Retrieve cart recovery settings
The abandoned-cart programme: whether it is on, how long after a cart goes idle each of the three recovery emails is sent, and the sender name and discount code that mail carries. A store that has never saved settings reads back the DISABLED DEFAULT rather than a 404. The programme exists for every store and is off until switched on, and a 404 would say the feature is unavailable on this platform, which is a different and wrong conclusion.
Authorizations
A secret API key. Publishable keys cannot reach this API. A key may carry an expiry, and an expired key is refused exactly like an unknown one, with a 401 that names no reason; check the key's expires_at in the dashboard rather than inferring it from a response. When a merchant rolls a key's secret they choose a grace window of up to 3 days, and for its duration BOTH the new secret and the one it replaced authenticate, so an integration moves over on its own deploy schedule instead of at the instant the button is pressed. Move before the window closes: after it, the old secret is refused. Nothing else about this contract moves with a roll. The key keeps its id and its scopes, so the only thing an integration updates is the credential itself.
Response
Success
