认证方式
登录成功后服务端会写入 sid Cookie,并返回 64 位 sessionToken。浏览器同域请求使用 Cookie;API 客户端推荐使用 Authorization 请求头。
Authorization: Bearer <sessionToken>X-Session-Token: <sessionToken>https://tk7188.top/api.php?route=面向主站、独立商家店铺和管理后台的接口参考。所有业务接口统一通过 api.php?route=接口路径 调用,JSON 请求请使用 UTF-8 编码。
先确认请求地址、认证方式和数据格式,再调用业务接口。
登录成功后服务端会写入 sid Cookie,并返回 64 位 sessionToken。浏览器同域请求使用 Cookie;API 客户端推荐使用 Authorization 请求头。
Authorization: Bearer <sessionToken>X-Session-Token: <sessionToken>Content-Type: application/json;文档上传接口使用 multipart/form-data。{"error":"错误说明"}。无需登录即可读取商城信息、健康状态和支付结果。
检查 PHP、数据目录和存储文件是否可用,适合部署后验收与监控。
GET https://tk7188.top/api.php?route=healthGET https://tk7188.top/api.php?route=health
{
"ok": true,
"phpVersion": "5.6.40",
"storage": { "readable": true, "writable": true }
}
注意:健康接口正常不代表支付配置已经完成。
返回商城名称、公告、分类、商品、登录用户和验证码配置。分站使用 merchant 参数。
GET https://tk7188.top/api.php?route=bootstrap| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
merchant | string | 否 | 分站标识,例如 merchant-1 |
GET https://tk7188.top/api.php?route=bootstrap
{
"shopName": "Future ai卡密小铺",
"settings": { "notice": "商城公告" },
"user": null,
"authConfig": {
"emailVerificationEnabled": true,
"captchaEnabled": true
},
"products": [],
"categories": []
}
注意:分站被封禁或不存在时返回 404;主站不传 merchant。
生成一次性验证码图片,验证码有效期为 300 秒。
GET https://tk7188.top/api.php?route=auth/captcha| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
purpose | enum | 是 | login 或 register |
GET https://tk7188.top/api.php?route=auth/captcha
{
"ok": true,
"captchaId": "7af...e90",
"image": "data:image/bmp;base64,...",
"expiresIn": 300
}
注意:提交登录、注册或发送邮箱验证码时同时传 captchaId 和 captchaCode。
按订单号返回脱敏后的商品订单或充值订单状态。
GET https://tk7188.top/api.php?route=order-query| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
orderNo | string | 是 | 平台订单号 |
GET https://tk7188.top/api.php?route=order-query
{
"type": "order",
"order": {
"orderNo": "K202607290001",
"status": "paid"
}
}
注意:公开查询不会返回完整卡密和敏感联系方式。
注册、登录、找回密码、修改密码和邮箱换绑。
根据 purpose 发送注册、登录、找回密码或邮箱换绑验证码。
POST https://tk7188.top/api.php?route=auth/email-code| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
purpose | enum | 是 | register、login、password_reset、email_change |
email | string | 按场景 | 注册或换绑时的新邮箱 |
identifier | string | 按场景 | 登录或找回密码时的用户名/邮箱 |
captchaId | string | 除换绑外 | 图形验证码 ID |
captchaCode | string | 除换绑外 | 用户输入的图形验证码 |
merchantSlug | string | 否 | 分站注册/登录时传入 |
{
"purpose": "register",
"email": "user@example.com",
"captchaId": "captcha-id",
"captchaCode": "A7K9"
}
{
"ok": true,
"message": "验证码已发送",
"email": "u***@example.com",
"cooldown": 60
}
注意:同一邮箱 60 秒内不能重复发送;同一 IP 10 分钟最多 5 次。
创建账号并立即建立会话。SMTP 启用时必须验证邮箱。
POST https://tk7188.top/api.php?route=register| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
username | string | 是 | 至少 3 个字符 |
password | string | 是 | 至少 6 位 |
email | string | 按配置 | SMTP 启用时必填 |
emailCode | string | 按配置 | 邮箱验证码 |
merchantSlug | string | 否 | 分站注册来源 |
{
"username": "future_user",
"password": "StrongPassword123",
"email": "user@example.com",
"emailCode": "123456"
}
{
"ok": true,
"sessionToken": "<64位会话令牌>",
"user": {
"id": 8,
"username": "future_user",
"isAdmin": false,
"balanceCents": 0
}
}
注意:浏览器端建议使用 HttpOnly Cookie;外部客户端可保存 sessionToken。
支持用户名或邮箱登录。普通用户在 SMTP 启用且已绑定邮箱时需要邮箱验证码。
POST https://tk7188.top/api.php?route=login| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
identifier | string | 是 | 用户名或邮箱,也兼容 username 字段 |
password | string | 是 | 账号密码 |
emailCode | string | 按配置 | 普通用户登录邮箱验证码 |
merchantSlug | string | 否 | 分站登录来源 |
{
"identifier": "future_user",
"password": "StrongPassword123",
"emailCode": "123456"
}
{
"ok": true,
"sessionToken": "<64位会话令牌>",
"user": { "id": 8, "username": "future_user" }
}
注意:失败次数过多会触发服务端登录限流;封禁账号不能使用业务功能。
只允许管理员账号登录,不要求普通用户的邮箱验证码和图形验证码。
POST https://tk7188.top/api.php?route=admin/login| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
identifier | string | 是 | 管理员用户名或邮箱 |
password | string | 是 | 管理员密码 |
{
"identifier": "admin",
"password": "<管理员强密码>"
}
{
"ok": true,
"sessionToken": "<64位会话令牌>",
"user": { "isAdmin": true }
}
注意:管理员登录同样受独立防爆破限流保护。
校验原密码后修改密码,并使该账号的其他登录会话失效。
POST https://tk7188.top/api.php?route=account/password| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
oldPassword | string | 是 | 当前密码 |
newPassword | string | 是 | 8 至 200 位新密码 |
{
"oldPassword": "OldPassword123",
"newPassword": "NewPassword456"
}
{
"ok": true,
"sessionToken": "<新的会话令牌>",
"user": { "id": 8 }
}
注意:调用成功后应立即用响应中的新令牌替换本地旧令牌。
使用发往新邮箱的验证码完成换绑,管理员不支持在线换绑。
POST https://tk7188.top/api.php?route=account/email| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
email | string | 是 | 未被其他账号使用的新邮箱 |
emailCode | string | 是 | purpose=email_change 的验证码 |
{
"email": "new@example.com",
"emailCode": "123456"
}
{
"ok": true,
"user": { "email": "new@example.com", "emailVerified": true }
}
注意:发送换绑验证码前必须已经登录。
验证账号绑定邮箱后重置普通用户密码,并注销该账号所有现有会话。
POST https://tk7188.top/api.php?route=auth/reset-password| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
identifier | string | 是 | 用户名或邮箱 |
newPassword | string | 是 | 8 至 200 位新密码 |
emailCode | string | 是 | purpose=password_reset 的验证码 |
{
"identifier": "future_user",
"newPassword": "RecoveredPassword789",
"emailCode": "123456"
}
{ "ok": true }
注意:管理员账号不能通过公开找回密码接口重置。
删除当前令牌对应的会话并清理认证 Cookie。
POST https://tk7188.top/api.php?route=logout{}
{ "ok": true }
创建订单、余额购买、充值、取消订单、查询支付状态与支付回调。
创建主站或分站商品订单。payType=balance 时必须登录并直接扣除余额及自动发货。
POST https://tk7188.top/api.php?route=orders| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
productId | integer | 是 | 商品 ID |
quantity | integer | 是 | 购买数量 |
contact | string | 是 | 收货联系方式 |
payType | enum | 是 | alipay、wxpay 或 balance |
merchantSlug | string | 分站必填 | 分站标识 |
{
"productId": 12,
"quantity": 1,
"contact": "user@example.com",
"payType": "balance",
"merchantSlug": "merchant-1"
}
{
"ok": true,
"orderNo": "K202607290001",
"status": "paid",
"payUrl": null,
"delivery": ["https://delivery.example/item"]
}
注意:第三方支付返回 payUrl;余额支付成功后立即自动发货。
读取当前用户的商品订单、充值记录和历史兼容退款记录。
GET https://tk7188.top/api.php?route=ordersGET https://tk7188.top/api.php?route=orders
{
"orders": [],
"recharges": [],
"refunds": []
}
注意:新售后退款统一通过工单处理,不再创建人工退款申请。
只允许订单本人取消未支付订单。取消不会扣减商品可售数量。
POST https://tk7188.top/api.php?route=orders/cancel| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
orderNo | string | 是 | 待支付订单号 |
{ "orderNo": "K202607290001" }
{
"ok": true,
"order": { "status": "cancelled" },
"orders": [],
"products": []
}
注意:已支付、已发货或已取消的订单不能重复取消。
创建 1 至 5000 元的易支付充值订单。
POST https://tk7188.top/api.php?route=recharge| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
amount | number | 是 | 充值金额,单位为元 |
payType | enum | 是 | alipay 或 wxpay |
{
"amount": 100,
"payType": "alipay"
}
{
"ok": true,
"orderNo": "R202607290001",
"payUrl": "https://payment.example/..."
}
注意:QQ 支付已经移除。余额仅在支付回调验签成功后入账。
商品订单允许公开读取脱敏状态;充值订单必须由订单本人登录查询。
GET https://tk7188.top/api.php?route=payment/status| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
order | string | 是 | 商品订单号或 R 开头的充值订单号 |
GET https://tk7188.top/api.php?route=payment/status
{
"ok": true,
"type": "order",
"order": { "status": "paid", "deliveryStatus": "delivered" }
}
注意:已登录用户只能读取自己的完整订单。
接收易支付通知,校验签名、商户号、金额和支付状态后完成充值或自动发货。
GET/POST https://tk7188.top/api.php?route=payment/notify| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
pid | string | 是 | 易支付商户 ID |
out_trade_no | string | 是 | 本站订单号 |
trade_no | string | 是 | 易支付交易号 |
trade_status | string | 是 | TRADE_SUCCESS 或 TRADE_FINISHED |
money | number | 是 | 支付金额 |
sign | string | 是 | 易支付签名 |
sign_type | string | 否 | 签名类型 |
out_trade_no=K202607290001&trade_status=TRADE_SUCCESS&sign=<签名>
success
注意:此接口由支付平台调用。不要在前端暴露商户密钥,也不要手工模拟成功回调。
购买文档商品、领取独立兑换码并生成一次性下载链接。
使用本人已发货订单中的 DOC- 兑换码换取下载链接。主站管理员和文件所属商家可测试自己有权限的文件。
POST https://tk7188.top/api.php?route=document/redeem| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
key | string | 是 | 订单发放的 DOC- 加 24 位十六进制兑换码 |
{
"key": "DOC-0123456789ABCDEF01234567"
}
{
"ok": true,
"name": "使用说明.pdf",
"downloadUrl": "/api/document/download?token=<48位令牌>"
}
注意:普通用户必须登录,且兑换码必须原样出现在本人状态为 delivered 的订单卡密中。
使用兑换接口返回的临时令牌下载私有文件。令牌与发起兑换的用户绑定。
GET https://tk7188.top/api.php?route=document/download| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
token | string | 是 | document/redeem 返回的 48 位下载令牌 |
GET https://tk7188.top/api.php?route=document/download
文件二进制内容
注意:下载令牌有效期 5 分钟且只能成功使用一次;不要把令牌发送给其他人。
退款、发货、补发、支付等售后问题统一走工单。
返回当前用户创建的全部售后工单及沟通记录。
GET https://tk7188.top/api.php?route=ticketsGET https://tk7188.top/api.php?route=tickets
{ "tickets": [] }
创建退款、售后、发货、补发、支付或其他类型工单,可关联本人订单。
POST https://tk7188.top/api.php?route=tickets| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
category | enum | 是 | refund、after_sales、delivery、restock、payment、other |
subject | string | 是 | 标题,最长 120 字节 |
content | string | 是 | 说明,最长 2000 字节 |
orderNo | string | 退款必填 | 只能关联当前用户自己的订单 |
merchantSlug | 分站场景 | 否 | 未关联订单时指定商家 |
{
"category": "delivery",
"subject": "支付成功但未收到卡密",
"content": "请核查订单发货状态",
"orderNo": "K202607290001"
}
{
"ok": true,
"ticket": {
"ticketNo": "T202607290001",
"status": "open"
}
}
注意:退款类工单必须关联订单;分站订单会自动进入对应商家后台。
用户回复自己的工单;主站管理员可回复主站工单并更新状态。
POST https://tk7188.top/api.php?route=tickets/reply| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
id | integer | 是 | 工单 ID |
content | string | 是 | 回复内容 |
status | enum | 管理员可用 | replied 或 closed |
{
"id": 15,
"content": "已补充支付截图",
"status": "replied"
}
{ "ok": true, "ticket": {} }
注意:分站工单必须由对应商家后台处理。
读取当前身份最近 50 条系统和工单通知。
GET https://tk7188.top/api.php?route=notificationsGET https://tk7188.top/api.php?route=notifications
{ "notifications": [] }
只会更新属于当前身份的通知。
POST https://tk7188.top/api.php?route=notifications/read| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
id | integer | 是 | 通知 ID |
{ "id": 22 }
{ "ok": true }
每个商家独立管理店铺、商品、库存、SMTP、支付和工单。
首次调用提交入驻申请;已有申请时更新资料,驳回后再次提交会回到待审核。
POST https://tk7188.top/api.php?route=merchants| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
shopName | string | 是 | 店铺名称 |
contactName | string | 是 | 联系人 |
contact | string | 是 | 联系方式 |
category | enum | 是 | 数字卡密、软件服务、会员权益、其他 |
description | string | 是 | 10 至 500 个字符 |
{
"shopName": "Future 软件店",
"contactName": "店主",
"contact": "owner@example.com",
"category": "软件服务",
"description": "提供正版数字软件服务"
}
{ "ok": true, "merchant": { "status": "pending" } }
返回当前用户拥有的商家资料和审核状态。
GET https://tk7188.top/api.php?route=merchants/mineGET https://tk7188.top/api.php?route=merchants/mine
{ "merchant": {} }
一次返回当前商家的资料、独立商品、订单、工单、文档、SMTP 和易支付配置。
GET https://tk7188.top/api.php?route=merchant/dashboardGET https://tk7188.top/api.php?route=merchant/dashboard
{
"merchant": {},
"products": [],
"orders": [],
"tickets": [],
"documents": [],
"smtp": {},
"epay": {}
}
注意:商家封禁或未审核通过时拒绝访问。
修改独立店铺名称、公告、客服说明和简介。
POST https://tk7188.top/api.php?route=merchant/settings| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
shopName | string | 是 | 店铺名称 |
notice | string | 否 | 店铺公告 |
service | string | 否 | 客服说明 |
description | string | 否 | 店铺简介 |
{
"shopName": "Future 软件店",
"notice": "每日自动发货",
"service": "工单回复时间 9:00-22:00",
"description": "数字商品独立店铺"
}
{ "ok": true, "merchant": {} }
保存商家自己的商品;不读取或覆盖主站商品。传 id 时编辑已有商品。
POST https://tk7188.top/api.php?route=merchant/products| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
id | integer | 编辑时 | 商品 ID |
name | string | 是 | 商品名称 |
price | number | 是 | 销售价,单位元 |
description | string | 否 | 商品说明 |
category | string | 否 | 商家自定义分类 |
active | boolean | 否 | 是否上架 |
{
"name": "软件月卡",
"price": 29.9,
"description": "购买后自动发货",
"category": "月卡",
"active": true
}
{ "ok": true, "products": [], "shopProducts": [] }
支持逐行卡密或重复链接。codes 可为换行文本,stock 用于补齐可售数量。
POST https://tk7188.top/api.php?route=merchant/product-stock| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
productId | integer | 是 | 商家商品 ID |
stock | integer | 是 | 目标可售数量 |
codes | string | 否 | 逐行卡密或链接,允许重复链接 |
{
"productId": 31,
"stock": 3,
"codes": "https://example.com/a\nhttps://example.com/a\nCARD-003"
}
{ "ok": true, "products": [], "shopProducts": [] }
注意:只允许修改当前商家自己的商品库存。
软删除当前商家的商品并立即从独立店铺下架。
POST https://tk7188.top/api.php?route=merchant/products/delete| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
id | integer | 是 | 商家商品 ID |
{ "id": 31 }
{ "ok": true, "products": [], "shopProducts": [] }
注意:历史订单不会随商品删除。
读取当前商家上传的私有文件。响应仅返回文件信息和兑换码末尾提示,不返回完整兑换码。
GET https://tk7188.top/api.php?route=merchant/documentsGET https://tk7188.top/api.php?route=merchant/documents
{
"documents": [
{ "id": 7, "name": "教程.pdf", "sizeBytes": 204800, "keyHint": "A1B2", "downloadCount": 0 }
]
}
注意:每个商家只能读取自己的文件。
使用 multipart/form-data 上传一个私有文件,并为该文件生成独立兑换码。
POST https://tk7188.top/api.php?route=merchant/documents/upload| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
file | file | 是 | 上传文件;受 PHP 和 MERCHANT_DOCUMENT_MAX_BYTES 限制 |
curl -X POST -H "Authorization: Bearer <sessionToken>" -F "file=@tutorial.pdf" "<BASE>/api.php?route=merchant/documents/upload"
{
"ok": true,
"document": { "id": 7, "name": "tutorial.pdf", "keyHint": "A1B2" },
"redeemKey": "DOC-0123456789ABCDEF01234567"
}
注意:完整兑换码只在上传响应中显示一次。把它添加到对应商家商品的卡密库存后再销售。
为当前商家的指定文件生成新的独立兑换码,旧兑换码立即失效。
POST https://tk7188.top/api.php?route=merchant/documents/regenerate-key| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
id | integer | 是 | 商家文档 ID |
{ "id": 7 }
{
"ok": true,
"document": { "id": 7, "keyHint": "C3D4" },
"redeemKey": "DOC-FEDCBA9876543210FEDCBA98"
}
注意:重置后需同步更新对应商品尚未售出的卡密库存。
删除当前商家的私有文件并立即使对应兑换码和下载令牌失效。
POST https://tk7188.top/api.php?route=merchant/documents/delete| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
id | integer | 是 | 商家文档 ID |
{ "id": 7 }
{ "ok": true, "documents": [] }
注意:历史订单仍保留兑换码记录,但文件删除后无法继续兑换。
保存商家独立 SMTP;action=test 时只测试连接,不覆盖现有配置。
POST https://tk7188.top/api.php?route=merchant/smtp| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
action | enum | 是 | save 或 test |
host | string | 是 | SMTP 主机 |
port | integer | 是 | 通常为 465 或 587 |
secure | string | 是 | ssl、tls 或空 |
username | string | 是 | SMTP 用户名 |
password | string | 保存时 | SMTP 授权码 |
fromEmail | string | 是 | 发件邮箱 |
{
"action": "test",
"host": "smtp.example.com",
"port": 465,
"secure": "ssl",
"username": "mail@example.com",
"password": "<SMTP授权码>",
"fromEmail": "mail@example.com"
}
{ "test": { "ok": true, "message": "连接成功" } }
注意:响应不会返回 SMTP 明文密码。
保存分站独立商户 ID、密钥、接口地址和回调地址。
POST https://tk7188.top/api.php?route=merchant/epay| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
apiUrl | url | 是 | 易支付接口地址 |
pid | string | 是 | 商户 ID |
key | string | 保存时 | 商户密钥 |
notifyUrl | url | 是 | 公网 HTTPS 回调地址 |
{
"apiUrl": "https://payment.example/",
"pid": "<商户ID>",
"key": "<商户密钥>",
"notifyUrl": "https://shop.example/api.php?route=payment/notify"
}
{ "ok": true, "epay": { "configured": true } }
注意:分站订单使用该商家配置,不使用主站易支付密钥。
商家只能回复归属自己店铺的工单并更新处理状态。
POST https://tk7188.top/api.php?route=merchant/tickets/reply| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
id | integer | 是 | 工单 ID |
content | string | 是 | 回复内容 |
status | enum | 否 | replied 或 closed |
{
"id": 18,
"content": "已核查并完成补发",
"status": "closed"
}
{ "ok": true, "ticket": {}, "tickets": [] }
仅管理员可调用,覆盖商品、分组、用户、商家、余额和系统配置。
读取管理后台所需的商品、分组、用户、订单、工单、主站文档、商家、设置和统计数据。
GET https://tk7188.top/api.php?route=admin/bootstrapGET https://tk7188.top/api.php?route=admin/bootstrap
{
"products": [],
"groups": [],
"users": [],
"orders": [],
"tickets": [],
"merchants": [],
"documents": [],
"settings": {},
"stats": {}
}
注意:数据量较大,后台首次加载使用;后续操作优先使用具体接口。
保存主站商品。主站管理员不能通过该接口编辑商家独立商品。
POST https://tk7188.top/api.php?route=admin/products| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
id | integer | 编辑时 | 主站商品 ID |
name | string | 是 | 商品名称 |
price | number | 是 | 销售价 |
description | string | 否 | 商品说明 |
category | string | 否 | 主站分组名称 |
active | boolean | 否 | 是否上架 |
{
"id": 12,
"name": "AI Plus 月卡",
"price": 39.9,
"description": "支付后自动发货",
"category": "AI服务",
"active": true
}
{ "ok": true, "products": [], "shopProducts": [] }
更新主站商品的卡密、链接和目标库存。
POST https://tk7188.top/api.php?route=admin/product-stock| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
productId | integer | 是 | 主站商品 ID |
stock | integer | 是 | 目标可售数量 |
codes | string | 否 | 逐行卡密或重复链接 |
{
"productId": 12,
"stock": 20,
"codes": "CARD-001\nCARD-002"
}
{ "ok": true, "products": [], "shopProducts": [] }
软删除主站商品、停止销售并保留历史订单。
POST https://tk7188.top/api.php?route=admin/products/delete| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
id | integer | 是 | 主站商品 ID |
{ "id": 12 }
{
"ok": true,
"products": [],
"groups": [],
"shopProducts": [],
"categories": []
}
注意:不能用该接口删除商家商品。商家商品由 merchant/products/delete 删除。
读取主站管理员上传的私有文件,不包含商家文件和完整兑换码。
GET https://tk7188.top/api.php?route=admin/documentsGET https://tk7188.top/api.php?route=admin/documents
{
"documents": [
{ "id": 4, "name": "主站教程.pdf", "sizeBytes": 409600, "keyHint": "9F2A", "downloadCount": 3 }
]
}
注意:完整兑换码不会在列表接口中重复返回。
使用 multipart/form-data 上传主站私有文件,并自动生成该文件专属的兑换码。
POST https://tk7188.top/api.php?route=admin/documents/upload| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
file | file | 是 | 上传文件;可执行文件和危险扩展名会被拒绝 |
curl -X POST -H "Authorization: Bearer <sessionToken>" -F "file=@guide.pdf" "<BASE>/api.php?route=admin/documents/upload"
{
"ok": true,
"document": { "id": 4, "name": "guide.pdf", "keyHint": "9F2A" },
"redeemKey": "DOC-0123456789ABCDEF01234567"
}
注意:兑换码只显示一次。应将它加入对应主站商品的卡密库存,用户购买后由订单自动发放。
为指定主站文件生成新的独立兑换码,并撤销旧兑换码及尚未使用的下载令牌。
POST https://tk7188.top/api.php?route=admin/documents/regenerate-key| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
id | integer | 是 | 主站文档 ID |
{ "id": 4 }
{
"ok": true,
"document": { "id": 4, "keyHint": "B7C8" },
"redeemKey": "DOC-FEDCBA9876543210FEDCBA98"
}
注意:重置后应删除商品库存中的旧兑换码并换成新兑换码。
物理删除私有文件并将文档记录标记为删除,对应兑换码立即失效。
POST https://tk7188.top/api.php?route=admin/documents/delete| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
id | integer | 是 | 主站文档 ID |
{ "id": 4 }
{ "ok": true, "documents": [] }
注意:删除前应确认没有仍需下载的已售订单。
action=save 新增/编辑分组;action=delete 删除分组并清空关联商品的分组字段。
POST https://tk7188.top/api.php?route=admin/groups| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
action | enum | 是 | save 或 delete |
id | integer | 编辑/删除 | 分组 ID |
name | string | 保存时 | 分组名称 |
sortOrder | integer | 否 | 排序值 |
{
"action": "save",
"name": "AI服务",
"sortOrder": 10
}
{ "ok": true, "groups": [] }
注意:“默认分类”名称已停用。
对普通用户执行软删除和匿名化,同时注销其全部会话。
POST https://tk7188.top/api.php?route=admin/users/delete| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
id | integer | 是 | 用户 ID |
{ "id": 8 }
{ "ok": true, "users": [] }
注意:管理员账号、余额不为 0 或仍拥有商家店铺的用户不能删除。
设置封禁截止时间和原因;封禁期间登录后会收到提示且业务功能被拒绝。
POST https://tk7188.top/api.php?route=admin/users/ban| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
id | integer | 是 | 用户 ID |
action | enum | 是 | ban 或 unban |
until | datetime | 封禁时 | ISO 时间或后台生成的截止时间 |
reason | string | 封禁时 | 封禁原因 |
{
"id": 8,
"action": "ban",
"until": "2026-08-05T12:00:00Z",
"reason": "违反平台规定"
}
{ "ok": true, "users": [] }
注意:到期后系统会自动视为解封。
按金额增加或扣减用户余额,金额在服务端以分存储。
POST https://tk7188.top/api.php?route=admin/balance| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
userId | integer | 是 | 用户 ID |
amount | number | 是 | 调整金额,单位元 |
action | enum | 是 | recharge 或 refund/扣减操作,以后台实现为准 |
note | string | 否 | 操作说明 |
{
"userId": 8,
"amount": 50,
"action": "recharge",
"note": "后台充值"
}
{ "ok": true, "users": [] }
注意:后台余额操作应记录原因并限制管理员权限。
审核入驻申请、修改商家资料或软删除店铺。审核通过时自动生成独立店铺标识。
POST https://tk7188.top/api.php?route=admin/merchants| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
id | integer | 是 | 商家 ID |
action | enum | 是 | save 或 delete |
status | enum | 保存时 | pending、active、rejected、suspended |
adminNote | string | 否 | 审核备注 |
{
"id": 3,
"action": "save",
"status": "active",
"adminNote": "资料审核通过"
}
{ "ok": true, "merchants": [] }
设置店铺封禁时间和原因;封禁后商品下架且商家后台被拒绝访问。
POST https://tk7188.top/api.php?route=admin/merchants/ban| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
id | integer | 是 | 商家 ID |
action | enum | 是 | ban 或 unban |
until | datetime | 封禁时 | 封禁截止时间 |
reason | string | 封禁时 | 封禁原因 |
{
"id": 3,
"action": "ban",
"until": "2026-08-05T12:00:00Z",
"reason": "店铺违规"
}
{ "ok": true, "merchants": [] }
保存商城名称、公告、客服信息和业务配置。
POST https://tk7188.top/api.php?route=admin/settings| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
shopName | string | 按页面 | 商城名称 |
notice | string | 否 | 首页公告 |
noticeEnabled | boolean | 否 | 是否显示公告 |
{
"shopName": "Future ai卡密小铺",
"notice": "欢迎使用自动发货商城",
"noticeEnabled": true
}
{ "ok": true, "settings": {} }
注意:具体字段以 admin/bootstrap 返回的 settings 为准。
主站 SMTP 保存和连接检测,字段与 merchant/smtp 相同。
POST https://tk7188.top/api.php?route=admin/smtp| 字段 | 类型 | 必填 | 说明 |
|---|---|---|---|
action | enum | 是 | save 或 test |
host | string | 是 | SMTP 主机 |
port | integer | 是 | SMTP 端口 |
secure | string | 是 | ssl、tls 或空 |
username | string | 是 | SMTP 用户名 |
password | string | 保存时 | SMTP 授权码 |
fromEmail | string | 是 | 发件邮箱 |
{
"action": "test",
"host": "smtp.example.com",
"port": 465,
"secure": "ssl",
"username": "mail@example.com",
"password": "<SMTP授权码>",
"fromEmail": "mail@example.com"
}
{ "test": { "ok": true } }
注意:管理员前端和 API 响应均不应回显明文授权码。
以下接口仅由主站页面调用;分站不会展示入口或提供调用权限。
| 服务 | 下单流程 | 订单查询 |
|---|---|---|
| 跨境电商服务 | 打开 panel.php,选择服务、填写目标链接与数量,创建易支付订单;支付回调成功后提交供应商。 | smm-api.php?route=order&order=本地订单号 |
| 货源采购 | 打开 wholesale.php,选择商品与规格、填写数量和支付方式;支付回调成功后使用货源余额采购。 | wholesale-api.php?route=order&order=本地订单号 |
| 发货信息 | 后台“订单管理”会显示本地单号、上游单号、联系信息和供应商实际返回的激活码、兑换码、链接或密码。上游未返回的字段保持为空。 | |
业务错误使用 JSON 返回;支付回调按易支付规范返回纯文本 success 或 fail。
| HTTP | 含义 | 常见处理方式 |
|---|---|---|
| 200 | 请求成功 | 继续读取响应中的业务字段。 |
| 400 | 参数或业务状态错误 | 显示 error 信息并检查请求字段。 |
| 401 | 未登录或会话已失效 | 清理旧会话并重新登录。 |
| 403 | 权限不足或账号/店铺被封禁 | 不要重试越权请求,向用户展示原因。 |
| 404 | 资源或接口不存在 | 检查 route、资源 ID 和部署文件版本。 |
| 409 | 用户名、邮箱或分组冲突 | 更换唯一字段后重新提交。 |
| 410 | 接口已停用 | 人工退款接口已关闭,请使用售后工单。 |
| 429 | 请求过于频繁 | 等待 cooldown 或错误信息指定的秒数。 |
| 500/503 | 存储、SMTP 或配置异常 | 检查 PHP 日志、数据目录权限和后台配置。 |