DEVELOPER PLATFORM

Build with
GORIB API

A focused interface for catalog access, balance management and instant digital delivery.

BASE URLhttps://api.goribucshop.com
01

ACCESS

Authentication

Every API request requires your personal key in the X-API-Key header. Keep it private and use it only from your backend.

⌁

API key

48 alphanumeric characters. The key remains available under My account until you regenerate it.

◇

Server-side only

Never expose the key in frontend code, mobile apps or public repositories.

Request header
X-API-Key: YOUR_API_KEY
02

FIRST REQUEST

Quick start

Request the live catalog in seconds. Replace the placeholder with your API key.

curl "https://api.goribucshop.com/api/v2/catalog" \
  -H "X-API-Key: YOUR_API_KEY"
import requests

response = requests.get(
    "https://api.goribucshop.com/api/v2/catalog",
    headers={"X-API-Key": "YOUR_API_KEY"},
    timeout=15,
)
response.raise_for_status()
print(response.json())
GET/api/v2/catalog

Returns every GORIB product with its public SKU, price and live availability.

Response

skustring

Stable GORIB product code.

fulfillmentstring

instant_code, automatic or assisted.

recipient_typestring

Which recipient value the order requires.

price_usdstring

Unit price in USD with three decimal places.

stockinteger | null

Finite code stock, or null for non-stock products.

200 OK
[
  {
    "sku": "GORIB-STARS",
    "name": "GORIB Stars",
    "category": "services/telegram/stars",
    "fulfillment": "automatic",
    "recipient_type": "telegram_recipient",
    "price_usd": "0.015",
    "available": true,
    "stock": null,
    "min_quantity": 50,
    "max_quantity": 9000
  }
]
GET/api/v2/profile

Returns account details and available balance.

Use this endpoint to

  • Display the current balance
  • Confirm account identity
  • Read the masked API key hint
200 OK
{
  "telegram_id": 123456789,
  "username": "username",
  "language": "en",
  "balance_usd": "250.000",
  "api_key_hint": "Ab12••••Xy90"
}
GET/api/v2/orders/{order_id}

Returns the current result, item statuses and any delivered customer codes.

Create order→Poll status URL→Receive final result
Private order scope

An API key can read only orders created by the same account. Internal processing details are never included.

POST/api/v2/api-key/rotate

Invalidates the current key and issues a new one.

Update integrations

The new key remains available under My account. The previous key stops working immediately.

03

REFERENCE

Error handling

StatusMeaningAction
400Invalid request or quantityValidate parameters
401Missing or invalid API keyCheck authentication
402Insufficient balanceAdd funds and retry
409Idempotency conflictUse a new unique key
422Product unavailableRefresh the catalog
04

GOOD PRACTICE

Security checklist

Treat your API key like a password. Rotate it immediately if it may have been exposed.

  • Keep credentials in environment variables or a secret manager
  • Use a new idempotency key for each checkout
  • Set request timeouts and log order IDs
  • Never publish delivered codes in application logs