Call the API
Miridia has two APIs:
- The Global API, at
https://global.miridia.io, handles accounts, login, and API keys. - The core API, at
https://api.miridia.io, holds your business data: products, orders, stock, and more.
In this tutorial you log in, create an API key, and use the key to list your products.
What you need
- A Miridia user that is an owner of the organisation. Only an owner can create an API key.
- The identifier of your business. You can find it in the business settings of the portal.
curlin a terminal. The examples use Bash. In PowerShell, usecurl.exe.
Steps
Log in
Send your email address and your password to the Global API.
curl -s https://global.miridia.io/api/auth/login \
-H "Content-Type: application/json" \
-d '{ "email": "you@example.com", "password": "<your-password>" }'
If your user belongs to one organisation, the response contains a session with an access token:
{
"data": {
"requiresOrganizationSelection": false,
"session": {
"accessToken": "<access-token>",
"expiresAtUtc": "2026-09-29T14:00:00Z",
"organization": { "id": "<organization-id>", "slug": "example-foods", "name": "Example Foods" }
}
},
"statusCode": 200,
"messages": []
}
Select an organisation, if necessary
If your user belongs to more than one organisation, the response has requiresOrganizationSelection: true, a short-lived selectionToken, and a list of organizations. Send the selection token as a bearer token, with the organisation that you want:
curl -s https://global.miridia.io/api/auth/select-organization \
-H "Authorization: Bearer <selection-token>" \
-H "Content-Type: application/json" \
-d '{ "organizationId": "<organization-id>" }'
The response contains the session with the access token.
Create an API key
An access token expires after a short time. For a script or an integration, create an API key. Send the access token and the business that the key acts for:
curl -s https://global.miridia.io/api/auth/tokens \
-H "Authorization: Bearer <access-token>" \
-H "Content-Type: application/json" \
-d '{ "label": "Stock report script", "businessId": "<business-id>", "ttlMinutes": 525600 }'
The token field of the response is the API key. Copy it now and keep it in a secret store.
The request has these fields:
DELETE /api/auth/tokens/{id}.List your products
Send the API key in the x-dispatch-api-key header to the core API:
curl -s "https://api.miridia.io/api/v1/Products?Page=1&PageSize=20" \
-H "x-dispatch-api-key: <api-key>"
The response is a page of products:
{
"data": [ { "id": "<product-id>", "title": "Vanilla ice cream, 500 ml", "sku": "VAN-500" } ],
"count": 1,
"totalCount": 1,
"page": 1,
"pageSize": 20,
"hasMore": false
}
Use the access token instead
You can also call the core API with the access token from the login. Then you must send the business in the X-Business-Id header, because a user can belong to more than one business:
curl -s "https://api.miridia.io/api/v1/Products?Page=1&PageSize=20" \
-H "Authorization: Bearer <access-token>" \
-H "X-Business-Id: <business-id>"
If the header is missing, or the user cannot access the business, the API returns 401.