Magento 2 REST/GraphQL API Configuration
Typical scenario: your CRM needs to push stock updates, but the standard /V1/products returns too many fields. Or your PWA frontend slows down due to N+1 queries to categories. We solve these tasks: configure authentication, write custom endpoints, implement GraphQL. The whole cycle — from analysis to deployment — takes 5 to 15 days. Experience shows that proper API configuration reduces integration time by 2–3 times.
Problems that API configuration solves
Authentication and security. A common mistake is misconfigured OAuth integration that returns 401. We set access permissions (Resource Access) so that each endpoint is accessible strictly by role. For internal services, we use token-based (Bearer) — simpler and faster. Debugging time saved — up to 2 days. Security is confirmed by regular audits.
REST performance. Without caching, bulk operations (e.g., updating 10,000 products) cause timeouts. Solution — Async REST API (POST /async/V1/products) and Varnish frontend. For public endpoints, we set up Nginx caching. As a result, TTFB drops by 3–5 times. On one project, this reduced server load by 40%.
GraphQL N+1. When requesting products with categories without DataLoader, each item spawns a separate SQL query. We use batch resolvers and aggregate the selection. GraphQL in this scenario is 2–3 times faster than REST in response size. Traffic savings up to 40%. For PWA frontends this is especially critical — pages load in 1–2 seconds.
Why choose a custom endpoint?
Standard endpoints do not cover business specifics. Example: you need to return view statistics and stock data in one response. We implement an interface:
interface ProductStatsInterface { public function getStats(string $sku): array; } In the class, we inject ProductRepositoryInterface and StockRegistryInterface. We return price, quantity, stock status. The route is configured in etc/webapi.xml. One endpoint instead of two — less traffic and faster development.
How to configure authentication for external services?
For external services (CRM, ERP), we use OAuth 1.0a. An integration is created in the admin panel, generating Consumer Key/Secret and Access Token/Secret. Each request is signed, providing high security. For internal integrations, token-based is sufficient: POST /V1/integration/admin/token returns a token valid for 1 hour. If longer is needed, we configure refresh tokens.
Process
- Analysis — identify bottlenecks: slow queries, redundant data, wrong roles.
- Design — choose protocol (REST/GraphQL), design endpoint schema, write tests.
- Implementation — write modules, configure ACL, optimize queries. For bulk operations — Async API with RabbitMQ.
- Testing — load tests with JMeter, check Core Web Vitals (LCP, TTFB). Ensure API handles 1000 RPS.
- Deployment — deploy with Varnish and Redis, deliver Postman collection and GraphQL schema, train the team.
How to avoid rate limiting during bulk operations?
For integrations with large volume (e.g., loading 10,000 products), we use Bulky API: send a request to /async/V1/products with an array of products. Magento processes them asynchronously, without blocking the thread. If feedback is needed, we subscribe to the product_action_notification queue. This bypasses limits and maintains performance. This solution has been proven on projects with 50,000+ products.
REST vs GraphQL Comparison
| Feature | REST API | GraphQL API |
|---|---|---|
| Response size | Redundant (all fields) | Minimal (only requested) |
| Number of requests | Many (N+1) | Single request for everything |
| Caching | Varnish, Nginx | Persisted Queries, CDN |
| Development complexity | Low | Medium |
Authentication Methods Comparison
| Method | When to use | Setup complexity | Security |
|---|---|---|---|
| Token-based (Bearer) | Internal integrations, mobile apps | Low | Medium (token lasts 1 hour) |
| OAuth 1.0a | External services (CRM, ERP) | High | High (request signature) |
What's included
- Authentication configuration (Token/OAuth) and ACL.
- Development of custom REST/GraphQL endpoints for business logic.
- Performance optimization: caching, async queues, DataLoader.
- API documentation (Postman, GraphQL schema) and team training.
- Compatibility guarantee with latest Magento versions and PHP 8.2+.
- Post-deployment support: monitoring, rate-limiting fixes, enhancements.
Estimated timeline: 5 to 15 days. Cost is calculated individually after project analysis. We have been working with Magento for over 8 years and have participated in 30+ integrations. Leave a request — we'll evaluate your project in 1 day. Contact us for a consultation — our engineers will help you choose an integration method and optimize your API. Order Magento 2 API configuration — we guarantee performance and security.
OAuth Configuration Example
In Magento Admin: Stores → Configuration → Services → OAuth. Specify Consumer Key and Consumer Secret, generate Access Token. Example signed request: GET /rest/V1/products?oauth_consumer_key=...&oauth_signature=....







