customers
62 uç · /api/shop/v1/customers
İstek örnekleri ucun GERÇEK metodu ve yolundan üretilir. 62 ucun elle doğrulanmış gövde örneği henüz yok; o uçlarda iskelet gövdesizdir — uydurma bir alan yazmıyoruz.
Staff edit
customer_idaddress_idcurl -X PUT "https://{slug}.shop.blesyum.app/api/shop/v1/admin/customers/<customer_id>/addresses/<address_id>" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}Masterpass cüzdan bağla (upsert msisdn; sandbox anında bağlanır — gerçek OTP=TF21). token_ref
customer_idserver-side üretilir, dönmez. customer_token verilirse müşteriye bağlanır.
curl -X POST "https://{slug}.shop.blesyum.app/api/shop/v1/admin/customers/<customer_id>/crm-link" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}Public-api durum ucu: geçerli API versiyonu + deprecation/sunset (X-Api-Version başlığıyla).
customer_idcurl -X GET "https://{slug}.shop.blesyum.app/api/shop/v1/admin/customers/<customer_id>/crm-link" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}CRM-worker geri-yazımı (consume-seam): contact-id ile pending→synced. Idempotent.
customer_idcurl -X POST "https://{slug}.shop.blesyum.app/api/shop/v1/admin/customers/<customer_id>/crm-link/confirm" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}curl -X GET "https://{slug}.shop.blesyum.app/api/shop/v1/admin/customers/<customer_id>/wallet" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}Admin adjust
customer_idcurl -X POST "https://{slug}.shop.blesyum.app/api/shop/v1/admin/customers/<customer_id>/wallet/adjust" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}Panel: müşteriye şifre sıfırlama bağlantısı gönder (destek aksiyonu).
idcurl -X POST "https://{slug}.shop.blesyum.app/api/shop/v1/admin/customers/<id>/password-reset" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}Panel: müşteriyi anonimleştir (KVKK silme talebi — BLE2-11307). GERİ ALINAMAZ.
idcurl -X POST "https://{slug}.shop.blesyum.app/api/shop/v1/admin/customers/<id>/privacy/erase" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}Panel: müşterinin verisini dışa aktar (KVKK erişim talebi — BLE2-11307).
idcurl -X GET "https://{slug}.shop.blesyum.app/api/shop/v1/admin/customers/<id>/privacy/export" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}curl -X GET "https://{slug}.shop.blesyum.app/api/shop/v1/admin/customers/<id>/support-context" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}curl -X POST "https://{slug}.shop.blesyum.app/api/shop/v1/storefront/customers/email/change/confirm" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}curl -X POST "https://{slug}.shop.blesyum.app/api/shop/v1/storefront/customers/email/change/request" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}POST /customers/email/verify/confirm — jetonu tüket, e-postayı doğrulanmış işaretle.
curl -X POST "https://{slug}.shop.blesyum.app/api/shop/v1/storefront/customers/email/verify/confirm" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}POST /customers/email/verify/request — oturumlu müşteri için doğrulama jetonu üret.
Yanıt jetonu TAŞIMAZ (üretimde); jeton bildirim kanalıyla gider. Üretim-dışında test/geliştirme
için verification_token döner — parola-sıfırlamanın TF21-öncesi deseniyle aynı.
curl -X POST "https://{slug}.shop.blesyum.app/api/shop/v1/storefront/customers/email/verify/request" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}DNS-TXT doğrulama (STUB: pending→verified; gerçek DNS-lookup + ACME/TLS = TF21). Yoksa/pending-değilse 404.
curl -X POST "https://{slug}.shop.blesyum.app/api/shop/v1/storefront/customers/magic-link/verify" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}Satıcı kendi profili. RLS: marketplace_vendors vendor_col='id' → yalnız kendi satırı.
curl -X GET "https://{slug}.shop.blesyum.app/api/shop/v1/storefront/customers/me" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}Order detail
order_numbercurl -X GET "https://{slug}.shop.blesyum.app/api/shop/v1/storefront/customers/orders/<order_number>" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}Reorder
order_numbercurl -X POST "https://{slug}.shop.blesyum.app/api/shop/v1/storefront/customers/orders/<order_number>/reorder" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}curl -X POST "https://{slug}.shop.blesyum.app/api/shop/v1/storefront/customers/passkey/<id>/remove" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}curl -X POST "https://{slug}.shop.blesyum.app/api/shop/v1/storefront/customers/passkey/authenticate/finish" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}Giriş-başlat: e-postanın kayıtlı passkey'leri → request-options + state. Passkey'siz →
404-yerine 401-tektip (enumeration sızdırmaz).
curl -X POST "https://{slug}.shop.blesyum.app/api/shop/v1/storefront/customers/passkey/authenticate/start" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}Credential-listesi + kaldırma (müşteri-oturumu).
curl -X POST "https://{slug}.shop.blesyum.app/api/shop/v1/storefront/customers/passkey/list" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}curl -X POST "https://{slug}.shop.blesyum.app/api/shop/v1/storefront/customers/passkey/register/finish" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}Kayıt-başlat: challenge + creation-options (istemci navigator.credentials.create girdisi).
curl -X POST "https://{slug}.shop.blesyum.app/api/shop/v1/storefront/customers/passkey/register/start" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}BLE-5057 · sil (kalıcı; kullanım-geçmişi orders snapshot'ında yaşar).
curl -X POST "https://{slug}.shop.blesyum.app/api/shop/v1/storefront/customers/privacy/delete" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}Temayı ZIP olarak indir. Ajans temayı müşteriye verir, satıcı yedek alır.
curl -X POST "https://{slug}.shop.blesyum.app/api/shop/v1/storefront/customers/privacy/export" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}curl -X POST "https://{slug}.shop.blesyum.app/api/shop/v1/storefront/customers/recently-viewed/merge" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}Credential-listesi + kaldırma (müşteri-oturumu).
curl -X GET "https://{slug}.shop.blesyum.app/api/shop/v1/storefront/customers/referrals" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}Cihaz-token kaydet/güncelle (upsert token). opt_in default true; false → gelmez (opt-out). Topics
aboneliği eklenir. Geçersiz platform → 400.
curl -X POST "https://{slug}.shop.blesyum.app/api/shop/v1/storefront/customers/register" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}VPOS tanımı ekle/güncelle (upsert bank). bank 1-32 char, threed_mode 3d|non3d. config_ref saklanır
ama response'ta dönmez.
curl -X POST "https://{slug}.shop.blesyum.app/api/shop/v1/storefront/customers/returns" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}Customer attachment upload
idcurl -X POST "https://{slug}.shop.blesyum.app/api/shop/v1/storefront/customers/returns/<id>/attachments" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}Müşterinin KENDİ talebindeki ekleri listeler (yüklediğini görebilsin).
idcurl -X GET "https://{slug}.shop.blesyum.app/api/shop/v1/storefront/customers/returns/<id>/attachments" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}Müşteri iade-uygunluk (TF8 · BLE-4889 /account/returns/eligibility): oturum-token'ı ile müşteri
çözülür, sipariş SAHİPLİK doğrulanır (başkasının siparişi sorgulanamaz), sonra return_policy çekirdeği ile uygunluk/pencere/restocking-fee döner. Admin-simülatörle AYNI motoru kullanır.
curl -X POST "https://{slug}.shop.blesyum.app/api/shop/v1/storefront/customers/returns/eligibility" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}curl -X POST "https://{slug}.shop.blesyum.app/api/shop/v1/storefront/customers/sessions/revoke-others" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}3DS callback: attempt'i (pending) sonuçla — outcome='fail' → failed, aksi → authenticated. Attempt
provideryoksa/zaten-sonuçlanmışsa 404.
⚠ **GÜVENLİK — stub ACS üretimde kimlik DOĞRULAYAMAZ (fail-closed):** Bu uç ağa hiç çıkmaz;
gerçek banka ACS'i (imzalı sonuç) TF21'de gelir. outcome istekten okunduğu için, üretimde
serbest bıraksaydık saldırgan /3ds/init (acs_ref al) + /3ds/callback (outcome=success) ile
threeds_status='authenticated' yazıp risk step-up kapısını KENDİ KENDİNE geçerdi (mock-social
deseninin ödeme karşılığı). Bu yüzden ÜRETİMDE stub asla authenticated yazmaz → step-up
tamamlanamaz ve sipariş fail-CLOSED bloke kalır (gerçek step-up için TF21 ACS gerekir).
Üretim-dışında (sandbox/dev) tam akış test edilebilir kalır.
curl -X GET "https://{slug}.shop.blesyum.app/api/shop/v1/storefront/customers/social/<provider>/callback" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}Yeni asistan oturumu (unguessable token). Storefront.
providercurl -X GET "https://{slug}.shop.blesyum.app/api/shop/v1/storefront/customers/social/<provider>/start" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}Cüzdan bağını kaldır (status=removed). Yoksa 404.
idcurl -X POST "https://{slug}.shop.blesyum.app/api/shop/v1/storefront/customers/social/identities/<id>/unlink" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}curl -X POST "https://{slug}.shop.blesyum.app/api/shop/v1/storefront/customers/subscriptions/<id>/action" \
-H "Authorization: Bearer <oturum-token>" \
-H "Accept: application/json"{
"data": "…",
"trace_id": "01JC…"
}