DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Introducing eBay’s Trading API: A Current Setup Guide

A current guide to eBay Trading API setup: environment-specific keys, Sandbox testing, Auth’n’Auth versus OAuth, XML calls, and secure token handling.
From TheFinanceBase Team7 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To set up eBay’s Trading API, create an eBay Developers account and an environment-specific keyset, authorize a Sandbox test user, then send XML over HTTPS to the matching Sandbox gateway. The 2015 tutorial that inspired this topic remains useful for its sequence, but its dashboard labels, API Test Tool references, compatibility level, and token assumptions are dated. This guide updates the setup and explains where to choose OAuth or the traditional Auth’n’Auth flow.

What the Trading API does

The Trading API is eBay’s XML-based API family for seller and listing operations. Depending on the task, calls include GetUser, GetItem, AddItem, ReviseItem, EndItem, and GetMyeBaySelling. Token-management calls include GetSessionID, FetchToken, GetTokenStatus, and RevokeToken.

It is not the same as eBay’s newer REST APIs. A marketplace application may need both families, depending on the operation. The original SitePoint tutorial described a PHP/MySQL application for creating and managing listings and store information; its setup concepts still help, but its implementation details should not be treated as eBay’s sole or preferred architecture. The original tutorial was published January 5, 2015.

What you need before making a call

  • An eBay Developers Program account and an application keyset for the environment you intend to use.
  • A Sandbox test user for Sandbox calls; eBay’s first-call guidance says only test users can invoke Sandbox calls.
  • A user authorization token appropriate to the call and authentication flow.
  • A server or development tool that can send HTTPS requests and inspect XML responses. For a web-based Auth’n’Auth flow, you also need reachable consent-return URLs.
  • A plan for keeping application credentials and user tokens out of source control, browser code, and unredacted logs.

eBay’s first-call guide describes the Sandbox test-user and token prerequisites.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose the right environment

Sandbox and Production are separate environments. Sandbox data is simulated, and its credentials, test users, and tokens do not carry over to Production. Use HTTPS for either gateway.

Environment XML gateway Account
Sandbox https://api.sandbox.ebay.com/ws/api.dll Sandbox test user
Production https://api.ebay.com/ws/api.dll Real eBay account

Confirm that the keyset, token, account, and endpoint all belong to the same environment before diagnosing an authorization error. eBay documents the gateways and XML-call setup in its XML call guide.

Create an application keyset

eBay’s traditional application identifiers are DevID, AppID, and CertID. DevID identifies the developer or company; AppID identifies the application; CertID identifies the application certificate/key pair. Create and manage separate Sandbox and Production keysets, and treat each value as a secret.

Do not assume every ordinary Trading API call needs all three identifiers in request headers. Header requirements depend on the call. Application keys are particularly relevant to token setup: eBay’s documentation specifies them for flows such as FetchToken, and a full keyset is required for calls such as GetTokenStatus and RevokeToken. Check the requirements for the specific operation in the XML guide, GetTokenStatus reference, and RevokeToken reference.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose and configure authorization

Authentication is a key modernization decision. eBay supports the older Auth’n’Auth flow and OAuth for many APIs, including some traditional APIs; support and required scopes vary by API and operation. Check the documentation for the exact call rather than assuming the two token types are interchangeable.

Traditional Auth’n’Auth: session, consent, and token

This is the flow used by the 2015 tutorial. It requires a registered RuName, eBay’s return identity for the application’s consent flow. Configure the relevant RuName for the Sandbox or Production keyset, including the display name and description, application type, accepted and declined redirect URLs, privacy-policy URL, and token return method where applicable. Use reachable HTTPS URLs. The RuName supplied to GetSessionID must match the one registered for that environment and keyset.

  1. Call GetSessionID with the application keys and registered RuName.
  2. Send the user to eBay’s sign-in and consent flow using the session information.
  3. After approval, receive eBay’s redirect at the configured accepted URL.
  4. Call FetchToken with the session ID and application keys.
  5. Store the returned user token and its expiration securely, then use it for authorized calls.

The official Auth’n’Auth token tutorial documents this sequence. The GetSessionID reference and FetchToken reference describe their requirements.

OAuth: use it when the specific call supports it

For XML Trading API calls that support OAuth user access tokens, pass the token in the HTTP header X-EBAY-API-IAF-TOKEN. Confirm the operation’s authentication support and required scopes in current eBay documentation. Do not put an OAuth token in the Auth’n’Auth XML element or assume a legacy call accepts OAuth.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

eBay’s XML call guide and Trading API call-construction guide explain token placement.

Make a first request

Start with a read-only call such as GetUser or GetItem in Sandbox. A typical request includes the endpoint, a call-name header without the Request suffix, a site ID, and a compatibility level. Use the current supported schema version shown in eBay’s documentation or generated examples; do not copy the historical value 885 from the 2015 article.

For example, the XML body for GetItem has this shape:

<?xml version="1.0" encoding="utf-8"?>
<GetItemRequest xmlns="urn:ebay:apis:eBLBaseComponents">
  <ItemID>ITEM_ID</ItemID>
</GetItemRequest>

For an OAuth-authorized call, the request headers are generally shaped like this; replace the compatibility level and site ID with values appropriate to the supported schema and operation:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Content-Type: text/xml
X-EBAY-API-COMPATIBILITY-LEVEL: VERSION
X-EBAY-API-CALL-NAME: GetItem
X-EBAY-API-SITEID: 0
X-EBAY-API-IAF-TOKEN: YOUR_OAUTH_USER_TOKEN

For a traditional Auth’n’Auth call, place the user token in the request body instead:

<RequesterCredentials>
  <eBayAuthToken>YOUR_AUTH_N_AUTH_TOKEN</eBayAuthToken>
</RequesterCredentials>

Token-management calls may need application-key headers such as X-EBAY-API-DEV-NAME, X-EBAY-API-APP-NAME, and X-EBAY-API-CERT-NAME; do not add them indiscriminately to calls that do not require them. Likewise, choose the site ID deliberately and keep it consistent with any site value in the request body. eBay’s XML request guide covers headers, namespace, and request shape; its Trading API guide covers site configuration.

Compatibility and development warnings

The X-EBAY-API-COMPATIBILITY-LEVEL header selects the schema version. Older versions may continue to work while they remain supported, but a dated version can leave an application behind current code lists and data. Review the AbstractRequestType reference and current call documentation when choosing or updating the version.

During development, <WarningLevel>High</WarningLevel> can help reveal unrecognized or deprecated elements and spelling or casing mistakes. eBay advises against using WarningLevel=High in production; omit it or use the production-appropriate default. See the request type reference.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Try calls with API Explorer

The 2015 article referred to an API Test Tool; current eBay documentation calls the tool API Explorer. Sign in to your eBay Developers account, open API Explorer, select Sandbox or Production, choose the API and call, provide or generate the required user access token, review the request, then run it and inspect the response. The selected environment needs a corresponding keyset. Use Sandbox while learning; API Explorer helps test sample calls but does not replace application-side secret storage, XML validation, token lifecycle management, error handling, or audit logging. Follow eBay’s API Explorer guide.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Store credentials and tokens safely

The original tutorial’s PHP/MySQL tables are examples, not a production-ready credential model. Keep application credentials separate from user authorization data, and associate each user’s token with the right account and environment. Store the expiration and, for OAuth, the token scope. Keep the RuName, environment, and intended eBay site or marketplace as explicit configuration rather than conflating them with item or user identifiers.

  • Keep credentials out of source control and client-side JavaScript; use a server-side secret manager or protected configuration.
  • Encrypt stored tokens at rest where appropriate, restrict access, and redact tokens and certificate values from logs.
  • Separate Sandbox and Production secrets and never send a token to the other environment.
  • Track expiration and authorization status; do not assume a token is permanent.
  • Provide a way to revoke access when a user disconnects or a security incident requires it.

GetTokenStatus can report token validity, expiration, and revocation information. RevokeToken can invalidate a token.

Diagnose common setup failures

Authentication or authorization fails

Check that the endpoint, keyset, user account, and token are all for Sandbox or all for Production. For a token failure, also confirm that the token is current and placed correctly: Auth’n’Auth uses RequesterCredentials, while supported OAuth XML calls use X-EBAY-API-IAF-TOKEN.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The consent flow does not return a token

Check that the RuName in GetSessionID exactly matches the registered RuName for the selected environment and keyset, and that the accepted and declined URLs are reachable.

The call is rejected or routed incorrectly

Make sure X-EBAY-API-CALL-NAME omits the Request suffix: a GetItemRequest body uses GetItem in the header. Verify the XML namespace, element names, and casing as well.

Site or schema validation is unexpected

Use a deliberate site ID and check for consistency with the request body. If code-list or field validation behaves unexpectedly, confirm that the compatibility level and application schema reflect a currently supported version rather than the 2015 value.

Move from Sandbox to Production

  1. Create or confirm the Production keyset and configure the Production RuName and redirect URLs.
  2. Obtain consent and a token for the real eBay account through the selected supported authorization flow.
  3. Switch to the Production gateway and Production credentials; never reuse Sandbox credentials or tokens.
  4. Verify the intended eBay site and marketplace settings, and remove development-only warning settings.
  5. Begin with read-only calls. Test listing or modification calls only when ready for their real seller-side effects.

Setup is only the foundation

A successful API call does not make a listing application production-ready. Listing operations such as AddItem require operation-specific validation and current marketplace data. A complete application also needs inventory synchronization, revision and ending logic, resilient error handling and retries, reconciliation, rate-limit monitoring, and appropriate notification handling. The Trading API may need to be combined with newer eBay APIs to cover the full workflow.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.