Vesremont
Vesremont catalog, product search and buyer-authorized shopping operations.
- 1.0.0
- Version
- remote
- Transport
- 21
- Tools
Security review
Review passedReviewed 1d ago.
- tools: 21 tools scanned
- metadata: scanned
No findings.
Tools (21)
search_products
Find current catalog products using the same search and filters as the storefront. Returns a bounded page with an exact total; narrow overly broad queries. Public; no OAuth required. Read-only.
get_product
Read a current product, price, aggregate warehouse stock and public characteristics. Stock does not promise same-day pickup; unknown values remain null. Public; no OAuth required. Read-only.
search_brands
Find brands through the storefront brand search, including its typo suggestions. Returns paginated public brand links. Public; no OAuth required. Read-only.
get_catalog_filters
Read real contextual catalog filters for a section or brand. Use returned IDs when searching; do not invent characteristic IDs. Public; no OAuth required. Read-only.
get_product_reviews
Read only moderated, published product reviews with real rating data and pagination. Public; no OAuth required. Read-only.
get_cart
Read the consenting buyer's existing basket and recheck its current prices and stock. OAuth scopes: cart:read. Read-only.
add_cart_item
Add a product quantity to the consenting buyer's existing basket. Quantity is an increment; do not retry blindly or use this to create an order. OAuth scopes: cart:write. Changes buyer or order state.
update_cart_item
Set the absolute quantity of an item in this buyer's basket. Quantity zero removes it. OAuth scopes: cart:write. Changes buyer or order state.
remove_cart_item
Remove an item owned by this buyer from their existing basket. OAuth scopes: cart:write. Changes buyer or order state.
get_favorites
Read the consenting buyer's existing favorites. OAuth scopes: favorites:read. Read-only.
add_favorite
Add a current public product to this buyer's favorites. OAuth scopes: favorites:write. Changes buyer or order state.
remove_favorite
Remove a product from this buyer's favorites. OAuth scopes: favorites:write. Changes buyer or order state.
get_checkout
Read current checkout details, validation and available store options. Unquoted delivery and final totals stay null; no payment is made. OAuth scopes: checkout:read. Read-only.
update_checkout
Update the buyer's delivery, payment or contact choices in the existing checkout. Does not send an order or make a payment. OAuth scopes: checkout:write. Changes buyer or order state.
prepare_order
Prepare an exact current order summary and a short-lived browser confirmation link. The buyer must personally approve that summary; this does not submit it. OAuth scopes: order:prepare. Changes buyer or order state.
submit_order
Submit only an order already approved by the buyer in the confirmation page. Requires the returned token and a stable unique idempotency_key; retry the same key after uncertainty. Never bypass confirmation. OAuth scopes: order:submit. Changes buyer or order state.
get_order
Read an order created by this application for the same buyer session, including after reauthorization. Saving means submitted, not confirmed by the store; unavailable history or confirmation data remain null. OAuth scopes: orders:read. Read-only.
list_webhooks
List this application and buyer session's order event subscriptions. Signing secrets are never returned again. OAuth scopes: webhooks:read. Read-only.
create_webhook
Create a pending order event subscription to a public HTTPS receiver. Returns its signing secret ONCE. The receiver must echo the signed verification challenge before activation. No customer contact fields are sent. Check expires_at and requires_active_grant. OAuth scopes: webhooks:write, orders:read. Changes buyer or order state.
delete_webhook
Revoke an owned order event subscription and cancel queued deliveries. An already in-flight HTTPS request cannot be recalled. OAuth scopes: webhooks:write. Changes buyer or order state.
list_webhook_deliveries
Read the latest 100 delivery attempts for an owned subscription, without event payloads or secrets. OAuth scopes: webhooks:read. Read-only.