Skip to main content
Version: 2026-06-01

Getting Started with CAFE24 API

With CAFE24 API, you can programmatically manage various data such as products, orders, and customers in your shopping mall.

API Overview​

ItemDescription
Base URLhttps://{mall_id}.cafe24api.com/api/v2
ProtocolHTTPS (TLS 1.2 or higher)
AuthenticationOAuth 2.0
Response FormatJSON
Character EncodingUTF-8

Quick Start​

1. Register App​

Register your app at CAFE24 Developer Center and obtain Client ID and Client Secret.

2. Issue Access Token​

curl -X POST "https://{mall_id}.cafe24api.com/api/v2/oauth/token" \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "grant_type=authorization_code" \
-d "code={authorization_code}" \
-d "redirect_uri={redirect_uri}" \
-d "client_id={client_id}" \
-d "client_secret={client_secret}"

3. Call API​

curl -X GET "https://{mall_id}.cafe24api.com/api/v2/admin/products" \
-H "Authorization: Bearer {access_token}" \
-H "Content-Type: application/json"

4. Check Response​

{
"products": [
{
"product_no": 1,
"product_name": "Sample Product",
"price": "10000.00",
"created_date": "2024-01-15T09:00:00+09:00"
}
]
}

API Types​

Admin API​

API for shopping mall administrators. Provides admin functions such as product registration, order management, and customer management.

  • Product Management (Products)
  • Order Management (Orders)
  • Customer Management (Customers)
  • Category Management (Categories)

Front API​

API for shopping mall frontend. Provides customer functions such as product inquiry, shopping cart, and ordering.

  • Product Inquiry
  • Shopping Cart
  • Order/Payment

Authentication (OAuth 2.0)​

CAFE24 API uses OAuth 2.0 authentication.

┌─────────┐     1. Auth Request   ┌─────────────┐
│ App │ ──────────────────▶ │ CAFE24 │
│ │ │ OAuth │
│ │ ◀────────────────── │ Server │
└─────────┘ 2. Access Token └─────────────┘
│
│ 3. API Call (Bearer Token)
▼
┌─────────────┐
│ CAFE24 │
│ API │
└─────────────┘

Token Types​

TokenValidity PeriodPurpose
Access Token2 hoursAuthentication for API calls
Refresh Token14 daysRefresh Access Token

Rate Limit​

API calls are subject to both a total volume limit (quota) and a burst rate limit. Unless configured otherwise, the following defaults apply:

TypeLimit
Requests per 10 minutes3,000 requests
Processing time per 10 minutes600 seconds

When a limit is exceeded, a 429 Too Many Requests response is returned. See the API Quota Guide for details.

Error Handling​

HTTP Status Codes​

CodeDescription
200Success
201Created
400Bad Request
401Unauthorized
403Forbidden
404Not Found
429Rate Limit Exceeded
500Internal Server Error

Error Response Format​

{
"error": {
"code": "INVALID_REQUEST",
"message": "Required parameter is missing.",
"more_info": "https://developers.cafe24.com/errors/INVALID_REQUEST"
}
}

Next Steps​