GRABO Affiliates
API docs

GRABO Affiliate API

Place drop-ship orders programmatically and get tracking back in the same call. Two interfaces over the same pipeline: a REST API, and an MCP server for agents. An order placed either way is identical to one placed in the portal.

Authentication

Every request carries your API key. Get it from your GRABO contact; it is shown once when your account is created.

X-Affiliate-Key: <your api key>

The MCP endpoint also accepts Authorization: Bearer <your api key>. Base URL for everything below: https://affiliates.grabo.com

How an order works

When you place an order we, in this order: charge your card on file, create the order, buy the shipping label, and return you the tracking number. You are emailed a receipt. Your customer is never emailed by us, and we do not ask for their email address: every message about the order goes to you. We ship direct to your customer with no GRABO invoice, price list or marketing insert in the box, so your customer never sees our pricing or our brand on the paperwork.

Retries are safe. reference is your own order number and we treat it as the idempotency key. Send the same reference twice and you get the original order back with created: false. Nothing is charged twice and nothing ships twice. This is the intended way to recover from a timeout.

Products

GET /api/products returns the catalogue with your cost applied. msrp is what your customer pays, cost is what you pay us. GET /api/products.csv returns the same as a spreadsheet.

curl -H "X-Affiliate-Key: $KEY" \
  https://affiliates.grabo.com/api/products
{
  "discount_pct": 30.0,
  "products": [
    { "sku": "GIP-V1", "name": "GRABO IMPACT PLATE",
      "msrp": 24.99, "cost": 17.49, "margin_each": 7.5,
      "in_stock": true, "stock_qty": 929, "weight_lb": 1.6 }
  ]
}

Place an order

POST /api/orders. Returns 201 when the order is new, 200 when it is an idempotent replay of one you already placed.

curl -X POST https://affiliates.grabo.com/api/orders \
  -H "X-Affiliate-Key: $KEY" -H "Content-Type: application/json" -d '{
  "reference": "your-order-1234",
  "ship_to": {
    "name": "Jose Lopez",
    "address_1": "6212 Flamingo Dr",
    "city": "Apollo Beach", "state": "FL",
    "postcode": "33572-2413", "country": "US",
    "phone": "+18134083599"
  },
  "items": [ { "sku": "GIP-V1", "quantity": 1 } ],
  "buy_label": true
}'
FieldRequiredNotes
referenceyesYour order number. The idempotency key, so it must be unique per order.
ship_toyesname, address_1, city, state, postcode required. country defaults to US. phone optional (carriers use it for delivery exceptions). No customer email: we never contact your customer, so we do not take one.
itemsyesArray of {sku, quantity}. Prices come from our catalogue; any price you send is ignored.
buy_labelnoDefault true. False creates the order without buying a label or returning tracking.
{
  "created": true,
  "order": {
    "id": 7, "woo_order_id": 42551,
    "status": "shipped", "payment_status": "paid",
    "cost_total": 17.49, "msrp_total": 24.99,
    "carrier": "UPS", "service": "Ground Saver",
    "tracking_number": "1Z...", "tracking_url": "https://..."
  },
  "items": [ ... ]
}

Order status

GET /api/orders          your recent orders
GET /api/orders/{id}     one order with its lines and tracking
statusMeaning
shippedLabel bought, tracking available. Normal end state.
createdOrder placed, no label bought (you sent buy_label: false).
error_paymentCard declined. No order, nothing shipped.
error_labelOrder exists but the label failed. We will ship it by hand.

MCP (for agents)

Streamable HTTP, stateless, at POST /mcp. Tools: list_products, place_order, get_order, list_orders. An initialize handshake is supported but not required, so a bare tools/call works.

{
  "mcpServers": {
    "grabo-affiliate": {
      "type": "http",
      "url": "https://affiliates.grabo.com/mcp",
      "headers": { "Authorization": "Bearer <your api key>" }
    }
  }
}

Or add it to Claude Code with:

claude mcp add --transport http grabo-affiliate \
  https://affiliates.grabo.com/mcp \
  --header "Authorization: Bearer $KEY"

A raw call, no handshake needed:

curl -X POST https://affiliates.grabo.com/mcp \
  -H "Authorization: Bearer $KEY" -H "Content-Type: application/json" -d '{
  "jsonrpc":"2.0","id":1,"method":"tools/call",
  "params":{"name":"place_order","arguments":{
     "reference":"your-order-1234",
     "ship_to":{"name":"Jose Lopez","address_1":"6212 Flamingo Dr",
                "city":"Apollo Beach","state":"FL","postcode":"33572-2413"},
     "items":[{"sku":"GIP-V1","quantity":1}]}}}'

Errors

CodeMeaning
400Bad request: unknown SKU, out of stock, missing address field, missing reference. The message says which.
401Missing or wrong API key.
404No such order, or not yours.

A declined card returns 400 with the reason. Nothing is charged and nothing ships. Fix the card and send the same reference again.

Questions: reply to your GRABO contact.