Versioned REST
A stable /v1 API for products, hierarchies and assets. Each tenant has its own tokens; each token sees only its entitled scope.
Shops, DXPs, apps, marketplaces and feeds take product data from one versioned API — filtered to what each consumer is entitled to see, delivered the way each one needs it, and reduced to what actually changed.
01 · What it does
A stable /v1 API for products, hierarchies and assets. Each tenant has its own tokens; each token sees only its entitled scope.
Consumers ask what changed since their last sync and receive exactly that, at field level — about 95% smaller than a full export.
Let the shop poll, let the CMS subscribe to signed webhooks, or deliver exports on a schedule. Mix patterns per integration.
The PIM Gate API is versioned in the path. Integrations built against /v1 keep working as the platform evolves; breaking changes ship under a new version, never silently. Products come back in the canonical schema with their attribute metadata, resolved for the market and locale you request, including fallbacks. Hierarchies and assets are first-class resources.
REST API
A stable, versioned contract for your integrations.
API tokens are issued per tenant and tied to an entitlement scope: a catalog view, markets and languages. Filtering happens server-side before a response is built, so a consumer cannot request its way into data it isn't entitled to — whatever query it sends. Rate limiting protects the platform and your integrations from runaway clients; monthly call volumes are part of your version.
Tokens & entitlements
Every token sees its own catalog — enforced on the server.
Every export in PIM Gate is versioned, and changes are tracked at field level. A consumer calls /v1/sync/diff?since= with the time of its last successful sync and receives the created, updated and removed products — and for updates, only the fields that changed. Payloads are about 95% smaller than full exports, syncs finish faster, and downstream systems stop re-processing records that didn't move.
Delta sync
Ask what changed. Get only that.
Different consumers need data differently. Pull suits shops and apps that fetch on demand. Signed webhooks notify a DXP the moment a product changes, with a pointer to the delta. Push delivers to endpoints you configure, and scheduled delivery produces versioned exports at fixed times for partners that work with files. Every pattern draws from the same validated, entitled data.
Delivery patterns
The shop polls, the CMS subscribes, the feed arrives on time.
06 · Examples
Illustrative requests against a demo tenant with fictional MESSARA data. Field names follow the canonical schema; the full reference ships with the OpenAPI documentation.
GET /v1/products?market=CH&locale=de-CH&limit=2Host: messara.pimgate.aiAuthorization: Bearer pg_live_••••••••••••// token scope: view=installers-ch · market=CHHTTP/1.1 200 OK{ "data": [ { "sku": "MS-12011", "version": 42, "updated_at": "2026-09-24T02:04:11Z", "product_group": "druckmesstechnik", "name": { "de-CH": "Rohrfeder-Manometer D63, 0–10 bar, G 1/4 unten" }, "attributes": { "measuring_range_max": { "value": 10, "unit": "bar" }, "nominal_size": { "value": 63, "unit": "mm" }, "process_connection": { "value": "G 1/4 unten" }, "gtin": { "value": "4260000120114" } }, "price": { "list": 41.50, "currency": "CHF" }, "assets": [ { "id": "as_7c1e20", "type": "image", "href": "/v1/assets/as_7c1e20" }, { "id": "as_7c1e21", "type": "datasheet", "href": "/v1/assets/as_7c1e21" } ] } ], "meta": { "total": 287, "limit": 2, "next_cursor": "eyJza3UiOiJNUy0xMjAxNCJ9" }}GET /v1/sync/diff?since=2026-09-23T02:00:00ZHost: messara.pimgate.aiAuthorization: Bearer pg_live_••••••••••••HTTP/1.1 200 OK{ "since": "2026-09-23T02:00:00Z", "until": "2026-09-24T02:04:11Z", "from_version": 41, "to_version": 42, "changes": [ { "sku": "MS-12011", "op": "update", "fields": { "price.list": 41.50, "name.en-GB": "Bourdon tube pressure gauge D63, 0–10 bar, G 1/4 bottom" } }, { "sku": "MS-20415", "op": "create", "href": "/v1/products/MS-20415" }, { "sku": "MS-10433", "op": "remove" } ], "meta": { "count": 3, "next_cursor": null }}// full export v42: 18.4 MB · this delta: 0.9 MBPOST /hooks/pimgate HTTP/1.1Host: shop.messara.exampleContent-Type: application/jsonX-PimGate-Event: product.updatedX-PimGate-Signature: t=1790215451,v1=3f9a…c21e// verify: HMAC over "t.body" with your webhook secret{ "event": "product.updated", "tenant": "messara", "occurred_at": "2026-09-24T02:04:11Z", "sku": "MS-12011", "version": 42, "changed_fields": ["price.list", "name.en-GB"], "delta": "/v1/sync/diff?since=2026-09-23T02:00:00Z"}ILLUSTRATIVE · SEE API REFERENCE FOR EXACT CONTRACT
07 · Specifications
| Spec | Value | Status |
|---|---|---|
| API style | REST · JSON · VERSIONED PATH /v1 | LIVE |
| Authentication | BEARER TOKEN · PER TENANT | LIVE |
| Authorization | SERVER-SIDE ENTITLEMENT FILTERING | LIVE |
| Rate limiting | PER TOKEN | LIVE |
| API calls / month | S 250k · M 2M · L 15M · XL 50M | — |
| Delivery patterns | PULL · PUSH · WEBHOOK (SIGNED) · SCHEDULED | LIVE |
| Delta endpoint | GET /v1/sync/diff?since= | LIVE |
| Delta granularity | FIELD LEVEL · ~95% SMALLER | LIVE |
| Versioned exports | EVERY EXPORT STORED · COMPARABLE | LIVE |
| Export formats | XML · JSON · CSV · XLSX | LIVE |
| GraphQL | POST /graphql | 2026 |
| API documentation | OPENAPI · docs.pimgate.ai | 2026 |
| Change notifications to portal users | EMAIL · WEBHOOK | ROADMAP |
| Hosting / data residency | DE (HETZNER FALKENSTEIN) · CH ON REQUEST | — |
08 · Typical consumers
Consumers integrate through the REST API or delivered exports. No pre-built plugins are implied.
09 · FAQ
Put a gate between your catalog and chaos.