Print Workflow AutomationPrintcart TutorialWeb-to-PrintPrint-on-Demand

API Keys, Credentials and Webhooks in the Printcart Dashboard

Find your store credentials, create and rotate named API keys, and set up a webhook for your own server. Nine steps with screenshots.

D
By David — CEO of Printcart
10/2/20266 min read

Open API & Keys in the left menu to see your store's Sid , Secret and Unauth Token , and to create named API keys that you can rotate or revoke one by one. Webhooks live under Apps & Connectors then Webhooks . Keep the Secret and any secret key on your server and never in browser code. Creating named keys needs the Advanced plan.

Key takeaways

✓Automate the handoff from order intake to artwork, approval, production status, and fulfillment tracking.
✓Define clear exception paths for missing artwork, manual approval, reorders, rush jobs, and repeat corporate buyers.
✓Use API Keys, Credentials and Webhooks in the Printcart Dashboard as an operating workflow, not a one-time setup task.
✓Document the approval owner, fallback process, and production handoff before customers start ordering.
✓Review the workflow after the first real orders and tighten the steps that cause rework.

Part 8 of 9 in the Printcart Dashboard tutorial series. Previous: Part 7, Plans, tokens and billing. Next: Part 9, Store profile and brand settings.

What do you need before you start?

  • A Printcart store. Each store has its own credentials and keys.
  • A server or service that will call the Printcart API or receive webhooks.

The screenshots come from a demo account with a demo store called Demo Print Shop and made-up buyer names. Your store name, products and numbers will differ, but the screens and buttons are the same. Secret values are always hidden in the pictures. The key values in the pictures are blurred and are not real.

How do you manage API keys and webhooks in the Printcart Dashboard?

Step 1Open API & Keys

In the left menu, under Store Setup, open API & Keys (www.printcart.com/en/settings).

Expected result: The page API & Keys opens for the store shown in the top bar.

Left menu with API and Keys highlighted

Step 2Know the three store credentials

The first cards hold the credentials every Printcart plugin and app uses. Sid is the public store identifier and is safe in client-side code. Secret is for server-side API calls only; use the eye button to reveal it and the copy button to copy it. Unauth Token is for the browser-side designer embed and read-only calls. The yellow banner repeats the rule: never expose the Secret in client-side code or in a public repository. On the right, a quick reference shows the Basic auth format and the SDK header.

Expected result: You can find, reveal and copy each credential.

API and Keys page with the Sid, Secret and Unauth Token cards highlighted and the values hidden

Step 3Rotate the Unauth Token only when you must

Click Rotate Unauth Token if the token has leaked. The dialog warns that the old token stops working at once and that any embedded customizer or SDK using it stays broken until you update it. Click Cancel if you only wanted to look. The Sid cannot be regenerated, and the Secret says to contact support to rotate it.

Expected result: The dialog explains the effect before anything changes.

Rotate Unauth Token confirmation dialog warning that the old token stops working, with the Cancel button highlighted

Step 4See the API keys for this store

Scroll to API keys. These are named, revocable keys with their own scopes and an audit trail, and the page recommends them over the store credentials above. The tab This store lists keys for the current store and Account-wide lists keys that reach every store on your account. Each row shows the type, the access, the status, when it was last used, and three actions: history, rotate and revoke.

Expected result: The table lists your keys, for example a server key and a browser key.

API keys section with the Create key button and the list of keys for this store

Step 5Create a key

Click Create key. Choose the type: a Secret key (starts with sk_live_, server only) or a Publishable key (starts with pk_live_, safe in a storefront and restricted by an origin list). Type a label so you can tell the key apart later, optionally set an expiry date, and click Create key.

Expected result: The key is created and a second window opens.

Create a key dialog with the key type, a label typed in and the Create key button highlighted

Step 6Copy the key now

The window Your new API key shows the full key once. Printcart stores only a hash, so nobody can show it again, not even support. Click Copy key to clipboard, store it in your password manager or server settings, tick I have stored this key somewhere safe and click Done.

Expected result: The window closes and the key appears in the table with a masked value.

Your new API key dialog warning that the key is shown only once, with the key value hidden

The new key listed in the API keys table with its type, access and status

Step 7Rotate or revoke a key

Use the rotate button on a row to issue a replacement. You choose how long the old key keeps working, from no grace at all up to 30 days, and 7 days is the recommended choice, so you can roll the new key out without downtime. Revoking is immediate and cannot be undone, so the dialog asks you to type the key's label first. Open the history button to see events such as created, first used and rotated.

Expected result: The rotate dialog shows the exact moment the current key stops working.

Rotate key dialog with the grace period for the current key

Step 8If your plan is too low

On a store that is not on the Advanced plan, clicking Create key in the dialog shows the message that creating API keys requires the Advanced plan and that keys you already have keep working. Click See plans to open the plans page. The Sid, Secret and Unauth Token on this page keep working on every plan.

Expected result: A notice appears in the dialog with the See plans button, and no key is created.

Create a key dialog showing the notice that creating API keys requires the Advanced plan, with the See plans button highlighted

Step 9Add a webhook

Open Apps & Connectors, then the Webhooks tab, and click Add webhook. Choose a Topic (products, designs, projects, sides, templates or user), an Event (POST, PUT or DELETE, with batch variants) and the Callback URL on your server, then save. For example, topic products with event POST fires when a new product is created.

Expected result: A green message says Webhook created. and the webhook is listed with its topic, event and URL. Use the pencil to edit it and the bin to delete it.

Apps and Connectors page on the Webhooks tab with no webhooks yet

New Webhook dialog with the topic, the event and the callback URL highlighted

The new webhook listed with its topic, event and callback URL

Which credential goes where?

Use Sid + Secret on your server for API calls, webhook signature checks, order creation and product sync. Use the Unauth Token in the browser for the designer embed and read-only product fetches. A Publishable key is the browser-safe key in the newer key system; a Secret key is server-only.

What happens to the plugins and apps I already connected?

Nothing. The Printcart WordPress plugin, the Wix app and the Shopify app use the Sid, Secret and Unauth Token. Rotating the Unauth Token does break an embed that still holds the old one, so update every place that uses it straight after you rotate.

How many webhooks can I have?

The limit depends on your plan; read the plan comparison under Wallet & Billing (see Part 7) before you build on webhooks.

What should you do next?

Stuck on a step? Message the Printcart team on WhatsApp and include a screenshot of the screen you are on.

What to verify before you roll out API Keys, Credentials and Webhooks in the Printcart Dashboard

This tutorial is written from Printcart implementation patterns across order operations, approval routing, and fulfillment handoff. Before treating it as complete, test the workflow with one real product, one real design file, and one real order path.

Can a customer complete the flow without staff intervention?
Does the production team receive the exact artwork, option, and approval data they need?
Is there a clear fallback when artwork, pricing, approval, or fulfillment data is missing?

API Keys, Credentials and Webhooks in the Printcart Dashboard — common questions

What do you need before you start?

The screenshots come from a demo account with a demo store called Demo Print Shop and made-up buyer names. Your store name, products and numbers will differ, but the screens and buttons are the same. Secret values are always hidden in the pictures. The key values in the pictures are blurred and are not real.

Which credential goes where?

Use Sid + Secret on your server for API calls, webhook signature checks, order creation and product sync. Use the Unauth Token in the browser for the designer embed and read-only product fetches. A Publishable key is the browser-safe key in the newer key system; a Secret key is server-only.

What happens to the plugins and apps I already connected?

Nothing. The Printcart WordPress plugin, the Wix app and the Shopify app use the Sid, Secret and Unauth Token. Rotating the Unauth Token does break an embed that still holds the old one, so update every place that uses it straight after you rotate.

How many webhooks can I have?

The limit depends on your plan; read the plan comparison under Wallet & Billing (see Part 7 ) before you build on webhooks.

Next steps in Printcart

Connect api keys, credentials and webhooks in the printcart dashboard with catalog setup, templates, production workflows, and implementation support.

Want to put api keys, credentials and webhooks in the printcart dashboard into practice?

Use the related Printcart tool below, or create a free account to start building with the product designer.

Related tutorials