To set up eBay’s Trading API, create an eBay Developers account and an environment-specific keyset, authorize a Sandbox test user, then send XML over HTTPS to the matching Sandbox gateway. The 2015 tutorial that inspired this topic remains useful for its sequence, but its dashboard labels, API Test Tool references, compatibility level, and token assumptions are dated. This guide updates the setup and explains where to choose OAuth or the traditional Auth’n’Auth flow.
What the Trading API does
The Trading API is eBay’s XML-based API family for seller and listing operations. Depending on the task, calls include GetUser, GetItem, AddItem, ReviseItem, EndItem, and GetMyeBaySelling. Token-management calls include GetSessionID, FetchToken, GetTokenStatus, and RevokeToken.
It is not the same as eBay’s newer REST APIs. A marketplace application may need both families, depending on the operation. The original SitePoint tutorial described a PHP/MySQL application for creating and managing listings and store information; its setup concepts still help, but its implementation details should not be treated as eBay’s sole or preferred architecture. The original tutorial was published January 5, 2015.
What you need before making a call
- An eBay Developers Program account and an application keyset for the environment you intend to use.
- A Sandbox test user for Sandbox calls; eBay’s first-call guidance says only test users can invoke Sandbox calls.
- A user authorization token appropriate to the call and authentication flow.
- A server or development tool that can send HTTPS requests and inspect XML responses. For a web-based Auth’n’Auth flow, you also need reachable consent-return URLs.
- A plan for keeping application credentials and user tokens out of source control, browser code, and unredacted logs.
eBay’s first-call guide describes the Sandbox test-user and token prerequisites.
#1 Best Overall
Choose the right environment
Sandbox and Production are separate environments. Sandbox data is simulated, and its credentials, test users, and tokens do not carry over to Production. Use HTTPS for either gateway.
| Environment | XML gateway | Account |
|---|---|---|
| Sandbox | https://api.sandbox.ebay.com/ws/api.dll |
Sandbox test user |
| Production | https://api.ebay.com/ws/api.dll |
Real eBay account |
Confirm that the keyset, token, account, and endpoint all belong to the same environment before diagnosing an authorization error. eBay documents the gateways and XML-call setup in its XML call guide.
Create an application keyset
eBay’s traditional application identifiers are DevID, AppID, and CertID. DevID identifies the developer or company; AppID identifies the application; CertID identifies the application certificate/key pair. Create and manage separate Sandbox and Production keysets, and treat each value as a secret.
Do not assume every ordinary Trading API call needs all three identifiers in request headers. Header requirements depend on the call. Application keys are particularly relevant to token setup: eBay’s documentation specifies them for flows such as FetchToken, and a full keyset is required for calls such as GetTokenStatus and RevokeToken. Check the requirements for the specific operation in the XML guide, GetTokenStatus reference, and RevokeToken reference.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchChoose and configure authorization
Authentication is a key modernization decision. eBay supports the older Auth’n’Auth flow and OAuth for many APIs, including some traditional APIs; support and required scopes vary by API and operation. Check the documentation for the exact call rather than assuming the two token types are interchangeable.
Rank #2
Traditional Auth’n’Auth: session, consent, and token
This is the flow used by the 2015 tutorial. It requires a registered RuName, eBay’s return identity for the application’s consent flow. Configure the relevant RuName for the Sandbox or Production keyset, including the display name and description, application type, accepted and declined redirect URLs, privacy-policy URL, and token return method where applicable. Use reachable HTTPS URLs. The RuName supplied to GetSessionID must match the one registered for that environment and keyset.
- Call
GetSessionIDwith the application keys and registered RuName. - Send the user to eBay’s sign-in and consent flow using the session information.
- After approval, receive eBay’s redirect at the configured accepted URL.
- Call
FetchTokenwith the session ID and application keys. - Store the returned user token and its expiration securely, then use it for authorized calls.
The official Auth’n’Auth token tutorial documents this sequence. The GetSessionID reference and FetchToken reference describe their requirements.
OAuth: use it when the specific call supports it
For XML Trading API calls that support OAuth user access tokens, pass the token in the HTTP header X-EBAY-API-IAF-TOKEN. Confirm the operation’s authentication support and required scopes in current eBay documentation. Do not put an OAuth token in the Auth’n’Auth XML element or assume a legacy call accepts OAuth.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemseBay’s XML call guide and Trading API call-construction guide explain token placement.
Make a first request
Start with a read-only call such as GetUser or GetItem in Sandbox. A typical request includes the endpoint, a call-name header without the Request suffix, a site ID, and a compatibility level. Use the current supported schema version shown in eBay’s documentation or generated examples; do not copy the historical value 885 from the 2015 article.
Rank #3
For example, the XML body for GetItem has this shape:
<?xml version="1.0" encoding="utf-8"?>
<GetItemRequest xmlns="urn:ebay:apis:eBLBaseComponents">
<ItemID>ITEM_ID</ItemID>
</GetItemRequest>
For an OAuth-authorized call, the request headers are generally shaped like this; replace the compatibility level and site ID with values appropriate to the supported schema and operation:
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Content-Type: text/xml
X-EBAY-API-COMPATIBILITY-LEVEL: VERSION
X-EBAY-API-CALL-NAME: GetItem
X-EBAY-API-SITEID: 0
X-EBAY-API-IAF-TOKEN: YOUR_OAUTH_USER_TOKEN
For a traditional Auth’n’Auth call, place the user token in the request body instead:
<RequesterCredentials>
<eBayAuthToken>YOUR_AUTH_N_AUTH_TOKEN</eBayAuthToken>
</RequesterCredentials>
Token-management calls may need application-key headers such as X-EBAY-API-DEV-NAME, X-EBAY-API-APP-NAME, and X-EBAY-API-CERT-NAME; do not add them indiscriminately to calls that do not require them. Likewise, choose the site ID deliberately and keep it consistent with any site value in the request body. eBay’s XML request guide covers headers, namespace, and request shape; its Trading API guide covers site configuration.
Compatibility and development warnings
The X-EBAY-API-COMPATIBILITY-LEVEL header selects the schema version. Older versions may continue to work while they remain supported, but a dated version can leave an application behind current code lists and data. Review the AbstractRequestType reference and current call documentation when choosing or updating the version.
Rank #4
During development, <WarningLevel>High</WarningLevel> can help reveal unrecognized or deprecated elements and spelling or casing mistakes. eBay advises against using WarningLevel=High in production; omit it or use the production-appropriate default. See the request type reference.
Free tools Windows power users keep installed
One-click scans. No signup required.
Try calls with API Explorer
The 2015 article referred to an API Test Tool; current eBay documentation calls the tool API Explorer. Sign in to your eBay Developers account, open API Explorer, select Sandbox or Production, choose the API and call, provide or generate the required user access token, review the request, then run it and inspect the response. The selected environment needs a corresponding keyset. Use Sandbox while learning; API Explorer helps test sample calls but does not replace application-side secret storage, XML validation, token lifecycle management, error handling, or audit logging. Follow eBay’s API Explorer guide.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Store credentials and tokens safely
The original tutorial’s PHP/MySQL tables are examples, not a production-ready credential model. Keep application credentials separate from user authorization data, and associate each user’s token with the right account and environment. Store the expiration and, for OAuth, the token scope. Keep the RuName, environment, and intended eBay site or marketplace as explicit configuration rather than conflating them with item or user identifiers.
- Keep credentials out of source control and client-side JavaScript; use a server-side secret manager or protected configuration.
- Encrypt stored tokens at rest where appropriate, restrict access, and redact tokens and certificate values from logs.
- Separate Sandbox and Production secrets and never send a token to the other environment.
- Track expiration and authorization status; do not assume a token is permanent.
- Provide a way to revoke access when a user disconnects or a security incident requires it.
GetTokenStatus can report token validity, expiration, and revocation information. RevokeToken can invalidate a token.
Diagnose common setup failures
Authentication or authorization fails
Check that the endpoint, keyset, user account, and token are all for Sandbox or all for Production. For a token failure, also confirm that the token is current and placed correctly: Auth’n’Auth uses RequesterCredentials, while supported OAuth XML calls use X-EBAY-API-IAF-TOKEN.
Recommended Free Tools
The consent flow does not return a token
Check that the RuName in GetSessionID exactly matches the registered RuName for the selected environment and keyset, and that the accepted and declined URLs are reachable.
The call is rejected or routed incorrectly
Make sure X-EBAY-API-CALL-NAME omits the Request suffix: a GetItemRequest body uses GetItem in the header. Verify the XML namespace, element names, and casing as well.
Site or schema validation is unexpected
Use a deliberate site ID and check for consistency with the request body. If code-list or field validation behaves unexpectedly, confirm that the compatibility level and application schema reflect a currently supported version rather than the 2015 value.
Move from Sandbox to Production
- Create or confirm the Production keyset and configure the Production RuName and redirect URLs.
- Obtain consent and a token for the real eBay account through the selected supported authorization flow.
- Switch to the Production gateway and Production credentials; never reuse Sandbox credentials or tokens.
- Verify the intended eBay site and marketplace settings, and remove development-only warning settings.
- Begin with read-only calls. Test listing or modification calls only when ready for their real seller-side effects.
Setup is only the foundation
A successful API call does not make a listing application production-ready. Listing operations such as AddItem require operation-specific validation and current marketplace data. A complete application also needs inventory synchronization, revision and ending logic, resilient error handling and retries, reconciliation, rate-limit monitoring, and appropriate notification handling. The Trading API may need to be combined with newer eBay APIs to cover the full workflow.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




