Download the PHP package bagisto/bagisto-api without Composer

On this page you can find all versions of the php package bagisto/bagisto-api. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package bagisto-api

Bagisto API Platform

Comprehensive REST and GraphQL APIs for seamless e-commerce integration and extensibility.

Run in Postman

Requirements

Bagisto Compatibility

One package serves the whole 2.4 line. It detects what the store it is installed on can do, so most of the API is identical everywhere and only the theme surface follows the store.

Store Theme endpoints Permissions
v2.4.10 and newer /api/admin/appearance/themes, /api/admin/appearance/sections, /api/shop/sections and /api/shop/theme — including the draft, publish, discard, reorder, duplicate and preview flow appearance.*
v2.4.9 and older /api/admin/settings/themes with mass-delete and mass-update-status, and /api/shop/theme-customizations settings.themes.*

Only one set is registered, so endpoints the store cannot support are absent rather than failing when called. A few smaller behaviours follow the store the same way: product image alt_text, the derived columns behind the product listing, attribute regex validation, the attribute-family delete guard, and the in-use guards on email templates and marketing events.

Upgrading Bagisto is what moves the theme endpoints — the package itself needs no change. Rebuild the caches afterwards so the new surface is picked up:

Installation

Method 1: Quick Start (Composer Installation – Recommended)

The fastest way to get started:

Your APIs are now ready! Access them at:

Method 2: Manual Installation

Use this method if you need more control over the setup.

Step 1: Download and Extract

  1. Download the BagistoApi package from GitHub
  2. Extract it to: packages/Webkul/BagistoApi/

Step 2: Register Service Provider

Edit bootstrap/providers.php:

Step 3: Update Autoloading

Edit composer.json and update the autoload section:

Step 4: Install Dependencies

Step 5: Run the installation

Step 6: Environment Setup (Update in the .env)

Access Points

Once verified, access the APIs at:

Exporting the API Schema

Generate schema files for the shop and admin APIs — OpenAPI JSON (REST) and GraphQL SDL — to import into Postman, a client/code generator, or a mock server without calling a live server:

The files are written to schema/generated/:

File Contents
openapi-shop.json / openapi-admin.json OpenAPI for each REST surface
shop.graphql / admin.graphql GraphQL SDL for each surface
graphql-operations-shop.json / -admin.json Every root GraphQL field mapped to its resource tag

Each spec is scoped to its own surface — the storefront spec carries no admin path, schema or tag, and the reverse — and the command refuses to write one that leaks the other surface or references a definition it does not include.

Options:

Re-running overwrites those six files and nothing else. To rebuild the Postman collections from them:

Postman Collections

Run them from the public workspace, or import the copies that ship with the package:

Both transports are covered: requests are foldered REST/ and GraphQL/ under the same resource names, with GraphQL split into Queries/ and Mutations/.

Importing

  1. Postman → Import → pick a file from collections/.
  2. Postman → Environments → Import → pick environments/Bagisto.postman_environment.json, select it, then fill in your values.
Variable Used by Description
url Both Your Bagisto URL, e.g. http://localhost:8000
storefrontKey Shop Storefront API key, from admin → Configuration → API
customerEmail Shop A storefront customer's email
customerPassword Shop That customer's password
customerToken Shop Filled in by the Customer login request
cartToken Shop Filled in by the Create cart token request
adminToken Admin Integration token, from admin → Settings → Integration
locale Both Locale code, defaults to en
channel Both Channel code, defaults to default
currency Shop Currency code, defaults to USD

Fill in only what the collection you are using needs.

Authenticating

Shop — run REST → Customer → Customer login. It stores customerToken, which every other request sends as the bearer. For a guest cart, run Create cart token instead and set the collection's Authorization tab to {{cartToken}}; the cart and checkout endpoints serve guests and logged-in customers alike, so the token you send decides whose cart you are working on.

Admin — there is no login request. Generate an integration token in the admin panel (see Admin API Authentication) and paste it into adminToken.

Keeping them current

schema/tools/build-collection.php regenerates the collections from the exported schemas, so a collection follows the API rather than being maintained by hand. After bagisto-api-platform:export-schema writes a new schema, rerun the builder and commit both — Validate rebuilds the collections in CI and fails the push if the committed copies no longer match, so a stale collection cannot reach the workspace.

Three workflows keep the published copies in step: Validate checks the files and that rebuild on every push, Push Collections to Postman publishes them to the official workspace when they change on main, and Sync Collections from Postman pulls edits made in Postman back into the repository on a release. All three refuse to move a real storefront key.

Publishing needs four repository secrets, and the push and sync jobs skip with a notice while any of them is missing rather than failing the build:

Secret Value
POSTMAN_API_KEY A Postman API key with write access to the workspace
POSTMAN_SHOP_COLLECTION_ID UID of the Bagisto Shop API collection
POSTMAN_ADMIN_COLLECTION_ID UID of the Bagisto Admin API collection
POSTMAN_ENVIRONMENT_ID UID of the Bagisto environment

Collection and environment UIDs come from Postman — open the item, then Info → ID. Validation needs no secret and runs on every push regardless.

Values in the requests are placeholders — replace them with records that exist on your store. Postman's Auto Fetch runs a schema introspection query that costs far more than a normal request; switch it off if the GraphQL folders feel slow.

Admin API Authentication

Admin endpoints (/api/admin/* and /api/admin/graphql) require an integration-token Bearer header:

Authorization: Bearer id|generated-token

To generate a token:

  1. Log into the Bagisto admin panel.
  2. Enable the module first: navigate to Configuration → API → Integration → Module Settings and turn Enabled on. (Without this, the Integration menu stays hidden.)
  3. Navigate to Settings → Integration.
  4. Click Create, fill in the name / description / assigned admin / permission mode (All, Custom, or Same as Web) / optional IP allowlist / rate limits / expiry, and save as a draft.
  5. Click Generate. The plaintext token is shown once — copy it immediately. You won't be able to view it again; if lost, use Regenerate to issue a new one.

Each token is scoped to a single admin user and inherits that admin's role permissions — so tokens can never do more than their owner could in the admin UI. To issue tokens to multiple admins, create one token per admin (each admin can hold only one active token at a time).

Tokens can be revoked at any time from the same page or via the signed link in the lifecycle notification email sent to the token owner.

Documentation

Support

For issues and questions, please visit:

📝 License

The Bagisto API Platform is open-source software licensed under the MIT license.


All versions of bagisto-api with dependencies

PHP Build Version
Package Version
Requires api-platform/laravel Version ~4.3.8
api-platform/graphql Version ~4.3.8
symfony/property-access Version ^7.0
symfony/property-info Version ^7.1
symfony/serializer Version ^7.4.9
symfony/type-info Version ^7.3
symfony/validator Version ^7.0
symfony/web-link Version ^7.4
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package bagisto/bagisto-api contains the following files

Loading the files please wait ...