1. What you can build on
Sublyra runs subscriptions on Shopify — billing, dunning, cancel flows, loyalty, win-backs. The developer platform is how you connect that subscription data to everything else you run: a 3PL or warehouse, an analytics pipeline, an ERP, or automations inside Shopify itself.
There are three building blocks, and they answer three different questions:
| Building block | Direction | The question it answers | Docs |
|---|---|---|---|
| REST API | You pull | "Give me the current state of my subscriptions, customers and orders." | API reference |
| Outbound webhooks | We push | "Tell my system the moment something happens." | Webhooks |
| Shopify Flow triggers | We push (inside Shopify) | "Start a Shopify Flow workflow when a subscription event occurs." | Flow triggers |
2. The REST API
A read-only JSON API for external systems. You generate an API key under Settings → Integrations in the Sublyra admin, send it as a Bearer token, and page through three resources:
GET https://app.sublyra.com/api/v1/subscriptions
GET https://app.sublyra.com/api/v1/customers
GET https://app.sublyra.com/api/v1/orders
- Read-only by design — anything but
GETgets a405. Shopify stays the source of truth; the API serves Sublyra's local mirror, kept in step by Shopify's webhooks. - Scoped to your shop — the API key itself identifies the shop. There is no shop parameter and no way to read across shops.
- Cursor pagination —
?limit=(default 50, max 250) plus an opaquenextCursorfrom each page.
Read the full API reference for response shapes and error codes, and Authentication for creating, using and rotating keys.
3. Outbound webhooks
When something happens in Sublyra — a subscription is created, a renewal charge fails, a cancel-flow offer is accepted — we POST a signed JSON event to an endpoint you control. You pick the topics under Settings → Developer:
| Topic | Fires when |
|---|---|
subscription.created | A new subscription contract starts |
subscription.updated | A contract's status or next billing date changes |
subscription.cancelled | A contract is cancelled |
order.charged | A renewal (or checkout) charge succeeds |
order.failed | A billing attempt is declined |
order.recovered | A previously failed order is charged successfully |
loyalty.reward_earned | A loyalty, streak or referral reward is earned |
cancel_flow.completed | A subscriber finishes the cancellation flow (offer accepted or not) |
Every delivery is signed with an HMAC-SHA256 signature you verify against your shop's signing secret, queued asynchronously so it never slows down checkout, and retried with exponential backoff — 5 attempts, then a manual retry button in the delivery log.
Read Webhooks for the payload envelope, signature verification code and the retry behaviour.
4. Shopify Flow triggers
If you'd rather automate inside Shopify than run an endpoint, Sublyra provides four triggers for Shopify Flow. Each starts any workflow you build — tag the customer, add order tags, send an internal email, ping a Slack webhook, anything Flow can do:
| Trigger | Starts a workflow when |
|---|---|
| Subscription created | A new Sublyra contract is created |
| Subscription cancelled | A Sublyra contract is cancelled |
| Billing attempt failed | A renewal charge is declined |
| Streak milestone reached | A subscriber crosses a streak milestone |
Each trigger carries the customer plus context fields (contract ID, interval, decline reason, milestone…). Read Flow triggers for the full field lists.
5. Shared conventions
| Convention | Rule |
|---|---|
| Money | Integer cents everywhere — totalCents: 4200 means $42.00. No floats, no currency ambiguity; all amounts are in the shop's currency. |
| Dates | ISO 8601 strings in UTC, e.g. 2026-08-24T12:00:00.000Z. Nullable fields are JSON null, never empty strings. |
| Shopify IDs | Shopify objects are identified by their gid, e.g. gid://shopify/SubscriptionContract/123. Sublyra's own records use internal IDs that are consistent across endpoints (customerId in orders matches id in customers). |
| Errors | Always JSON: { "error": { "code": "…", "message": "…" } } with a conventional HTTP status. Never an HTML error page. |
6. Quickstart
1 In the Sublyra admin, open Settings → Integrations and create an API key. Copy it — it's shown once. (Details)
2 Make your first call:
curl https://app.sublyra.com/api/v1/subscriptions?limit=50 \
-H "Authorization: Bearer cad_pk_your_key_here"
3 For live events, open Settings → Developer, paste a public https:// endpoint (a request bin like webhook.site works for a first look), tick the topics you want and save. (Details)
4 Verify signatures on every delivery with the signing secret shown on that page before you trust the payload.
7. FAQ
Can I create or modify subscriptions through the API?
No. The public API is read-only — writes return 405. Subscription changes happen in Shopify checkout, the customer portal, or the Sublyra admin; your systems read the results through the API or react to webhooks.
Should I use the API or webhooks?
Both, usually. Webhooks tell you something changed the moment it happens; the API lets you reconcile full state on your own schedule. A common pattern is webhook-driven sync with a nightly API sweep as a backstop.
What plan do I need?
Pro ($39/mo) includes API access, webhooks and Flow. On the Free plan you can add the same capabilities with the API & webhooks add-on for $19.99/mo. Full details on the pricing page.
Is there a rate limit?
The API is designed for sync workloads — page through with a sensible limit and you'll be fine. If you're planning a high-frequency integration, talk to us first via support.