TypeScript SDK
Install and start using the TypeScript SDK.
Intro
The Walmart Seller API — Authorization SDK provides access to the Walmart Seller API — Authorization REST APIs.
OAuth token issuance for Walmart Marketplace, covering both v4 authorization flows in one contract:
- Seller-direct (
client_credentials) — a seller's own application exchanges its client credentials for a short-lived access token, then calls the v4 APIs withAuthorization: Bearer <token>. - Solution-Provider delegated (
authorization_code+ PKCE,refresh_token, and Dynamic Client Registration) — a seller grants a Solution Provider's application access to their Marketplace account.
Both flows are served by the Authorization API as a stateless proxy to
Walmart IAM : IAM remains the sole issuer; no secrets are stored and no
tokens are signed here. Access tokens are opaque, Bearer-type, short-lived;
refresh tokens (delegated flow) are rotated on use. Never log tokens.
One token endpoint, grant dispatch
POST /auth/v4/token handles all three grants (client_credentials,
authorization_code, refresh_token) via grant_type dispatch — the merged v4
contract ( for seller-direct, for delegated). This is why the two
formerly separate specs (openapi.yaml + delegated-oauth.yaml) are now a single
document: a path can carry exactly one post:, so one file makes the shared
endpoint unambiguous for codegen and for the implementing controller.
Posture
- Seller-direct is OAuth 2.0 : documents what IAM/Apigee already do.
IAM cannot add new auth features for this flow, so
client_credentialsissues no refresh token,scope=is accepted-but-ignored (no down-scoping), and introspection (RFC 7662) / revocation (RFC 7009) / discovery (RFC 8414) are deliberately absent. - Delegated is OAuth 2.1 : IAM already supports PKCE (
S256), refresh rotation (~1-year TTL viaoffline_access), and Dynamic Client Registration (RFC 7591), so this flow specifies them properly.
The one modernization over /v3 shared by both flows is the access-token
header: v4 uses the standard Authorization: Bearer and does not use
WM_SEC.ACCESS_TOKEN (the gateway already tolerates Bearer).
Delegated-flow upstream gaps (, pending)
GET /auth/v4/authorize documents the OAuth-2.1-correct target. Three of its
guarantees depend on upstream changes that are not yet in place: iss
emission (RFC 9207), exact redirect_uri enforcement, and server-side PKCE S256
enforcement (rejecting plain) are IAM / app-store responsibilities tracked in
. the Authorization API validates the request-side invariants it can and
redirects correctly; the full end-to-end guarantee lands when IAM + app-store ship
those changes.
Pod Owner: Pod 0 — Core & Auth Implementation target: the Authorization API (proxy) → Walmart IAM
Installation
The SDK compiles to dist/ before it can be referenced — run its build script once in the SDK folder, then add it to your project by path:
npm install <path-to-sdk>Quick Start
Create one client and reuse it. Configure its behaviour through ClientOptions.
import {
PkceMethod,
ServerEnvironment,
WalmartSellerApiAuthorizationClient,
} from "walmart-seller-api-authorization";
const client = new WalmartSellerApiAuthorizationClient({
serverEnvironment: ServerEnvironment.Production,
sellerAuthAuthorizationCode: {
clientId: "YOUR_CLIENT_ID",
redirectUri: "YOUR_REDIRECT_URI",
pkce: PkceMethod.S256,
promptForAuthorizationCode: (authorizationUrl, signal) => Promise.resolve("YOUR_AUTHORIZATION_CODE"),
},
sellerAuthClientCredentials: { clientId: "YOUR_CLIENT_ID", clientSecret: "YOUR_CLIENT_SECRET" },
basicClientAuth: { username: "YOUR_USERNAME", password: "YOUR_PASSWORD" },
});Nothing in ClientOptions is required — new WalmartSellerApiAuthorizationClient() compiles — and each option left out falls back to its default. serverEnvironment is spelled out above so the environment a call reaches is visible where the client is built rather than inherited silently.
From CommonJS
The package ships both dialects from a single entry, so require works with full types. In a TypeScript CommonJS file use the import ... = require(...) form — a plain destructuring require runs fine but gives you any.
import sdk = require("walmart-seller-api-authorization");
const client = new sdk.WalmartSellerApiAuthorizationClient({
serverEnvironment: sdk.ServerEnvironment.Production,
sellerAuthAuthorizationCode: {
clientId: "YOUR_CLIENT_ID",
redirectUri: "YOUR_REDIRECT_URI",
pkce: sdk.PkceMethod.S256,
promptForAuthorizationCode: (authorizationUrl, signal) => Promise.resolve("YOUR_AUTHORIZATION_CODE"),
},
sellerAuthClientCredentials: { clientId: "YOUR_CLIENT_ID", clientSecret: "YOUR_CLIENT_SECRET" },
basicClientAuth: { username: "YOUR_USERNAME", password: "YOUR_PASSWORD" },
});