For developers & AI

API, webhooks and MCP for your Shopify subscriptions

Fetching, pausing, skipping, rescheduling and cancelling subscriptions works from your own system too. Webhooks tell you what changes, and through the MCP server an AI assistant works with the same data, within the scopes you give it.

12
endpoints for subscriptions, customers and points
7
webhook events, signed with HMAC-SHA256
6
scopes you switch on or off per key
120/min
requests per key, adjustable
In your dashboard

You manage keys and webhooks yourself

You do not have to request access. You create a key in a minute, with exactly the scopes the integration needs.

API keys

One key per integration

Give your ERP, your support tool and your AI assistant a key each. That shows you who does what, and you revoke one key without touching the rest.

  • Scopes per key: read, or write as well
  • A limit of its own per key
  • You see when a key was last used
  • A key cannot be retrieved after it is created
API keys in Loyalo with the scopes, the limit and the last use per key, and the address of the REST API and the MCP server
Webhooks

Hear it as soon as something changes

You set an endpoint and choose the events you want to receive. Every message is signed. When delivery fails, Loyalo tries again after 1, 5, 20, 60 and 240 minutes.

  • Send a test message with one button
  • The latest deliveries with status and number of attempts
  • Resend a failed delivery by hand
  • Switch an endpoint off for a while
Webhooks in Loyalo: an endpoint with the chosen events and the latest deliveries with their result
Examples

Your first request in five minutes

Send your key in the x-api-key header. Responses are JSON; lists include a next_offset for the next page.

curl "https://mwugkfkidoakjoelhtir.supabase.co/functions/v1/v2-api/subscriptions?status=active&limit=50" \
  -H "x-api-key: $LOYALO_API_KEY"

Full API documentation

REST API

The endpoints of the subscription API

The endpoints of the subscription API
EndpointScopeWhat it does
GET /subscriptionssubscriptionsList your shop's subscriptions, newest first.
GET /subscriptions/{id}subscriptionsA single subscription with lines, amount and next billing date.
POST /subscriptions/{id}/pausesubscriptions:writePauses the subscription (both Shopify and Mollie).
POST /subscriptions/{id}/resumesubscriptions:writeResumes a paused subscription.
POST /subscriptions/{id}/skipsubscriptions:writeSkips the next delivery; the date moves one interval forward.
POST /subscriptions/{id}/reschedulesubscriptions:writeMoves the next delivery to another date (within a year).
POST /subscriptions/{id}/cancelsubscriptions:writeCancels the subscription permanently.
GET /customerscustomersCustomers with point balance, spend and language preference.
GET /pointspointsPoint transactions, optionally filtered by customer.
POST /pointspoints:writeAdd (positive) or remove (negative) points. Give the customer by customer_id (Loyalo's), shopify_customer_id or email: exactly one. The same idempotency_key (or Idempotency-Key header) never books twice.
GET /redemptionsredemptionsRedeemed discounts with code, status and expiry.
GET /ping—Validates your key and returns the shop and its scopes.
Webhooks

The events you can receive

Next to Shopify's own webhooks, which are about orders and customers, Loyalo sends events about the subscription and the points.

The events you can receive
EventWhen
subscription.createdNew subscription created
subscription.updatedSubscription changed (date, lines, frequency)
subscription.pausedSubscription paused
subscription.resumedSubscription resumed
subscription.cancelledSubscription cancelled
subscription.payment_failedPayment attempt failed
points.changedA customer's point balance changed
pingTest message (button in Loyalo)
Reliable

Built to rely on

Scopes per key

A key belongs to one store and only works for the scopes you tick: subscriptions, customers, points and redemptions, read or write.

Rate limit

By default 120 requests per minute per key. Go over it and you get a 429; try again a little later.

Never booked twice

Adding points with an idempotency key never books twice, not even when your request is sent again after a timeout.

Signed messages

Every webhook carries a signature: HMAC-SHA256 over the timestamp and the body, with your endpoint's secret. You reject old messages.

AI agents

An MCP server for your AI assistant

Loyalo is an MCP server as well. An assistant such as Claude or ChatGPT uses the same operations as tools, and can look up or pause a subscription in plain language.

How to connect an assistant
  • Connect with one address and an API key as Bearer token
  • The assistant only sees the tools its key's scopes allow
  • Give it read scopes only, or write scopes as well when it may change things
  • A key of its own per assistant, which you revoke separately
  • Works with any client that supports MCP over HTTP
Use cases

What you build with it

ERP and warehouse

Tell your ERP that a subscription started or was cancelled, and fetch the running subscriptions for your planning.

Customer service

Pause or reschedule a subscription from your own support tool, without switching screens.

Points from other channels

Add points for a purchase at a fair or in your own app, and read a customer's balance.

Your own reporting

Fetch subscriptions, customers and points for your data warehouse or your BI tool.

Frequently asked questions from developers

Does Loyalo have an API?

Yes. A REST API for subscriptions, customers, points and redemptions, with keys you create yourself in the dashboard. The API is in every plan.

How do I authenticate?

With an API key in the x-api-key header, or as a Bearer token. You create the key under Settings > API & webhooks. A key belongs to one store and cannot be retrieved after it is created, so store it safely.

Which webhooks does Loyalo send?

Seven events: a subscription that was created, changed, paused, resumed or cancelled, a failed collection and a changed point balance. There is also a test message you send with a button.

What happens when my endpoint is unreachable for a while?

Loyalo retries the delivery after 1, 5, 20, 60 and 240 minutes. In the dashboard you see every delivery with its result and resend a failed delivery by hand. Respond with a 2xx status within 10 seconds.

How do I check that a webhook comes from Loyalo?

Every delivery has the headers x-loyalo-timestamp and x-loyalo-signature. The signature is an HMAC-SHA256 over 'timestamp.body' with your endpoint's secret. Compare in constant time and reject requests older than five minutes.

Can an AI assistant change subscriptions?

Only when you give it a key with write scopes. With a read-only key an assistant can look things up and summarise, but change nothing.

Can I use the Shopify API for subscriptions as well?

Yes. Orders and customers are in Shopify, and a card subscription is a contract there; you read those through Shopify as usual. Loyalo's API adds what Shopify does not have: pausing, skipping and rescheduling in one request, iDEAL subscriptions and points.

Read on: API documentationIntegrationsAnalytics

Demo

Request a demo or a trial

In half an hour we show you how Loyalo works in your shop, or we send you an install link right away. The trial runs for 14 days and needs no credit card.

Build on your subscriptions

Questions about an integration? In a demo we look at what you want to build.