DEVELOPER PLATFORM

Build with
GORIB API

A focused interface for catalog access, balance management and instant digital delivery.

BASE URLhttps://api.goribucshop.com
01

ACCESS

Authentication

Every API request requires your personal key in the X-API-Key header. Keep it private and use it only from your backend.

⌁

API key

48 alphanumeric characters. The key remains available under My account until you regenerate it.

◇

Server-side only

Never expose the key in frontend code, mobile apps or public repositories.

Request header
X-API-Key: YOUR_API_KEY
02

FIRST REQUEST

Quick start

Request the live catalog in seconds. Replace the placeholder with your API key.

curl "https://api.goribucshop.com/api/v1/catalog" \
  -H "X-API-Key: YOUR_API_KEY"
import requests

response = requests.get(
    "https://api.goribucshop.com/api/v1/catalog",
    headers={"X-API-Key": "YOUR_API_KEY"},
    timeout=15,
)
response.raise_for_status()
print(response.json())
GET/api/v1/catalog

Returns products, prices and live availability.

Response

idinteger

Product identifier.

denominationinteger

Product value.

price_usdstring

Unit price in USD.

availableinteger

Quantity currently available.

200 OK
[
  {
    "id": 12,
    "game": "PUBG Mobile",
    "product": "UC Code",
    "denomination": 660,
    "price_usd": "9.950",
    "available": 84
  }
]
GET/api/v1/profile

Returns account details and available balance.

Use this endpoint to

  • Display the current balance
  • Confirm account identity
  • Read the masked API key hint
200 OK
{
  "telegram_id": 123456789,
  "username": "username",
  "language": "en",
  "balance_usd": "250.000",
  "api_key_hint": "Ab12••••Xy90"
}
GET/api/v1/orders

Returns the authenticated account’s order history.

Authenticate→Request history→Receive orders
POST/api/v1/api-key/rotate

Invalidates the current key and issues a new one.

Update integrations

The new key remains available under My account. The previous key stops working immediately.

03

REFERENCE

Error handling

StatusMeaningAction
400Invalid request or quantityValidate parameters
401Missing or invalid API keyCheck authentication
402Insufficient balanceAdd funds and retry
409Idempotency conflictUse a new unique key
422Product unavailableRefresh the catalog
04

GOOD PRACTICE

Security checklist

Treat your API key like a password. Rotate it immediately if it may have been exposed.

  • Keep credentials in environment variables or a secret manager
  • Use a new idempotency key for each checkout
  • Set request timeouts and log order IDs
  • Never publish delivered codes in application logs