Skip to content

Web API v1

Web API v1 availability

The recommended version of the Apptus eSales 3 Enterprise Web API is the Web API v2, released May 22, 2018. The Apptus eSales 3 Enterprise Web API v1 is disabled by default. For more information about enabling Web API v1, contact Apptus Support.

The Apptus eSales 3 Enterprise Web API makes it easy to integrate eSales into a site by enabling both client and server side integration. It consists of two main components:

The Web API also includes methods for GDPR Data Management for eSales Enterprise data.

Getting started

Supported browsers

The Web API is built to support major browsers such as Mozilla Firefox, Google Chrome, Safari, and Microsoft Internet Explorer (10 and newer).


Apptus Cloud environment configuration is a part of the customer onboarding process. This configuration is performed by Apptus, but for it to be completed some information regarding origin host settings and selected client side payment strategy are needed from the customer. The customer must also verify that the connection requirements are met when using the RESTful API.

With this provided to Apptus the initial set-up for the Web API will be performed, and the following information is returned to the customer.

  • A private key - used for visitor sign in and dynamic pages
  • Cluster ID - used when requesting data from the Apptus Cloud
  • Cluster credentials - used when importing data to eSales 3
  • Apptus eSales Apps and Manager access rights

The private key and cluster ID are also available in Credentials tab of the Integration app. If an alternative API base URL is to be used, this will be provided by Apptus.

When the cloud configuration is completed, customers can contact Apptus Support if there are any questions about the current security settings used for their eSales cluster, or if the security settings must be changed.

Origin host

The origin host is part of the security settings for a cluster. It specifies what domain Ajax requests to the cluster is allowed to originate from.

The following information is needed from the customer to configure the origin host.

  • Protocols (HTTP/HTTPS)
  • Domains (subdomains)
  • Ports (80, 443)

Client side payments

Client side payment strategy is part of the security settings for a cluster. There are three different strategies for handling payment notifications with the eSales 3 Web API.

  • Do not allow payment notifications - This strategy should be used when payment notifications are always sent server side. Recommended for production clusters.
  • Allow limited payments - Ignore suspicious payments e.g. payment notification that seem to be machine generated.
  • Allow all payment notifications - Most useful at an early stage of the integration.

Connection requirements

JavaScript library

The JavaScript library exposes methods to fetch panels and notify events as clicks, adding to carts, etc. It communicates via Ajax requests with an eSales 3 Web API Service on the Apptus Cloud.

For more details of the JavaScript library, see the JavaScript library documentation pages.


The RESTful API handles the communication with the Apptus eSales Cluster. Load balancing and failover are both handled automatically.

For more details of the RESTful API, see the RESTful API documentation pages.

Sessions and notifications

Sessions and notifications are used to keep track of information about visitor interaction that is sent to eSales via the Web API. This information is used to enable personalisation and to improve recommendations and more.

For more details about Notifications, see the Sessions and Notifications page.

Recommendations and best practice

  • Always instantiate an esales object as a variable with a URL to a cluster and market that exists.
  • A general rule of thumb is to never cache eSales generated results. Static data such as descriptions and images can be cached.
  • When notifying payments, the recommended notification method to use is Secure Payment Notification.

Last update: January 28, 2022

This online publication is intellectual property of Apptus Technologies. Its contents can be duplicated in part or whole, provided that a copyright label is visibly located on each copy and the copy is used in conjunction with the product described within this document.

All information found in these documents has been compiled with utmost attention to detail. However, this does not guarantee complete accuracy. Neither Apptus Technologies nor the authors shall be held liable for possible errors or the consequences thereof.

Software and hardware descriptions cited in these documents might be registered trademarks. All trade names are subject to copyright restrictions and may be registered trademarks. Apptus Technologies essentially adheres to the manufacturer’s spelling. Names of products and trademarks appearing in this document, with or without specific notation, are likewise subject to trademark and trade protection laws and may thus fall under copyright restrictions.