> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.coi.co.il/orders/list-orders/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.coi.co.il/_mcp/server. # List orders GET https://www.your-store.co.il/api/v1/orders The store's orders, newest first, in full. Requires `orders:read`. Reference: https://docs.coi.co.il/orders/list-orders ## Authentication - `Authorization` header (bearer token, required) — An API key from the store's admin: חנות > API ומפתחות. Send it as `Authorization: Bearer coi_sk_...` (or `X-Api-Key: coi_sk_...`). Never in the URL - `?apikey=` is refused with 400. ## Request ### Query parameters - `limit` (integer, optional, default: 50) — Rows per page, 1 to 100. - `cursor` (string, optional) — `nextCursor` from the previous page, as is. Omit for the first page. - `status` (integer, optional) — Only orders in this status. - `paid` (boolean, optional) — Only paid (true) or unpaid (false) orders. - `created_since` (string, optional) — Only orders placed from then on. ISO 8601: `2026-09-27` or `2026-09-27T10:00:00+03:00`. - `created_until` (string, optional) — Only orders placed before then. ISO 8601: `2026-09-27` or `2026-09-27T10:00:00+03:00`. ## Response ### 200 A page of orders. - `ok` (true, optional) - `data` (list of Order, optional) - `hasMore` (boolean, optional) — Whether there is another page. - `nextCursor` (string, optional, nullable) — Pass as `cursor` for the next page; null on the last page. ## Errors ### 400 Bad Request Error The request is not valid - a field of the wrong type, a missing field, a bad parameter. - `ok` (false, optional) - `error` (ErrorError, optional) ### 401 Unauthorized Error Missing, invalid, revoked or expired API key. The same answer for all of them. - `ok` (false, optional) - `error` (ErrorError, optional) ### 403 Forbidden Error The key lacks the permission (`insufficient_scope`), or the site's plan does not include the API (`plan_required`). - `ok` (false, optional) - `error` (ErrorError, optional) ### 429 Too Many Requests Error More than 120 requests a minute with one key. Wait `Retry-After` seconds. - `ok` (false, optional) - `error` (ErrorError, optional) ## Types ### Order - `id` (integer, optional) — The id to use in the API. - `number` (integer, optional, nullable) — The order number the customer sees. - `createdAt` (string, optional) - `updatedAt` (string, optional, nullable) — Set when the order itself was edited ("ערוך הזמנה"). - `status` (OrderStatus, optional) — The store's own statuses ("נהל סטטוסים"). 1 = new, 2 = read. - `paid` (boolean, optional) - `payType` (enum, optional) - Allowed values: `phone`, `paypal`, `credit_card`, `bit`, `none` - `total` (double, optional, nullable) — The grand total: delivery, coupon, promotions and VAT included. - `customer` (OrderCustomer, optional) - `customerNotes` (string, optional, nullable) - `adminNotes` (string, optional, nullable) - `trackingNumber` (string, optional, nullable) — The shipment's tracking number, set with PATCH. - `newsletter` (boolean, optional) - `invoice` (OrderInvoice, optional, nullable) - `items` (list of OrderItemsItems, optional) — The products bought. `total` = `unitPrice` x `quantity`; `unitPrice` = `price` + `optionsPrice`. - `delivery` (OrderDelivery, optional, nullable) - `coupon` (OrderCoupon, optional, nullable) - `promotions` (list of OrderPromotionsItems, optional) - `vat` (double, optional, nullable) — VAT added on top, when the store adds it. - `paypalFee` (double, optional, nullable) — The PayPal fee line, when there is one. - `payments` (integer, optional, nullable) — Number of card installments, when more than one. - `fields` (list of OrderFieldsItems, optional) — Everything the customer filled in at checkout, label and value. ### ErrorError - `code` (string, optional) — Stable, machine-readable: `unauthorized`, `insufficient_scope`, `plan_required`, `invalid_field`, `invalid_parameter`, `invalid_json`, `json_required`, `not_found`, `method_not_allowed`, `nothing_to_update`, `plan_limit`, `email_taken`, `registration_disabled`, `rate_limited`, `too_many_failures`, `https_required`, `key_in_url`, `server_error`. - `message` (string, optional) — What went wrong, in English, for a person. ### OrderStatus The store's own statuses ("נהל סטטוסים"). 1 = new, 2 = read. - `id` (integer, optional) - `name` (string, optional) ### OrderCustomer - `id` (integer, optional, nullable) — The registered customer, when one was logged in. - `name` (string, optional) - `email` (string, optional) - `phone` (string, optional) - `address` (string, optional) ### OrderInvoice - `number` (integer, optional, nullable) - `url` (string, optional, nullable) ### OrderItemsItems - `productId` (integer, optional) - `name` (string, optional) - `sku` (string, optional, nullable) - `quantity` (double, optional) - `unitName` (string, optional, nullable) - `price` (double, optional) - `optionsPrice` (double, optional) - `unitPrice` (double, optional) - `total` (double, optional) - `options` (list of OrderItemsItemsOptionsItems, optional) - `vatFree` (boolean, optional) ### OrderDelivery - `name` (string, optional) - `price` (double, optional) ### OrderCoupon - `code` (string, optional) - `description` (string, optional, nullable) - `amount` (double, optional) — Negative. ### OrderPromotionsItems - `name` (string, optional) - `amount` (double, optional) - `productId` (integer, optional, nullable) — The product the discount came off; null for a basket-level one. ### OrderFieldsItems - `name` (string, optional) - `value` (string, optional) ### OrderItemsItemsOptionsItems - `name` (string, optional) - `price` (double, optional) ## Examples **Response** ```json { "ok": true, "data": [ { "id": 4203, "number": 67, "createdAt": "2026-09-24T15:14:00+03:00", "updatedAt": null, "status": { "id": 7, "name": "בדרך ללקוח" }, "paid": true, "payType": "credit_card", "total": 2340, "customer": { "id": null, "name": "ישראל ישראלי", "email": "israel@example.com", "phone": "0501234567", "address": "הרצל 13 תל אביב" }, "customerNotes": "להשאיר ליד הדלת", "adminNotes": null, "trackingNumber": "RR123456789IL", "newsletter": false, "invoice": { "number": 10231, "url": "https://..." }, "items": [ { "productId": 1180, "name": "טלפון סלולרי 256GB", "sku": "886886000028", "quantity": 1, "unitName": null, "price": 3000, "optionsPrice": 600, "unitPrice": 3600, "total": 3600, "options": [ { "name": "צבע: שחור", "price": 600 } ], "vatFree": false } ], "delivery": { "name": "משלוח: איסוף עצמי", "price": 0 }, "coupon": { "code": "SUMMER", "description": "מבצע קיץ", "amount": -900 }, "promotions": [ { "name": "הנחה על הסל", "amount": -360, "productId": null } ], "vat": null, "paypalFee": null, "payments": null, "fields": [ { "name": "שם מלא", "value": "ישראל ישראלי" }, { "name": "עיר", "value": "תל אביב" } ] } ], "hasMore": true, "nextCursor": "aToxNjQ2" } ``` **SDK Code** ```python import requests url = "https://www.your-store.co.il/api/v1/orders" querystring = {"created_since":"2026-09-01","created_until":"2026-09-01"} headers = {"Authorization": "Bearer "} response = requests.get(url, headers=headers, params=querystring) print(response.json()) ``` ```javascript const url = 'https://www.your-store.co.il/api/v1/orders?created_since=2026-09-01&created_until=2026-09-01'; const options = {method: 'GET', headers: {Authorization: 'Bearer '}}; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go package main import ( "fmt" "net/http" "io" ) func main() { url := "https://www.your-store.co.il/api/v1/orders?created_since=2026-09-01&created_until=2026-09-01" req, _ := http.NewRequest("GET", url, nil) req.Header.Add("Authorization", "Bearer ") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby require 'uri' require 'net/http' url = URI("https://www.your-store.co.il/api/v1/orders?created_since=2026-09-01&created_until=2026-09-01") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Get.new(url) request["Authorization"] = 'Bearer ' response = http.request(request) puts response.read_body ``` ```java import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.get("https://www.your-store.co.il/api/v1/orders?created_since=2026-09-01&created_until=2026-09-01") .header("Authorization", "Bearer ") .asString(); ``` ```php request('GET', 'https://www.your-store.co.il/api/v1/orders?created_since=2026-09-01&created_until=2026-09-01', [ 'headers' => [ 'Authorization' => 'Bearer ', ], ]); echo $response->getBody(); ``` ```csharp using RestSharp; var client = new RestClient("https://www.your-store.co.il/api/v1/orders?created_since=2026-09-01&created_until=2026-09-01"); var request = new RestRequest(Method.GET); request.AddHeader("Authorization", "Bearer "); IRestResponse response = client.Execute(request); ``` ```swift import Foundation let headers = ["Authorization": "Bearer "] let request = NSMutableURLRequest(url: NSURL(string: "https://www.your-store.co.il/api/v1/orders?created_since=2026-09-01&created_until=2026-09-01")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "GET" request.allHTTPHeaderFields = headers let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```