
The Account API: moving off GET v1/managers/profile
Zid is retiring GET v1/managers/profile, with migration due 30 September 2026. Here are the new Account API endpoints, their scopes and a migration checklist.
What's changing and when
On 16 June 2026, Zid announced on the partner changelog that the GET v1/managers/profile endpoint is being retired, with migration due 30 September 2026. After that date the endpoint is no longer available, so any app that still calls it needs to move by then.
It's replaced by the Account API: a set of smaller endpoints, each tied to its own OAuth scope. Zid's stated goal is more granular access control, in line with security best practices. Instead of one call that returns everything, your app asks only for the data it needs, and the merchant approves only the scopes that data requires.
The new endpoints and their scopes
In the docs, the endpoints sit under Merchant APIs > Account. The ones below are all GET requests on https://api.zid.sa/:
- Account Identity:
/v1/managers/account/mereturns the signed-in user's basic identity: id, UUID, name, email, mobile, gender, preferred language and creation date. Scope:third_account_identity_read. - Store Details:
/v1/managers/account/storereturns the store's id, UUID, title, phone, email, URL and timezone. Scope:third_store_details_read. - Store Branding:
/v1/managers/account/store/brandingreturns the active theme, logos, cover image, icon and button colors. Scope:third_store_details_read. - Store Localization:
/v1/managers/account/store/localizationreturns supported and active languages (with text direction) and currencies, including the default currency. Scope:third_store_details_read. - Store Social:
/v1/managers/account/store/socialreturns the store's social media handles. Scope:third_store_details_read. - Store Operations:
/v1/managers/account/store/operationsreturns operational settings such as maintenance mode, active customer login methods, mobile app availability and store availability. Scope:third_store_details_read. - Store Business:
/v1/managers/account/store/businessreturns KYC details, including Commercial Registration (CR) information and business data. Scope on the docs page:third_store_business_read.
The changelog also lists an Account Profile endpoint, with scope third_account_profile_read, for extended data such as birthdate, job title and geographical information.
Before and after
The docs mark both Authorization and X-Manager-Token as required on every Account API endpoint. Accept-Language is optional, accepts en or ar, and defaults to en.
# Before: being retired (migration due 30 September 2026)
GET v1/managers/profile
# After: Account Identity (scope: third_account_identity_read)
GET https://api.zid.sa/v1/managers/account/me
Authorization: Bearer {{authorization}}
X-Manager-Token: {{access_token}}
Accept-Language: enA successful /me response wraps the user in a user object (personal values shortened here):
{
"status": "object",
"user": {
"id": 1,
"uuid": "e5616699-6f91-4e84-a655-19f1ecb4b166",
"name": "...",
"email": "...",
"mobile": "966500000005",
"mobile_object": { "country_code": "966", "mobile": "500000005" },
"gender": "f",
"preferred_language": "ar",
"created_at": "2019-07-28 22:26:53"
},
"message": { "type": "object", "code": null, "name": null, "description": null }
}Store endpoints follow the same pattern, with the data under a key named after the endpoint: store, branding, localization, social, operations or business.
A migration checklist
- Find every call. Search your codebase, background jobs and scripts for
v1/managers/profile. - List the fields you actually use. For each call, note which values your app reads: the manager's name and email, the store URL, the currency, the logo, and so on.
- Map fields to endpoints. Use the list above, and call only the endpoints whose fields your app reads.
- Select the scopes in the Partner Dashboard. Scopes are chosen on your app's page in the Partner Dashboard. Add only the scopes behind the endpoints you call.
- Update and test. Replace the calls, then run the full install flow on a development store and confirm every field your app relies on comes back as expected.
- Remove the old call. Once nothing depends on
v1/managers/profile, delete it so it doesn't fail later.
curl -X GET 'https://api.zid.sa/v1/managers/account/store' \
--header 'Authorization: Bearer {{authorization}}' \
--header 'X-Manager-Token: {{access_token}}' \
--header 'Accept-Language: ar'Details to double-check
- Business scope. The changelog lists
third_store_details_readfor Store Business, but the Business page in the docs liststhird_store_business_read. Go by the docs page when you set scopes, and test the call before you rely on it. - Account Profile page. At the time of writing, the docs link for Account Profile in the changelog doesn't open, and the Account section of the docs lists Me and the store endpoints. If your app needs birthdate, job title or geographical data, check the docs for the current page first.
- 401 and 403 responses. Every Account API page documents both. A good practice is to log the response body and check that the matching scope is enabled before you retry.
Key takeaways
GET v1/managers/profileis being retired. Migration is due 30 September 2026, and after that date the endpoint is no longer available.- The Account API splits the data into
/v1/managers/account/meplus six store endpoints, each tied to a specific OAuth scope. - Map the fields your app actually uses to endpoints, and select only the matching scopes in the Partner Dashboard.
- For Store Business, the docs page lists
third_store_business_read, not the scope given in the changelog. Confirm on the docs page before you ship. - Test the full install flow on a development store before you remove the old call.
Sources
- [Docs Update - Apps] Action Required: Upcoming API Changes by September 30, 2026
- [Docs Update - Apps] Action Required: Webhook Security Changes by September 30, 2026
- Me - Zid Docs
- Store - Zid Docs
- Branding - Zid Docs
- Localization - Zid Docs
- Social - Zid Docs
- Operations - Zid Docs
- Business - Zid Docs
- Authorization - Zid Docs
Start building on Zid
Sign up in the partner portal, then build and test on a development store.


