Use your ajar API key to sign in. Request a Depop email link through Depop, then copy the fresh, unopened link into POST /v1/connections/depop/email/complete as {"magic_link_url":"https://www.depop.com/login/magic-link/verify/.../web"}. A link is one use and should never be stored in source code or logs.
Save the returned depop_token securely on your device. Send Authorization: Bearer YOUR_AJAR_API_KEY and x-depop-token: YOUR_DEPOP_TOKEN with each Depop operation. The token is bound to your ajar caller and expires at expires_at_epoch_s.
Before expiry, POST an empty body to /v1/connections/depop/refresh with your ajar Authorization bearer and x-depop-token. Replace your saved token with the returned depop_token. If it has expired, request a new Depop email link.
Messages, offers, and shipping-address adds require explicit confirmation and a new x-idempotency-key for each intended action. After an uncertain response, check Depop state before attempting another write. Discard the token locally to sign out; an earlier copy remains usable until expiry.
Authentication guide