Place drop-ship orders programmatically and get tracking back in the same call. Two interfaces over the same pipeline: a REST API, and an MCP server for agents. An order placed either way is identical to one placed in the portal.
Every request carries your API key. Get it from your GRABO contact; it is shown once when your account is created.
X-Affiliate-Key: <your api key>
The MCP endpoint also accepts Authorization: Bearer <your api key>.
Base URL for everything below: https://affiliates.grabo.com
When you place an order we, in this order: charge your card on file, create the order, buy the shipping label, and return you the tracking number. You are emailed a receipt. Your customer is never emailed by us, and we do not ask for their email address: every message about the order goes to you. We ship direct to your customer with no GRABO invoice, price list or marketing insert in the box, so your customer never sees our pricing or our brand on the paperwork.
Retries are safe. reference is your own order number and
we treat it as the idempotency key. Send the same reference twice and you get the
original order back with created: false. Nothing is charged twice and
nothing ships twice. This is the intended way to recover from a timeout.
GET /api/products returns the catalogue with your cost applied.
msrp is what your customer pays, cost is what you pay us.
GET /api/products.csv returns the same as a spreadsheet.
curl -H "X-Affiliate-Key: $KEY" \
https://affiliates.grabo.com/api/products
{
"discount_pct": 30.0,
"products": [
{ "sku": "GIP-V1", "name": "GRABO IMPACT PLATE",
"msrp": 24.99, "cost": 17.49, "margin_each": 7.5,
"in_stock": true, "stock_qty": 929, "weight_lb": 1.6 }
]
}
POST /api/orders. Returns 201 when the order is new,
200 when it is an idempotent replay of one you already placed.
curl -X POST https://affiliates.grabo.com/api/orders \
-H "X-Affiliate-Key: $KEY" -H "Content-Type: application/json" -d '{
"reference": "your-order-1234",
"ship_to": {
"name": "Jose Lopez",
"address_1": "6212 Flamingo Dr",
"city": "Apollo Beach", "state": "FL",
"postcode": "33572-2413", "country": "US",
"phone": "+18134083599"
},
"items": [ { "sku": "GIP-V1", "quantity": 1 } ],
"buy_label": true
}'
| Field | Required | Notes |
|---|---|---|
reference | yes | Your order number. The idempotency key, so it must be unique per order. |
ship_to | yes | name, address_1, city, state, postcode required. country defaults to US. phone optional (carriers use it for delivery exceptions). No customer email: we never contact your customer, so we do not take one. |
items | yes | Array of {sku, quantity}. Prices come from our catalogue; any price you send is ignored. |
buy_label | no | Default true. False creates the order without buying a label or returning tracking. |
{
"created": true,
"order": {
"id": 7, "woo_order_id": 42551,
"status": "shipped", "payment_status": "paid",
"cost_total": 17.49, "msrp_total": 24.99,
"carrier": "UPS", "service": "Ground Saver",
"tracking_number": "1Z...", "tracking_url": "https://..."
},
"items": [ ... ]
}
GET /api/orders your recent orders
GET /api/orders/{id} one order with its lines and tracking
status | Meaning |
|---|---|
shipped | Label bought, tracking available. Normal end state. |
created | Order placed, no label bought (you sent buy_label: false). |
error_payment | Card declined. No order, nothing shipped. |
error_label | Order exists but the label failed. We will ship it by hand. |
Streamable HTTP, stateless, at POST /mcp. Tools:
list_products, place_order, get_order,
list_orders. An initialize handshake is supported but not
required, so a bare tools/call works.
{
"mcpServers": {
"grabo-affiliate": {
"type": "http",
"url": "https://affiliates.grabo.com/mcp",
"headers": { "Authorization": "Bearer <your api key>" }
}
}
}
Or add it to Claude Code with:
claude mcp add --transport http grabo-affiliate \
https://affiliates.grabo.com/mcp \
--header "Authorization: Bearer $KEY"
A raw call, no handshake needed:
curl -X POST https://affiliates.grabo.com/mcp \
-H "Authorization: Bearer $KEY" -H "Content-Type: application/json" -d '{
"jsonrpc":"2.0","id":1,"method":"tools/call",
"params":{"name":"place_order","arguments":{
"reference":"your-order-1234",
"ship_to":{"name":"Jose Lopez","address_1":"6212 Flamingo Dr",
"city":"Apollo Beach","state":"FL","postcode":"33572-2413"},
"items":[{"sku":"GIP-V1","quantity":1}]}}}'
| Code | Meaning |
|---|---|
| 400 | Bad request: unknown SKU, out of stock, missing address field, missing reference. The message says which. |
| 401 | Missing or wrong API key. |
| 404 | No such order, or not yours. |
A declined card returns 400 with the reason. Nothing is charged and nothing
ships. Fix the card and send the same reference again.
Questions: reply to your GRABO contact.