> ## Documentation Index
> Fetch the complete documentation index at: https://docs.taberna.io/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Taberna is a crypto payments API. Amounts are priced in fiat (USD or EUR) and paid in crypto.
> Fiat amounts are ALWAYS decimal strings ("9.99"), never numbers. Crypto amounts are integer strings in the asset's smallest unit.
> Authenticate merchant endpoints with `Authorization: Bearer tbrn_live_...`. Every key is bound to one store and carries an explicit scope set, so never pass a store id to a /v1 endpoint.
> A 401 means the credential is bad; a 403 means the key lacks a scope. Never retry or re-authenticate on a 403 — surface it as a configuration error.
> The /v1/checkouts endpoints are deliberately unauthenticated and run in the buyer's browser. Never send an API key to a browser.
> Verify webhook signatures over the RAW request body before parsing JSON, and treat delivery as at-least-once: handlers must be idempotent.
> Never grant value based on a browser redirect to successUrl. Fulfil on a signature-verified webhook, or on a server-side read of GET /v1/orders/{id} or GET /v1/invoices/{id}.
> There is no test mode: every payment method is a live chain moving real funds.
> A merchant can run an entire shop with no code: the dashboard creates products and invoices, and every store can host a storefront at {slug}.taberna.io with its own theme, sections, branding and optional custom domain. Never assume the reader has an API integration.
> Taberna issues no refunds and performs no KYC. A refund is something the merchant sends from their own payout wallet, off-platform.

# List products

> The store's products, newest first, optionally filtered by `listed`. Requires the `products:read` scope.

Fulfillment secrets never appear here: delivery is reported as its type plus remaining `stock`, never as pool lines, shared text, file keys or redirect targets.



## OpenAPI

````yaml /api-reference/openapi.json get /v1/products
openapi: 3.1.0
info:
  title: Taberna API
  description: >-
    Accept crypto payments for digital goods. Create orders and invoices, hand
    the buyer a hosted checkout link, and let webhooks tell you when the money
    lands.


    Authenticate merchant endpoints with a store API key as a bearer token
    (`Authorization: Bearer tbrn_live_…`). Every key is bound to one store and
    carries an explicit set of scopes; the scope a route requires is stated in
    its description and in the `x-required-scope` extension. A key without the
    scope gets a 403 — mint one with the scope rather than retrying.


    The Checkout endpoints are the exception: they are unauthenticated and meant
    to be called from the buyer's browser. Possession of the checkout id is the
    credential there, so never ship an API key to a page.


    Conventions: ids in links are short ids; fiat amounts are decimal strings
    ("9.99"); crypto amounts are integer strings in the asset's smallest unit;
    timestamps are ISO-8601 UTC. Errors carry `{ "error": "…" }` unless
    documented otherwise.
  version: 1.0.0
servers:
  - url: https://api.taberna.io
    description: Taberna API
security: []
tags:
  - name: Orders
    description: Carts of products, paid through a hosted checkout.
  - name: Invoices
    description: Merchant-issued bills with their own payment page.
  - name: Invoice Templates
    description: Saved invoice presets, referenced by `templateId` when creating one.
  - name: Products
    description: Catalogue reads and delivery stock top-ups.
  - name: Store
    description: What the calling API key is and what it may do.
  - name: Webhook Deliveries
    description: Delivery history for the store webhook, and replay.
  - name: Checkout
    description: >-
      Buyer-facing hosted-page endpoints. Unauthenticated by design — never send
      an API key.
paths:
  /v1/products:
    get:
      tags:
        - Products
      summary: List products
      description: >-
        The store's products, newest first, optionally filtered by `listed`.
        Requires the `products:read` scope.


        Fulfillment secrets never appear here: delivery is reported as its type
        plus remaining `stock`, never as pool lines, shared text, file keys or
        redirect targets.
      operationId: getV1Products
      parameters:
        - in: query
          name: page
          schema:
            default: 1
            example: 1
            type: integer
            exclusiveMinimum: 0
          description: Page to return, 1-based.
        - in: query
          name: limit
          schema:
            default: 20
            example: 20
            type: integer
            minimum: 1
            maximum: 100
          description: Rows per page, 1–100.
        - in: query
          name: listed
          schema:
            example: 'true'
            type: string
          description: >-
            Filter by whether the product is visible on the storefront. Accepts
            true/false, 1/0, yes/no, on/off (case-insensitive); an empty value
            applies no filter, and so does omitting it.
      responses:
        '200':
          description: A page of products.
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items:
                      type: object
                      properties:
                        id:
                          type: string
                          format: uuid
                          description: >-
                            The product's id — pass it in an order's `items` to
                            sell it. Formatted as a UUID, e.g.
                            `3f1a9c2e-7b04-4d8e-9a6f-2c5b1e0d7a83`.
                          example: 3f1a9c2e-7b04-4d8e-9a6f-2c5b1e0d7a83
                        title:
                          type: string
                          description: Product name as shown at checkout.
                          example: Nitro — 1 Month
                        body:
                          anyOf:
                            - type: string
                            - type: 'null'
                          description: Long-form product description. Null when unset.
                        price:
                          type: string
                          description: >-
                            Price of one unit. Decimal string in the resource's
                            fiat currency, e.g. `"49.99"` — a string, never a
                            JSON number, so no precision is lost in transit.
                          example: '49.99'
                        currency:
                          type: string
                          enum:
                            - usd
                            - eur
                          description: >-
                            The fiat currency every amount on this resource is
                            priced in. Crypto is quoted against it at payment
                            time.
                          example: usd
                        productType:
                          type: string
                          enum:
                            - single-purchase
                          description: >-
                            How the product is sold. `single-purchase` — a
                            one-off purchase, the only mode today.
                          example: single-purchase
                        listed:
                          type: boolean
                          description: >-
                            Whether the product is visible on the storefront.
                            Unlisted products can still be bought through an
                            order you create.
                          example: true
                        image:
                          anyOf:
                            - type: string
                            - type: 'null'
                          description: >-
                            Absolute URL of the product image, or null when it
                            has none.
                          example: https://cdn.taberna.io/products/nitro.png
                        deliveryType:
                          anyOf:
                            - type: string
                              enum:
                                - text_pool
                                - text_shared
                                - file_shared
                                - redirect
                            - type: 'null'
                          description: >-
                            How the product is fulfilled once an order
                            completes. `text_pool` — one line of stock per unit
                            sold (keys, codes, accounts). `text_shared` — the
                            same text to every buyer. `file_shared` — the same
                            file, handed over as a short-lived download link.
                            `redirect` — the buyer is sent to a URL you host.
                            Null when no delivery is configured yet. The
                            contents are never exposed here — only the type and,
                            for pools, the remaining count.
                        stock:
                          anyOf:
                            - type: integer
                              minimum: -9007199254740991
                              maximum: 9007199254740991
                            - type: 'null'
                          description: >-
                            Units still available for a `text_pool` delivery.
                            Null when delivery is unlimited (`text_shared`,
                            `file_shared`, `redirect`) or not configured.
                          example: 42
                        minQuantity:
                          type: integer
                          minimum: -9007199254740991
                          maximum: 9007199254740991
                          description: Fewest units one order may buy.
                          example: 1
                        maxQuantity:
                          anyOf:
                            - type: integer
                              minimum: -9007199254740991
                              maximum: 9007199254740991
                            - type: 'null'
                          description: Most units one order may buy. Null when uncapped.
                          example: 10
                        createdAt:
                          type: string
                          format: date-time
                          description: >-
                            When the product was created. UTC timestamp in ISO
                            8601, e.g. `2026-07-29T14:30:00.000Z`.
                          example: '2026-07-29T14:30:00.000Z'
                        updatedAt:
                          anyOf:
                            - type: string
                              format: date-time
                              description: >-
                                UTC timestamp in ISO 8601, e.g.
                                `2026-07-29T14:30:00.000Z`.
                              example: '2026-07-29T14:30:00.000Z'
                            - type: 'null'
                          description: >-
                            When the product was last edited. Null if never. UTC
                            timestamp in ISO 8601, e.g.
                            `2026-07-29T14:30:00.000Z`.
                      required:
                        - id
                        - title
                        - body
                        - price
                        - currency
                        - productType
                        - listed
                        - image
                        - deliveryType
                        - stock
                        - minQuantity
                        - maxQuantity
                        - createdAt
                        - updatedAt
                      description: A product in the store's catalogue.
                    description: The products on this page. Newest first.
                  pagination:
                    type: object
                    properties:
                      page:
                        type: integer
                        minimum: -9007199254740991
                        maximum: 9007199254740991
                        description: The page that was returned, 1-based.
                        example: 1
                      limit:
                        type: integer
                        minimum: -9007199254740991
                        maximum: 9007199254740991
                        description: Rows per page, as requested (max 100).
                        example: 20
                      total:
                        type: integer
                        minimum: -9007199254740991
                        maximum: 9007199254740991
                        description: Total rows matching the filter, across all pages.
                        example: 137
                      totalPages:
                        type: integer
                        minimum: -9007199254740991
                        maximum: 9007199254740991
                        description: >-
                          Number of pages at this `limit`. Zero when nothing
                          matched.
                        example: 7
                    required:
                      - page
                      - limit
                      - total
                      - totalPages
                    description: Where this page sits in the full result set.
                required:
                  - data
                  - pagination
        '400':
          description: >-
            The request failed validation (`{ "error": "Invalid request data"
            }`), or the operation is not allowed in the resource's current
            state.
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                    description: >-
                      Human-readable explanation of what went wrong. Meant for
                      logs and developers, not for branching — switch on the
                      HTTP status instead.
                    example: Order not found
                required:
                  - error
                description: The standard error body, returned by every failing endpoint.
                example:
                  error: Order not found
        '401':
          description: >-
            Missing, malformed, revoked or expired API key. The
            `WWW-Authenticate` header names the challenge that failed.
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                    description: >-
                      Human-readable explanation of what went wrong. Meant for
                      logs and developers, not for branching — switch on the
                      HTTP status instead.
                    example: Order not found
                required:
                  - error
                description: The standard error body, returned by every failing endpoint.
                example:
                  error: Order not found
        '403':
          description: The key is valid but was not granted the scope this route requires.
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
                    description: >-
                      Human-readable explanation of what went wrong. Meant for
                      logs and developers, not for branching — switch on the
                      HTTP status instead.
                    example: Order not found
                required:
                  - error
                description: The standard error body, returned by every failing endpoint.
                example:
                  error: Order not found
      security:
        - bearerAuth: []
components:
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        A store API key, sent as `Authorization: Bearer <key>`.


        A key looks like `tbrn_live_` followed by 48 hex characters, e.g.
        `tbrn_live_4f2a...c91b`. Mint one in the Taberna dashboard under
        Developers → API Keys, tick the scopes the integration needs, and copy
        it there and then — the full value is shown once and only its hash is
        stored, so a lost key is replaced rather than recovered.


        One key belongs to one store and carries a fixed scope set. Send it from
        a server, never from a browser: it can create orders and invoices and
        read every order the store has.

````