All skills
wix avatar

/wix-manage

@4895cc9 official
by Wix.comwix/skills33 stars
33

REST recipes to configure and manage a Wix site's business solutions — stores, bookings, payments, CMS, and more. Open the matching recipe for the exact endpoint, method, and payload before calling — never guess a Wix API, never write Wix dashboard URL from memory. Routes to: stores, bookings, get-paid, CMS, contacts, forms, media, app-installation, pricing-plans, restaurants, ricos rich-content, sites, blog, calendar, domains, events, site-properties, ecommerce, marketing, google-ads, google-business-profile, analytics, accessibility, seo, dashboard-navigation.

Use this Skill: https://skilld.dev/gh/wix/skills/wix-manage

This session only. Nothing lands on disk.

referencessitesmanage-oauth-apps.md

≈1.4k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Manage OAuth Apps

An OAuth app is a site-level credential holder. Its id is the client_id (the two terms are interchangeable — Wix uses appId in provisioning responses, clientId in token requests, and id in the OAuth Apps API; they all refer to the same value).

When a headless site is provisioned it gets one OAuth app automatically (see Create Headless Site); use this recipe to create additional apps, inspect existing ones, or update their redirect configuration.

client_id is not a secret — it is a public identifier safe to embed in frontend code. The visitor token it mints is also non-privileged: it represents an anonymous visitor, not an admin. The client_secret is different — shown once in the Headless Settings dashboard, never returned by the API, and rotation is dashboard-only.


Create an OAuth App

Endpoint: POST https://www.wixapis.com/oauth-app/v1/oauth-apps

curl -X POST \
  'https://www.wixapis.com/oauth-app/v1/oauth-apps' \
  -H 'Authorization: <AUTH>' \
  -H 'wix-site-id: <metaSiteId>' \
  -H 'Content-Type: application/json' \
  -d '{
    "oAuthApp": {
      "name": "My Storefront",
      "loginUrl": "https://example.com/login",
      "allowedRedirectUris": ["https://example.com/callback"],
      "allowedRedirectDomains": ["example.com"]
    }
  }'

Response:

{
  "oAuthApp": {
    "id": "<clientId>",
    "name": "My Storefront",
    "loginUrl": "https://example.com/login",
    "allowedRedirectUris": ["https://example.com/callback"],
    "allowedRedirectDomains": ["example.com"],
    "createdDate": "2026-08-18T10:00:00Z"
  }
}

id is the OAuth client_id. After creating the app, retrieve the client_secret from the Headless Settings dashboard.


Get an OAuth App

Endpoint: GET https://www.wixapis.com/oauth-app/v1/oauth-apps/{id}

curl 'https://www.wixapis.com/oauth-app/v1/oauth-apps/<clientId>' \
  -H 'Authorization: <AUTH>' \
  -H 'wix-site-id: <metaSiteId>'

Query OAuth Apps

Endpoint: POST https://www.wixapis.com/oauth-app/v1/oauth-apps/query

curl -X POST \
  'https://www.wixapis.com/oauth-app/v1/oauth-apps/query' \
  -H 'Authorization: <AUTH>' \
  -H 'wix-site-id: <metaSiteId>' \
  -H 'Content-Type: application/json' \
  -d '{ "query": {} }'

Returns all OAuth apps for the site.


Update an OAuth App

Endpoint: PATCH https://www.wixapis.com/oauth-app/v1/oauth-apps/{id}

Update requires an explicit mask.paths — omitting it silently updates nothing.

Updatable fields: name, description, loginUrl, logoutUrl, allowedRedirectUris, allowedRedirectDomains, technology.

curl -X PATCH \
  'https://www.wixapis.com/oauth-app/v1/oauth-apps/<clientId>' \
  -H 'Authorization: <AUTH>' \
  -H 'wix-site-id: <metaSiteId>' \
  -H 'Content-Type: application/json' \
  -d '{
    "oAuthApp": {
      "allowedRedirectUris": ["https://example.com/callback", "https://example.com/auth"]
    },
    "mask": { "paths": ["allowedRedirectUris"] }
  }'

Key Fields

Field Notes
id The OAuth client_id. Read-only.
name Required on create. 2–256 chars.
loginUrl External login redirect. Defaults to Wix login if omitted.
logoutUrl Called when the user logs out at Wix.
allowedRedirectUris Exact-match URIs for post-authentication redirect. Max 20.
allowedRedirectDomains Domain-level allow-list for non-auth redirects (e.g. checkout). Max 20.
applicationType WEB_APP, MOBILE, OTHER

Minting a Visitor Token

Once you have a client_id, frontends use it to mint an anonymous visitor token for buyer-facing API calls.

Endpoint: POST https://www.wixapis.com/oauth2/token

# Initial anonymous mint
curl -X POST 'https://www.wixapis.com/oauth2/token' \
  -H 'Content-Type: application/json' \
  -d '{ "clientId": "<clientId>", "grantType": "anonymous" }'

# Response: { "access_token": "...", "refresh_token": "...", "expires_in": 14400 }
# Refresh (use this instead of re-minting)
curl -X POST 'https://www.wixapis.com/oauth2/token' \
  -H 'Content-Type: application/json' \
  -d '{ "clientId": "<clientId>", "grantType": "refresh_token", "refreshToken": "<refreshToken>" }'

Use the access_token as the Authorization header on subsequent API calls.

Never re-mint anonymous on every load. The visitor token is the cart/session identity — a fresh anonymous mint creates a new visitor and silently empties the cart. Persist the refresh_token and use it to renew.


API Reference

Source: SKILL.md on GitHub

1 warning1d4 checks · Risk SAFE
  • Gen Agent Trust Hub1d

    The wix-manage skill is an extensive collection of management recipes for Wix sites, covering business solutions such as eCommerce, Bookings, SEO, and site provisioning. It utilizes official Wix REST endpoints and incorporates robust safety patterns, including mandatory user confirmation for sensitive operations and careful validation of site data before mutation.

  • Socket1d

    No alerts

  • Snyk1d

    Risk: MEDIUM · 1 issue

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 4895cc9. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated yesterday
compatibility
Requires Wix REST API access (API key or OAuth).
  • wix
  • rest-api
  • ecommerce
  • bookings
  • cms
  • contacts
  • blog
  • domains
  • restaurants
  • site-configuration
  • api-integration

README badge

README badge for wix/skills/wix-manage

REST API operations for configuring Wix business solutions including stores, bookings, CMS, contacts, domains, and ecommerce. Routes to site setup, entity management (products, services, staff), bulk administrative operations, and server-to-server integrations across Wix's business app ecosystem.

Generated from the current SKILL.md.

Do I need API credentials to use these recipes?
Yes. The skill requires Wix REST API access via either an API key or OAuth token to execute any management operations.
Can I use these recipes to display data on my site frontend?
No. These recipes are for backend REST API operations only — site configuration, entity management, and administrative tasks. They do not cover frontend development or displaying data to users.
What business domains do these recipes cover?
The skill covers stores, bookings, payments, CMS, contacts, forms, media, apps, pricing plans, restaurants, rich content, sites, blogs, calendars, domains, and site properties.
Do these recipes handle OAuth authentication with external services like Google Calendar?
Yes. The external calendar integration recipe covers OAuth-based setup with Google Calendar, Microsoft Outlook, and Apple Calendar for bidirectional event sync.

Generated from the current SKILL.md. These answers refresh after source changes.