Overview
The Waffo Pancake API lets you programmatically manage your entire payment infrastructure:- Create and manage stores
- Create products (one-time and subscription)
- Generate checkout sessions and process orders
- Manage subscriptions and billing
- Query data via GraphQL
- Handle refunds
Base URL
All API requests are made to:Architecture
The API uses a hybrid approach:- REST endpoints (
/v1/actions/...) for all write operations (create, update, delete) - GraphQL (
/v1/graphql) for all read operations (queries)
POST method exclusively. There are no GET, PUT, PATCH, or DELETE methods.
TypeScript SDK
The official@waffo/pancake-ts SDK wraps the entire API with full type safety. It handles authentication, request signing, idempotency keys, and webhook verification automatically.
Authentication
Waffo Pancake uses API Key authentication for all programmatic API access. API Key authentication is handled automatically by the SDK. For public-facing checkout flows, use Store Slug authentication with theX-Store-Slug header.
Learn more about authentication ->
Common Headers
API Key authentication headers (
X-Merchant-Id, X-Timestamp, X-Signature) are handled automatically by the SDK. You only need to provide your Merchant ID and private key when initializing the client.Request Format
- Method: All write endpoints use
POST - Body: JSON
- Timestamps: ISO 8601 UTC (e.g.,
2026-01-23T00:00:00.000Z) - Amounts: Display format strings (e.g.,
"29.00"= $29.00 USD) - Currencies: ISO 4217 codes (e.g.,
USD,EUR,JPY) - Status values: Always lowercase (e.g.,
active, notACTIVE)
ID Formats
All externally-facing entity IDs use Short ID format:{PREFIX}_{base62}.
Checkout Session IDs use a special format:
cs_ + UUID (e.g., cs_550e8400-e29b-41d4-a716-446655440000). They are not part of the Short ID system.Response Format
Success
Error
In the
errors array, errors[0] is the root cause of the failure. Subsequent entries represent higher-level callers in the request chain.Error layer Field
Each error includes a layer string indicating which part of the system produced the error. Use this to identify the root cause when debugging. The value is always one of the predefined layer names (e.g., "gateway", "store", "product").
HTTP Status Codes
Environments
API Key authentication determines the environment automatically based on which key verifies successfully. Store Slug authentication requires theX-Environment header:
Idempotency
Prevent duplicate write operations by including anX-Idempotency-Key header:
Let the SDK generate the key when you can — it derives a deterministic hash from
merchantId + path + body, so it is unique per request by construction. If you build the key yourself, combine your merchantId with a UUID:
Endpoint Groups
Authentication
Issue session tokens for checkout flows
Stores
Create, update, and delete stores
One-Time Products
Create and manage one-time purchase products
Subscription Products
Create tiered subscription products and groups
Orders
Create checkout sessions and orders
Subscriptions
Manage subscription lifecycle
Refunds
Request and process refunds
GraphQL
Query all data with GraphQL