Agilix Shop integration with Allegro

How the Agilix Sklep app uses the Allegro REST API: purpose, operation, authorization, permissions, data and compliance with the terms.

As of 29 September 2026.

Agilix Sklep is an application registered in Allegro Developer Apps that connects the agilix.dog online shop (toys, treats and accessories for dogs) with a seller account on Allegro. With it the shop keeps one product catalogue, one stock level and one order process - without running a second back office in the Allegro panel.

The application is built and maintained by:

Hackerman Consulting - Adam Gajzlerowicz

NIP 7772841677

Regon 380997651

Hebanowa 16E, 62-020 Zalasewo, woj. wielkopolskie

+48 737 909 076

adam@agilix.dog

What the application is for

  • listing agilix.dog shop products as Allegro offers and keeping their name, description, images and price up to date;
  • keeping one shared stock level - a sale in the shop lowers the quantity of the Allegro offer, and a sale on Allegro lowers the shop stock, usually within a minute;
  • bringing paid Allegro orders into the shop order panel, so they are fulfilled together with orders placed in the shop;
  • sending the fulfilment status and the tracking number back to Allegro.

Who uses the application

The application is used only by the administrator of the agilix.dog shop, in the shop settings of the admin panel. The administrator connects one Allegro seller account - the one the shop sells from. Buyers and other Agilix users never sign in to Allegro through this application and have no access to its settings.

How offers are listed

The administrator ticks "Synchronise with Allegro" on a product and chooses the category, the required parameters and the Allegro price. After the product is saved, the Agilix server uploads the images to Allegro in the background, creates or updates the offer (product, category and parameters, GPSR producer and responsible person data, price, quantity, shipping rates, return and complaint conditions) and publishes it.

  • Unticking the box, deactivating the product or running out of stock ends the offer; availability coming back reactivates it.
  • Changes go through a background job queue, so editing in the shop never waits for Allegro.
  • If Allegro rejects an offer, the administrator sees the error code and Allegro's message next to the product and can retry the sync.

How orders are handled

  • Once a minute the server reads the order event journal from the last processed event.
  • An order enters the shop only when it is ready for processing (READY_FOR_PROCESSING) and has not been cancelled; every order is imported exactly once and the stock drops by the ordered quantity.
  • Cancelling an order on Allegro cancels it in the shop and restores the stock.
  • When the administrator changes the order status or ships the parcel, the application updates the fulfilment status on Allegro and adds the tracking number.
  • Refunds for Allegro orders are handled in the Allegro panel, outside the application.

How users are authorized

The application uses the standard OAuth 2.0 Authorization Code flow provided by Allegro. It never asks anyone for a login, password, Client ID or Client Secret.

  1. The administrator clicks "Connect to Allegro" in the shop settings. The server creates a signed state parameter, valid for 15 minutes and bound to that administrator.
  2. The browser goes to the Allegro sign-in page (https://allegro.pl/auth/oauth/authorize), where the seller signs in to their account and consents to the application's permissions.
  3. Allegro redirects to the registered address https://api.agilix.dog/allegro/oauth/callback. The server checks the signature and expiry of state and that the user is still a shop administrator, then exchanges the code for tokens (https://allegro.pl/auth/oauth/token), authenticating with the application's own Client ID and Client Secret.
  4. The server reads the login of the connected account and saves the connection. The refresh token is stored on the server only, encrypted with AES-256-GCM. The access token is refreshed automatically, and each new refresh token replaces the previous one immediately.

The Client Secret and the tokens never reach the browser, the mobile app or any third party.

Application permissions

The application asks only for the permissions the features above need:

allegro:api:profile:read
reading the login of the connected account, so the administrator can see which Allegro account is connected.
allegro:api:sale:offers:read
reading the shop's offers and the results of their creation, plus category suggestions and category parameters.
allegro:api:sale:offers:write
creating, editing, publishing and ending the shop's offers and uploading their images.
allegro:api:sale:settings:read
reading shipping rates, return and complaint conditions, and responsible producer and person data (GPSR), so the administrator can choose them for offers.
allegro:api:sale:settings:write
adding responsible producer data (GPSR) when the account has none yet.
allegro:api:orders:read
reading order events and details, carriers and shipments.
allegro:api:orders:write
updating the order fulfilment status and adding the tracking number.

REST API resources used

All requests are sent from the Agilix server to https://api.allegro.pl (images to https://upload.allegro.pl) on behalf of the connected account:

Offers and publication

  • POST /sale/product-offers
  • PATCH /sale/product-offers/{offerId}
  • GET /sale/product-offers/{offerId}
  • GET /sale/product-offers/{offerId}/operations/{operationId}
  • PUT /sale/offer-publication-commands/{commandId}
  • GET /sale/offer-publication-commands/{commandId}

Images

  • POST /sale/images

Categories and parameters

  • GET /sale/matching-categories
  • GET /sale/categories/{categoryId}/parameters

Sales settings

  • GET /sale/shipping-rates
  • GET /after-sales-service-conditions/return-policies
  • GET /after-sales-service-conditions/implied-warranties
  • GET /after-sales-service-conditions/warranties
  • GET /sale/responsible-producers
  • POST /sale/responsible-producers
  • GET /sale/responsible-persons

Orders

  • GET /order/events
  • GET /order/event-stats
  • GET /order/checkout-forms/{checkoutFormId}

Fulfilment and shipments

  • PUT /order/checkout-forms/{checkoutFormId}/fulfillment
  • GET /order/checkout-forms/{checkoutFormId}/shipments
  • POST /order/checkout-forms/{checkoutFormId}/shipments
  • GET /order/carriers

Account

  • GET /me

Data processed

The application processes only the data needed to sell: the shop's offer data and Allegro order data - name, delivery address or pickup point, phone number, the allegromail.pl e-mail address, invoice details, ordered products and the message to the seller.

Order data is used only to fulfil and ship that order. The shop sends Allegro buyers no e-mails at all - neither transactional nor marketing - and never uses their data for marketing.

Personal data processing rules: Privacy Policy

Compliance with the Allegro REST API terms

  • The application uses only its own Client ID and Client Secret, kept as server secrets; it shares them with no one and never asks users for their keys.
  • It gains access to a seller account only through OAuth 2.0, with the seller's consent and within the permissions listed above.
  • Every request carries a fixed User-Agent header identifying the application: Agilix-Sklep/1.0.0 (+https://agilix.dog/).
  • The application respects the limits: it polls the order journal once a minute, updates offers only after a product changes, and after a 429 response waits as long as the Retry-After header says.
  • It never bulk-downloads offers or data of other sellers and buyers; API data is used only to run the connected account's sales.
  • All communication uses HTTPS only, and tokens are stored encrypted.

Disconnecting the account

The administrator can click "Disconnect" in the shop settings at any time - the server then deletes the stored tokens and the offer links, and the application stops sending requests for that account. Access can also be revoked on the Allegro side, in the account settings; the application then marks the connection as disconnected and shows this to the administrator.

Questions about the application: adam@agilix.dog.