Create a price list
Authorizations
A secret API key. Publishable keys cannot reach this API. A key may carry an expiry, and an expired key is refused exactly like an unknown one, with a 401 that names no reason; check the key's expires_at in the dashboard rather than inferring it from a response. When a merchant rolls a key's secret they choose a grace window of up to 3 days, and for its duration BOTH the new secret and the one it replaced authenticate, so an integration moves over on its own deploy schedule instead of at the instant the button is pressed. Move before the window closes: after it, the old secret is refused. Nothing else about this contract moves with a roll. The key keeps its id and its scopes, so the only thing an integration updates is the credential itself.
Headers
A unique key per logical write. Replaying a request with the same key returns the first response byte for byte instead of applying the write twice.
Body
The list is inert until prices land on it through POST /price-lists/{priceListId}/prices, and it defaults to disabled so that going live is a deliberate second act. Nothing is emitted: this family publishes no webhook topics, so clients poll.
Required on create.
Required on create. A list price applies only when it is strictly BELOW the variant's base price, on both types: a price INCREASE pushed through an "override" list answers 200 and changes nothing at checkout.
sale, override Defaults to disabled on create, so a public create cannot put pricing in front of shoppers without a second deliberate act. Flipping to active takes effect at the next cart recompute: resolution happens at read time and is never snapshotted, so carts already in flight re-price.
active, disabled Merchant notes. Never shown to a shopper.
2000Response
Created
