BigCommerce
Purpose
Orders, catalog, and customers.
Authentication
Client id, secret, and access token.
Webhooks and callbacks
OAuth-style routes are @PublicRoute: /integrations/bigcommerce/auth, /load, /uninstall. remove-user was observed as JWT, not public. Link and preview routes are JWT.
There is no dedicated flush job name. Inventory falls through flush-channel:DEFAULT.
Code
src/integrations/bigcommerce.
Failure
Shared sync circuit breaker. Callback signature rules were not re-read for this page. Treat the public routes as unauthenticated at the JWT layer and read the controller for payload verification before you change them.