C# SDK
Install and start using the C# SDK.
Intro
The Walmart Seller API — Authorization SDK provides access to the Walmart Seller API — Authorization REST APIs.
OAuth token issuance for Walmart Marketplace, covering both v4 authorization flows in one contract:
- Seller-direct (
client_credentials) — a seller's own application exchanges its client credentials for a short-lived access token, then calls the v4 APIs withAuthorization: Bearer <token>. - Solution-Provider delegated (
authorization_code+ PKCE,refresh_token, and Dynamic Client Registration) — a seller grants a Solution Provider's application access to their Marketplace account.
Both flows are served by the Authorization API as a stateless proxy to
Walmart IAM : IAM remains the sole issuer; no secrets are stored and no
tokens are signed here. Access tokens are opaque, Bearer-type, short-lived;
refresh tokens (delegated flow) are rotated on use. Never log tokens.
One token endpoint, grant dispatch
POST /auth/v4/token handles all three grants (client_credentials,
authorization_code, refresh_token) via grant_type dispatch — the merged v4
contract ( for seller-direct, for delegated). This is why the two
formerly separate specs (openapi.yaml + delegated-oauth.yaml) are now a single
document: a path can carry exactly one post:, so one file makes the shared
endpoint unambiguous for codegen and for the implementing controller.
Posture
- Seller-direct is OAuth 2.0 : documents what IAM/Apigee already do.
IAM cannot add new auth features for this flow, so
client_credentialsissues no refresh token,scope=is accepted-but-ignored (no down-scoping), and introspection (RFC 7662) / revocation (RFC 7009) / discovery (RFC 8414) are deliberately absent. - Delegated is OAuth 2.1 : IAM already supports PKCE (
S256), refresh rotation (~1-year TTL viaoffline_access), and Dynamic Client Registration (RFC 7591), so this flow specifies them properly.
The one modernization over /v3 shared by both flows is the access-token
header: v4 uses the standard Authorization: Bearer and does not use
WM_SEC.ACCESS_TOKEN (the gateway already tolerates Bearer).
Delegated-flow upstream gaps (, pending)
GET /auth/v4/authorize documents the OAuth-2.1-correct target. Three of its
guarantees depend on upstream changes that are not yet in place: iss
emission (RFC 9207), exact redirect_uri enforcement, and server-side PKCE S256
enforcement (rejecting plain) are IAM / app-store responsibilities tracked in
. the Authorization API validates the request-side invariants it can and
redirects correctly; the full end-to-end guarantee lands when IAM + app-store ship
those changes.
Pod Owner: Pod 0 — Core & Auth Implementation target: the Authorization API (proxy) → Walmart IAM
Installation
Add the SDK as a project reference into your solution:
dotnet add reference <path-to-sdk>/WalmartSellerApiAuthorization.csprojQuick Start
Dependency Injection
Register the client with IServiceCollection and resolve it from the container. The HttpClient is managed by IHttpClientFactory. Configure the client's behavior through WalmartSellerApiAuthorizationClientOptions.
services.AddWalmartSellerApiAuthorizationClient(options =>
{
options.BasicClientAuth = new BasicAuthCredentials { Username = "YOUR_USERNAME", Password = "YOUR_PASSWORD" };
options.SellerAuthClientCredentials =
new OAuth2ClientCredentials { ClientId = "YOUR_CLIENT_ID", ClientSecret = "YOUR_CLIENT_SECRET" };
options.SellerAuthAuthorizationCode =
new OAuth2AuthorizationCodeCredentials
{
ClientId = "YOUR_CLIENT_ID",
RedirectUri = "YOUR_REDIRECT_URI",
PromptForAuthorizationCode = (authUrl, ct) => Task.FromResult(""),
};
options.Environment = ServerEnvironment.Production;
// TODO: configure more client options here
});Direct Instantiation
Create the client by passing an HttpClient you manage yourself. Configure the client's behavior through WalmartSellerApiAuthorizationClientOptions.
var httpClient = new HttpClient();
// TODO: configure more client options here
var options = new WalmartSellerApiAuthorizationClientOptions
{
BasicClientAuth = new BasicAuthCredentials { Username = "YOUR_USERNAME", Password = "YOUR_PASSWORD" },
SellerAuthClientCredentials = new OAuth2ClientCredentials
{
ClientId = "YOUR_CLIENT_ID",
ClientSecret = "YOUR_CLIENT_SECRET",
},
SellerAuthAuthorizationCode = new OAuth2AuthorizationCodeCredentials
{
ClientId = "YOUR_CLIENT_ID",
RedirectUri = "YOUR_REDIRECT_URI",
PromptForAuthorizationCode = (authUrl, ct) => Task.FromResult(""),
},
Environment = ServerEnvironment.Production,
};
var client = new WalmartSellerApiAuthorizationClient(httpClient, options);