Connect a Merchant and Authenticate

Your integration cannot do anything useful until a merchant is connected to it. This guide covers linking a demo merchant, generating merchant credentials, and authenticating your API requests.

Before you start you need an approved partner account and an approved integration with its Client ID and Secret. If you do not have those yet, see the onboarding overview and Create an Integration.

Step 1 — Connect a demo merchant account

To test your integration end to end you need a demo merchant account linked to it.

Register the demo merchant at merchant-demo.mypos.eu/en/onboarding, providing:

  • Name
  • Email
  • Mobile phone number

Then connect that merchant to your integration: open the Summary tab of your integration, copy your personal integration share link from the Share section, and send it to the merchant. Once they approve, the merchant is tied to your integration and you can build and test against it. See Share the approval link.

Use the demo onboarding URL above, not the live merchant site. Demo merchants only work with Demo integration credentials.

Step 2 — Get merchant credentials

After a merchant is connected, go to the Merchants tab. The merchant appears as a card marked Active, showing the date access was granted and a Generate button.

Click Generate to issue API credentials for that merchant. The Integration Merchant API credentials dialog opens with the merchant Client Secret. Use the copy button next to the field to copy it before you click Confirm — the secret is not shown again. These credentials are separate from your integration credentials.

Once confirmed, the merchant card replaces Generate with View and Regenerate. Use View to see the existing credentials, or Regenerate to issue a new set if they are compromised.

View reopens the Integration Merchant API credentials dialog. The merchant Client ID is shown in full and can be copied with the button beside it, while the Client Secret stays masked. If you no longer have the secret, use Regenerate to issue a new pair.

There are two credential levels:

CredentialsWhere to find themWhat they produceWhat it does
Integration Client ID + SecretIntegration → SettingsBearer tokenAuthenticates your integration
Merchant Client ID + SecretMerchants tabX-Session IDScopes requests to a specific connected merchant

Secrets are shown only once. Copy and store them securely as soon as they are generated.

POS hardware integrations only: you can also request an optional Demo POS device from Sales Ops, including your shipping address.

Step 3 — Authenticate your requests

Authentication happens in two stages, one per credential level.

  1. Bearer token — generate it from your Partner Client ID and Partner Secret. It authenticates your integration and is valid for 1 hour.
  2. X-Session ID — generate it from the Merchant ID, Merchant Secret, and the bearer token. It scopes each request to one connected merchant.

On every request include the Application ID, Partner ID, and Session ID headers, and use the bearer token for authorization. When the bearer token expires, generate a new bearer token and a new Session ID before continuing.

Exception: the eCommerce API does not require authorization.

Full request and response formats are in the myPOS API Gateway reference.

Step 4 — Track progress and go live

You can follow your setup via the Checklist in the Portal, where tasks are grouped into Initial setup, Testing, and Deployment. When your integration is tested and ready, we will help you transition from Demo to Production.