Developers · Concierge API 1.0

Build with Concierge. Own the experience.

Bring Concierge into your own experience with a streaming API, multimodal input, and the same engine that powers HawkShift’s storefront agent: our own commerce search, live checks on every size and colour, web research and memory. Every turn streams its steps. Product claims are grounded in your catalogue. Actions come back for your storefront to run — nothing writes to your cart until you do.

Want to see it answer first? Try Concierge on a live store.

2 callsto a streaming answerOne keyper store1.0additive changes only
# 1. start a conversation
curl -X POST https://hawkshift.com/api/futurehawk/v1/conversations \
  -H "Authorization: Bearer fhk_…"

# 2. send a message and stream the answer
curl -N -X POST https://hawkshift.com/api/futurehawk/v1/conversations/$ID/stream \
  -H "Authorization: Bearer fhk_…" \
  -H "Content-Type: application/json" \
  -d '{"message":"Waterproof running shoes, 10 wide"}'
Response stream streaming
Three ways to build

From no code to all code.

No code

Shopify app

Install the app, approve scopes, enable the theme block. Concierge reads your catalogue, prices and stock — install and setup, not application code.

# Shopify Install → Sync catalogue → Enable block
A little code

Widget on any site

Allowlist your origin in the dashboard. Your server mints a short-lived token. Add one script tag, or call Concierge API from your own UI.

POST /v1/widget-tokens { "origin": "https://shop.example.com" }
Your own interface

Concierge API

Build any experience: an app, a kiosk, your own chat. Concierge thinks; your code runs the actions.

POST /v1/conversations POST /v1/conversations/{id}/stream
Anatomy of a turn

Concierge decides. Your code acts.

Actions like CART_ADD come back in the response. On Shopify, the storefront applies cart mutations to the shopper’s browser cart. On your own UI, you run what you support and ignore the rest.

POST /stream

You send a message

Plus optional context: history, memory, current products, attachments.

event: step

Progress streams back

Understanding, searching, checking. Show it, or don’t. Trust only done.

› understanding› searching› checking stock
event: done

One final answer

Authoritative envelope: text, products and typed actions.

“Three fit. The Ridge Runner GTX is closest.”
actions[]

You run the actions

Your store, your rules.

CART_ADDADD_TO_LISTPROPOSE_ALERTnavigate_to
Widget on your site

Mint a token. Mount the widget.

Permanent keys stay on your server. The browser only ever sees a short-lived widget token bound to your origin.

1 · Allowlist + key

In the dashboard: create a key, add your storefront origin, turn the widget on. Keys are shown once.

# dashboard Integrations → API key Theme Studio → Allowed sites

2 · Mint from your server

Never call this from the browser with a permanent key. Optional: bind a conversation, pass your signed-in customer.

POST /v1/widget-tokens { "origin": "https://shop.example.com", "customer": "cust_123" }

3 · Add the widget

One script tag loads the widget from HawkShift. Point data-bootstrap-url at an endpoint on your site that mints a token and returns it with apiBaseUrl. See the token endpoint.

<div
  data-futurehawk-widget
  data-bootstrap-url="/api/concierge-token"
  data-title="Shopping assistant"
  data-position="right"
></div>
<script async src="https://hawkshift.com/futurehawk/embed.js"></script>
Secure by design

Keys stay on your server. Tokens expire fast.

Shown once

API keys are shown a single time and stored only as a hash. Nobody can read them back, including us.

One key, one store

Each key belongs to exactly one store. The key decides where a request goes — never the request body.

Widget tokens expire

Browser tokens last five minutes by default, fifteen at most, and only work on the origin they were minted for.

Revoke in one step

Revoking a key also cuts off every widget token minted with it. Rotate by creating new, deploying, then revoking old.

Platforms

ShopifyAvailable · App · install in minutes
WooCommerceAvailable October 16
MagentoAvailable October 16
WixAvailable October 16
SquarespaceAvailable October 16
Any storefrontAvailable · Concierge API + widget
Concierge APIAvailable · 1.0
Hosted storefront widgetAvailable
Agent endpoint (UCP · MCP · WebMCP)Live from October 9

Errors you can rely on

400Invalid request — including trying to override store or environment in the body
401Key or widget token missing, wrong, expired or revoked
403Wrong store/environment, or origin not allowed
409Setup incomplete or widget disabled
429Rate limit — back off and retry
503Catalogue or signing unavailable right now
Also in 1.0

More than chat. Still one contract.

Catalogue grounding

Product facts Concierge asserts are checked against your catalogue evidence — not free invention. How it works

Agent tasks

Longer work continues over /task, /task-stream and /task-kick on the same conversation.

Shopper memory

Widget tokens can carry a durable shopper subject and your own customer id — memory that belongs to the shopper, scoped to your store. Read more

Universal Search

Results come from HawkShift’s own search engine: word and meaning search, a shopping-relevance re-ranker, and each product’s sizes and colours with live stock per option.

Store knowledge and handoff

Store questions are answered from the store’s policies, website and business knowledge. When a shopper needs a person, the turn returns a drafted message for the store’s inbox.

Dashboard

Keys, origins, Theme Studio, catalogue sync and Shopify install — all in one place after you sign in.

Agentic commerce · Live from October 9

Built for the agents shopping for people.

Shoppers increasingly send their own AI agent. Concierge meets it at three levels, on every platform it runs on.

Level 1 · MCP

Agent connector

Your store gets its own MCP address. Add it as a connector in ChatGPT, Claude or any MCP client, and the agent can search your catalogue, ask Concierge about your products and policies, and open verified product links. Read-only, rate-limited, and never touching a cart or an order.

Level 2 · UCP · REST

Open commerce protocol

The same endpoint speaks the Universal Commerce Protocol over REST, with a discovery document, so agents built for UCP can search your catalogue and ask your Concierge without custom work. Answers are Concierge’s checked answers, with links back to your store.

Level 3 · WebMCP

On your storefront

Concierge registers its product-search and store-question tools on your storefront through WebMCP, so an AI agent browsing your site works from your live catalogue instead of guessing from the page, and can open Concierge with the question ready for the shopper.

Documentation

Everything, in order.

Developers

Start building today.

Create a key in the dashboard after you sign in. Your first streamed answer is two calls away.

See pricing, try the live store, or read our research.