The developer username is not a login — it is a signature
The Hepsiburada setup asks for three values, and the third one confuses people: the integration developer username. It is not a login credential — it travels in the User-Agent header of every request, and that is how the platform reads which integrator the request came from. When it is wrong the error usually mentions authorisation; people start checking the password, while the actual problem is the signature.
The store ID is a UUID — a long mix of letters and digits, not the short number you might expect from Trendyol. The service key is used as the Basic Auth password. All three sit on the same screen in the seller panel, under account → integration information.
What happens if you leave the optional webhook fields empty?
The setup screen has three more optional fields: a webhook token, a webhook username and a password. They exist so incoming order and claim notifications can be verified. Leave them empty and the connection still works — verification then falls back to the merchant identifier inside the payload. Fill them in and every notification passes an additional identity check.
One more point to set expectations: you can push your issued invoice to Hepsiburada, but the shipping label PDF does not come through this connection — the label side runs through the carrier's own integration. Product matching also works by stock code only; there is no barcode matching on this platform, which makes consistent stock codes more critical here than elsewhere.
Connecting to the Hepsiburada API: what comes from where
Connecting to the Hepsiburada API takes three values, and all three sit on the same screen in the seller panel under account settings and integration information: the store ID, the developer username and the service key. You do not register on a separate developer portal, create an application or wait for approval — that is where it differs from Amazon and eBay.
Authentication is Basic Auth: the store ID acts as the username and the service key as the password. The developer username is not a credential but a signature carried in the User-Agent header of every request. With those three set correctly, order retrieval, stock and price updates, returns and customer questions all flow over a single connection.
For a developer considering writing their own integration, the real cost is not the first connection but everything after it: rate limits, pagination, order status transitions, the returns flow, and keeping up when the API version changes. Stokzone provides that layer ready-made, so you think about your own product rather than Hepsiburada's rules.