Skip to content
Zid partners
Developer programsAn overview of every way to build on ZidApp PartnersPublish your app in the Zid App MarketTheme PartnersLaunch your theme in the Zid Theme Market
App MarketApps available to Zid merchantsTheme MarketThemes ready to install
Support
Partner help centreHow-to guides and troubleshootingDeveloper docsAPIs, SDKs and integration guidesBook a meetingA business or technical support call
What's new
BlogGuides and updates for developersChangelogThe latest partner platform updatesSuggest a featureThe feedback and ideas board
Partner enablement
Partner AdsVisibility packages on Zid’s channelsCustom themesThemes built for one merchantPartner communityConnect with developers building on Zid
Zid library
Zid reportsEverything you need to know about the marketDeveloper guidesOfficial references to build on
العربيةLog inJoin as a partner
Partner programs
Developer programsApp PartnersTheme Partners
Browse the market
App MarketTheme Market
Support & enablement
Partner help centreDeveloper docsBook a meetingBlogChangelogSuggest a featurePartner AdsCustom themesPartner communityZid reportsDeveloper guides
Language
العربية
Log inJoin as a partner
Home/Blog/Developer updates
Developer updates

The Account API: moving off GET v1/managers/profile

Zid is retiring GET v1/managers/profile, with migration due 30 September 2026. Here are the new Account API endpoints, their scopes and a migration checklist.

Sep 30, 20265 min read

What's changing and when

On 16 June 2026, Zid announced on the partner changelog that the GET v1/managers/profile endpoint is being retired, with migration due 30 September 2026. After that date the endpoint is no longer available, so any app that still calls it needs to move by then.

It's replaced by the Account API: a set of smaller endpoints, each tied to its own OAuth scope. Zid's stated goal is more granular access control, in line with security best practices. Instead of one call that returns everything, your app asks only for the data it needs, and the merchant approves only the scopes that data requires.

The same deadline applies to a second change: Basic Authentication becomes mandatory for webhooks. If you're updating your integration anyway, check both.

The new endpoints and their scopes

In the docs, the endpoints sit under Merchant APIs > Account. The ones below are all GET requests on https://api.zid.sa/:

  • Account Identity: /v1/managers/account/me returns the signed-in user's basic identity: id, UUID, name, email, mobile, gender, preferred language and creation date. Scope: third_account_identity_read.
  • Store Details: /v1/managers/account/store returns the store's id, UUID, title, phone, email, URL and timezone. Scope: third_store_details_read.
  • Store Branding: /v1/managers/account/store/branding returns the active theme, logos, cover image, icon and button colors. Scope: third_store_details_read.
  • Store Localization: /v1/managers/account/store/localization returns supported and active languages (with text direction) and currencies, including the default currency. Scope: third_store_details_read.
  • Store Social: /v1/managers/account/store/social returns the store's social media handles. Scope: third_store_details_read.
  • Store Operations: /v1/managers/account/store/operations returns operational settings such as maintenance mode, active customer login methods, mobile app availability and store availability. Scope: third_store_details_read.
  • Store Business: /v1/managers/account/store/business returns KYC details, including Commercial Registration (CR) information and business data. Scope on the docs page: third_store_business_read.

The changelog also lists an Account Profile endpoint, with scope third_account_profile_read, for extended data such as birthdate, job title and geographical information.

Before and after

The docs mark both Authorization and X-Manager-Token as required on every Account API endpoint. Accept-Language is optional, accepts en or ar, and defaults to en.

# Before: being retired (migration due 30 September 2026)
GET v1/managers/profile

# After: Account Identity (scope: third_account_identity_read)
GET https://api.zid.sa/v1/managers/account/me
Authorization: Bearer {{authorization}}
X-Manager-Token: {{access_token}}
Accept-Language: en

A successful /me response wraps the user in a user object (personal values shortened here):

{
  "status": "object",
  "user": {
    "id": 1,
    "uuid": "e5616699-6f91-4e84-a655-19f1ecb4b166",
    "name": "...",
    "email": "...",
    "mobile": "966500000005",
    "mobile_object": { "country_code": "966", "mobile": "500000005" },
    "gender": "f",
    "preferred_language": "ar",
    "created_at": "2019-07-28 22:26:53"
  },
  "message": { "type": "object", "code": null, "name": null, "description": null }
}

Store endpoints follow the same pattern, with the data under a key named after the endpoint: store, branding, localization, social, operations or business.

A migration checklist

  1. Find every call. Search your codebase, background jobs and scripts for v1/managers/profile.
  2. List the fields you actually use. For each call, note which values your app reads: the manager's name and email, the store URL, the currency, the logo, and so on.
  3. Map fields to endpoints. Use the list above, and call only the endpoints whose fields your app reads.
  4. Select the scopes in the Partner Dashboard. Scopes are chosen on your app's page in the Partner Dashboard. Add only the scopes behind the endpoints you call.
  5. Update and test. Replace the calls, then run the full install flow on a development store and confirm every field your app relies on comes back as expected.
  6. Remove the old call. Once nothing depends on v1/managers/profile, delete it so it doesn't fail later.
curl -X GET 'https://api.zid.sa/v1/managers/account/store' \
  --header 'Authorization: Bearer {{authorization}}' \
  --header 'X-Manager-Token: {{access_token}}' \
  --header 'Accept-Language: ar'

Details to double-check

  • Business scope. The changelog lists third_store_details_read for Store Business, but the Business page in the docs lists third_store_business_read. Go by the docs page when you set scopes, and test the call before you rely on it.
  • Account Profile page. At the time of writing, the docs link for Account Profile in the changelog doesn't open, and the Account section of the docs lists Me and the store endpoints. If your app needs birthdate, job title or geographical data, check the docs for the current page first.
  • 401 and 403 responses. Every Account API page documents both. A good practice is to log the response body and check that the matching scope is enabled before you retry.

Key takeaways

  • GET v1/managers/profile is being retired. Migration is due 30 September 2026, and after that date the endpoint is no longer available.
  • The Account API splits the data into /v1/managers/account/me plus six store endpoints, each tied to a specific OAuth scope.
  • Map the fields your app actually uses to endpoints, and select only the matching scopes in the Partner Dashboard.
  • For Store Business, the docs page lists third_store_business_read, not the scope given in the changelog. Confirm on the docs page before you ship.
  • Test the full install flow on a development store before you remove the old call.

Sources

  1. [Docs Update - Apps] Action Required: Upcoming API Changes by September 30, 2026
  2. [Docs Update - Apps] Action Required: Webhook Security Changes by September 30, 2026
  3. Me - Zid Docs
  4. Store - Zid Docs
  5. Branding - Zid Docs
  6. Localization - Zid Docs
  7. Social - Zid Docs
  8. Operations - Zid Docs
  9. Business - Zid Docs
  10. Authorization - Zid Docs

Start building on Zid

Sign up in the partner portal, then build and test on a development store.

Create your account →

Contents

  1. What's changing and when
  2. The new endpoints and their scopes
  3. Before and after
  4. A migration checklist
  5. Details to double-check

Share

Start building

Related articles

→
Developer updates

Developer updates roundup: what's new on Zid for partners

New Wallet and Blogs APIs, webhook health tracking, a Sept 30 deadline for profile and webhook changes, more pricing plans, and new AI tools for building on Zid.

5 min read
APIs & integration

Embedded apps on Zid: build inside the merchant dashboard

How embedded apps load inside the Zid merchant dashboard, the six-step auth flow, and the tools that help: Zid MUI, the Zid SDKs and storefront events.

6 min read
APIs & integration

Webhooks on Zid: subscribe, monitor health and recover broken endpoints

Subscribe to store events, keep your endpoints healthy, and bring a broken webhook back to life with Zid's health tracking and recovery APIs.

4 min read
Zid Partners

Partner programs

Developer programsApp PartnersTheme PartnersCreate your account

Resources

BlogPartner AdsZid reportsDeveloper docsPartner help centerChangelogRequest a feature

Browse the market

App MarketTheme Market

Terms & policies

App Partner termsTheme Partner termsTheme commercial policyPrivacy policy

Get in touch

Book a business callBook a technical support callTheme designers community
Zid — Al-Qudrah Al-Taqniyah for Technology and Communicationالعربية
Al-Qudrah Al-Taqniyah for Technology and Communication CompanyCR No. 1010365366VAT No. 300827827900003