npx skills add ...
npx skills add bagisto/agent-skills --skill bagisto-api-admin
Use when building an admin app or UI on the Bagisto Admin API — a back-office dashboard, an order, catalog, customer, marketing, CMS or settings management screen, an admin mobile app, the Create-Order flow, or any admin panel page on the API. Ask the client's platform and stack first, and treat the api-docs as the source of truth for exact shapes. Trigger phrases include "admin orders", "admin products", "customers", "cart rules", "CMS", "settings", "reporting", "admin panel on the API".
npx skills add bagisto/agent-skills --skill bagisto-api-admin
Implement any admin/back-office interface on the Bagisto Admin API (/api/admin/* REST + POST /api/admin/graphql). The API mirrors the Bagisto admin panel menu-for-menu, so any admin screen can be rebuilt from it. This skill is a router: it gives the flow and points you at the per-menu reference page; the reference pages carry the endpoints, UI/UX, and checklists.
reference/connecting-to-the-api.md — admin auth (the Integration Bearer token), the {data,meta} listing envelope, the list→detail→action pattern, permissions, errors, and the verify-before-coding protocol.reference/graphql.md — if the client picked GraphQL: the admin endpoint, the result-field/id rule, camelCase inputs + filter args, cursor pagination.The api-docs are the source of truth for exact shapes — https://api-docs.bagisto.com (Admin API section) + its /llms.txt index. The reference pages name the endpoints and flow; open the linked docs page for the precise body/response before writing the call. Never invent a payload from memory.
Confirm, then tailor everything to the answers. Don't assume a stack.
Almost every admin screen is the same shape (detailed in connecting-to-the-api.md):
GET /api/admin/<resource> → { data, meta } envelope; drive tables with ?page= + ?per_page= + the screen's filters.GET /api/admin/<resource>/{id} → full record, relations embedded (no follow-up calls).POST/PUT/DELETE for create/update/delete + per-record actions (cancel order, create invoice, mass-update, …), each with its own eligibility rules.| Page | Build this |
|---|---|
reference/flows/create-order.md | The admin Create-Order flow (place an order for a customer via a draft cart) |
| Page | Covers |
|---|---|
reference/menus/sales.md | Orders (list/detail + cancel/comment/invoice/shipment/refund), Invoices, Shipments, Refunds, Transactions, Bookings, CSV exports |
reference/menus/catalog.md | Products (datagrid + CRUD + images/inventory/customer-group-prices + mass actions), Categories (+tree), Attributes (+options), Attribute Families |
reference/menus/customers.md | Customers (CRUD + addresses/notes/impersonate), Groups, Reviews, GDPR |
reference/menus/marketing.md | Cart Rules (+coupons), Catalog Rules, Email Templates, Events, Campaigns, Subscribers, Search Terms/Synonyms, URL Rewrites, Sitemaps |
reference/menus/cms.md | CMS Pages |
reference/menus/settings.md | Currencies, Channels, Locales, Exchange Rates, Inventory Sources, Tax Rates/Categories, Roles, Users, Themes, Data-Transfer Imports |
reference/menus/configuration.md | Store configuration (schema / values / update) |
reference/menus/dashboard-reporting.md | Dashboard stats + Reporting (sales/customers/products + export) |
Two read-only endpoints (REST + GraphQL) tell you what the current token can do — drive navigation and action-gating from them instead of hardcoding:
GET /api/admin/menu (getAdminMenu) — the admin sidebar as a permission-filtered tree; each node maps to its API endpoint (apiResource: { rest, graphql }, or null for group headers / panel-only screens).GET /api/admin/permissions (getAdminPermissions) — the token's effective { permissionType, permissions } (["*"] = full access).Details in reference/connecting-to-the-api.md.
Authorization: Bearer <id>|<token> (a pre-issued admin Integration token). There's no login endpoint — the token is made in the store's admin panel. The admin GraphQL endpoint is POST /api/admin/graphql (admin token only; not the shop endpoint, no storefront key).{ data, meta } (+ X-Total-* headers); page with ?page=/?per_page= (default 10, cap 50) + the per-screen filters.id; inputs are camelCase; custom filter args are documented per page. See reference/graphql.md.