration hits the Etsy API rate limit?
Etsy returns a 429 status with a retry-after header. Limits apply per API key as queries per second and queries per day over a sliding 24-hour window. A good integration queues requests, backs off exponentially, and asks Etsy for a higher limit by email when needed.
Can an Etsy integration buy shipping labels?
No. Open API v3 has no endpoint for purchasing shipping. An integration can send the carrier and tracking code back to Etsy through the tracking endpoint, but the seller buys and prints labels themselves.
Can the Etsy API list digital products?
Yes. Create a draft listing, upload the digital file with the listing files endpoint, and set the listing type to download. Files are managed separately from the draft, and buyers who already purchased keep the version they bought.
How much does an Etsy API integration cost?
It depends on scope: which workstreams are needed (listings, inventory, orders, tracking), how many systems connect to Etsy, and how much custom variation or SKU mapping is involved. Netalith prices Etsy work to scope after reviewing your requirements.