Scopes per key
A key belongs to one store and only works for the scopes you tick: subscriptions, customers, points and redemptions, read or write.
Fetching, pausing, skipping, rescheduling and cancelling subscriptions works from your own system too. Webhooks tell you what changes, and through the MCP server an AI assistant works with the same data, within the scopes you give it.
You do not have to request access. You create a key in a minute, with exactly the scopes the integration needs.
Give your ERP, your support tool and your AI assistant a key each. That shows you who does what, and you revoke one key without touching the rest.
You set an endpoint and choose the events you want to receive. Every message is signed. When delivery fails, Loyalo tries again after 1, 5, 20, 60 and 240 minutes.
Send your key in the x-api-key header. Responses are JSON; lists include a next_offset for the next page.
curl "https://mwugkfkidoakjoelhtir.supabase.co/functions/v1/v2-api/subscriptions?status=active&limit=50" \
-H "x-api-key: $LOYALO_API_KEY" curl -X POST "https://mwugkfkidoakjoelhtir.supabase.co/functions/v1/v2-api/subscriptions/SUBSCRIPTION_ID/pause" \
-H "x-api-key: $LOYALO_API_KEY" curl -X POST "https://mwugkfkidoakjoelhtir.supabase.co/functions/v1/v2-api/points" \
-H "x-api-key: $LOYALO_API_KEY" \
-H "Content-Type: application/json" \
-d '{ "customer_id": "…", "points": 100, "note": "Goodwill", "idempotency_key": "ticket-4711" }' import crypto from "node:crypto";
// Express-voorbeeld met de ruwe body (Buffer)
function verifyLoyaloWebhook(req, secret) {
const timestamp = req.header("x-loyalo-timestamp");
const signature = req.header("x-loyalo-signature");
const expected = crypto
.createHmac("sha256", secret)
.update(`${timestamp}.${req.rawBody}`)
.digest("hex");
const ok = crypto.timingSafeEqual(
Buffer.from(expected),
Buffer.from(signature ?? ""),
);
// Weiger verzoeken ouder dan 5 minuten
const fresh = Math.abs(Date.now() / 1000 - Number(timestamp)) < 300;
return ok && fresh;
} claude mcp add --transport http loyalo https://mwugkfkidoakjoelhtir.supabase.co/functions/v1/v2-api/mcp \
--header "Authorization: Bearer lo_live_xxxxxxxxxxxxxxxx" | Endpoint | Scope | What it does |
|---|---|---|
| GET /subscriptions | subscriptions | List your shop's subscriptions, newest first. |
| GET /subscriptions/{id} | subscriptions | A single subscription with lines, amount and next billing date. |
| POST /subscriptions/{id}/pause | subscriptions:write | Pauses the subscription (both Shopify and Mollie). |
| POST /subscriptions/{id}/resume | subscriptions:write | Resumes a paused subscription. |
| POST /subscriptions/{id}/skip | subscriptions:write | Skips the next delivery; the date moves one interval forward. |
| POST /subscriptions/{id}/reschedule | subscriptions:write | Moves the next delivery to another date (within a year). |
| POST /subscriptions/{id}/cancel | subscriptions:write | Cancels the subscription permanently. |
| GET /customers | customers | Customers with point balance, spend and language preference. |
| GET /points | points | Point transactions, optionally filtered by customer. |
| POST /points | points:write | Add (positive) or remove (negative) points. Give the customer by customer_id (Loyalo's), shopify_customer_id or email: exactly one. The same idempotency_key (or Idempotency-Key header) never books twice. |
| GET /redemptions | redemptions | Redeemed discounts with code, status and expiry. |
| GET /ping | — | Validates your key and returns the shop and its scopes. |
Next to Shopify's own webhooks, which are about orders and customers, Loyalo sends events about the subscription and the points.
| Event | When |
|---|---|
| subscription.created | New subscription created |
| subscription.updated | Subscription changed (date, lines, frequency) |
| subscription.paused | Subscription paused |
| subscription.resumed | Subscription resumed |
| subscription.cancelled | Subscription cancelled |
| subscription.payment_failed | Payment attempt failed |
| points.changed | A customer's point balance changed |
| ping | Test message (button in Loyalo) |
A key belongs to one store and only works for the scopes you tick: subscriptions, customers, points and redemptions, read or write.
By default 120 requests per minute per key. Go over it and you get a 429; try again a little later.
Adding points with an idempotency key never books twice, not even when your request is sent again after a timeout.
Every webhook carries a signature: HMAC-SHA256 over the timestamp and the body, with your endpoint's secret. You reject old messages.
Loyalo is an MCP server as well. An assistant such as Claude or ChatGPT uses the same operations as tools, and can look up or pause a subscription in plain language.
How to connect an assistantTell your ERP that a subscription started or was cancelled, and fetch the running subscriptions for your planning.
Pause or reschedule a subscription from your own support tool, without switching screens.
Add points for a purchase at a fair or in your own app, and read a customer's balance.
Fetch subscriptions, customers and points for your data warehouse or your BI tool.
Yes. A REST API for subscriptions, customers, points and redemptions, with keys you create yourself in the dashboard. The API is in every plan.
With an API key in the x-api-key header, or as a Bearer token. You create the key under Settings > API & webhooks. A key belongs to one store and cannot be retrieved after it is created, so store it safely.
Seven events: a subscription that was created, changed, paused, resumed or cancelled, a failed collection and a changed point balance. There is also a test message you send with a button.
Loyalo retries the delivery after 1, 5, 20, 60 and 240 minutes. In the dashboard you see every delivery with its result and resend a failed delivery by hand. Respond with a 2xx status within 10 seconds.
Every delivery has the headers x-loyalo-timestamp and x-loyalo-signature. The signature is an HMAC-SHA256 over 'timestamp.body' with your endpoint's secret. Compare in constant time and reject requests older than five minutes.
Only when you give it a key with write scopes. With a read-only key an assistant can look things up and summarise, but change nothing.
Yes. Orders and customers are in Shopify, and a card subscription is a contract there; you read those through Shopify as usual. Loyalo's API adds what Shopify does not have: pausing, skipping and rescheduling in one request, iDEAL subscriptions and points.
In half an hour we show you how Loyalo works in your shop, or we send you an install link right away. The trial runs for 14 days and needs no credit card.
Questions about an integration? In a demo we look at what you want to build.