Important notice – GATO Supplier API
Dear business customer,
GATO has updated the policy and terms of use for the GATO International Supplier API.
The API is only for authorised business customers and partners. It is used to retrieve product, stock and price information, and to place and manage that partner's own orders.
From 1 November 2026, the updated GATO Supplier API Policy & Terms of Use apply to every business user of the API.
Please pay particular attention to the following:
- API keys and JWT tokens are strictly confidential and must not be shared with third parties.
- API keys must not be stored in source code, public repositories or publicly reachable applications.
- Passing an API key in a URL, such as
?api_key=..., is not allowed. Use theX-API-Keyheader, or a Bearer token. - Partners are responsible for securing their API credentials and systems.
- Product, stock and price data may be used only for the business relationship with GATO.
- GATO sets the applicable prices and stock availability. Partners cannot set their own prices or stock through the API.
- Orders can be placed only for the registered business partner and are subject to the API rules then in force.
- If an API key may have leaked, or if there is unauthorised access or another security incident, tell GATO as soon as possible at it@gatosports.com.
- Use of the API is subject to applicable law, including European privacy and data-protection law.
If you keep using the GATO Supplier API after 1 November 2026, that use is governed by the API Policy & Terms of Use then in force, to the extent permitted by law and without affecting any additional written agreement between GATO and the partner.
1. Who may use the API
The API is not a public service. Only a partner account that GATO has created and left active may use it. The account is linked to one business customer and one customer group. That group determines the net prices. A partner can see only its own orders.
2. Access and confidentiality
An API key has the form gsa_…. The secret is shown once. GATO stores only a hash. A JWT access token lasts one hour. GATO cannot revoke a token before it expires: a token that has been issued stays valid until then. If a key is lost, suspected of misuse, or held by someone who has left, rotate it immediately. Rotation disables the previous secret at once.
A valid key can read the catalogue, stock, prices and changes, and can place and cancel that partner's orders. The scopes listed on a token do not currently limit that access.
If the partner account has an IP allowlist, other addresses are refused. Without an allowlist, any address with a valid key is accepted. Traffic must use HTTPS.
3. Permitted use of data
Catalogue, stock and price data belong to GATO. They may be used to order, to plan the partner's own purchasing, and to maintain the integration with GATO. They may not be resold, published, or used to build a competing catalogue. Prices returned by the API are the prices GATO applies. A partner cannot submit its own unit price. Stock shown by the API can be up to about a minute behind. An order checks stock at the moment it is placed. If there is not enough stock, the whole order is refused.
4. Orders
- At most 100 lines per order, and 1 to 9999 units per line.
- Each line refers to an active product by product id or EAN, and to a variant where needed.
- The partner's purchase-order number cannot be reused.
- Shipping charged through the API is zero. Amounts are in euro.
- An accepted order is created in GATO's shop and stock is deducted.
- Cancellation is possible only while the API status is accepted or processing. Stock is then restored.
- There is no webhook. The partner polls for status changes.
5. Limits and logging
The default limit is 60 requests per minute and 1,000 per hour, unless GATO has set a different limit for that partner. Excess requests are refused. GATO keeps API requests and responses, including order contents, for 90 days for security and support. The key itself must not appear in a URL or in a support ticket.
6. Documentation
7. Contact
Gato-International B.V.
Jan van Geunsweg 7
2031 BD Haarlem
Chamber of Commerce 34297677
General: office@gato-international.com
API and security incidents: it@gatosports.com
Phone: +31 (0)23 57 62 891
gatosports.com