# X-Cart SvelteKit Storefront — Svelte Commerce Connector

> Svelte Commerce on X-Cart 5.5.1+: 26 of 43 services wired, with cart, checkout and sign-in; vendors are the gap. Setup, API key, environment and fixes.

- Canonical: https://kitcommerce.store/svelte-commerce/backends/x-cart/
- Last updated: 2026-09-25

---

Svelte Commerce × X-Cart

## Svelte Commerce on X-Cart

Solid core coverage: cart, checkout and sign-in are wired against X-Cart’s modern API, and the one recorded gap is vendors. Every call carries the store’s API key; a shopper’s token joins it after sign-in.

- **26/43** services wired
- **@misiki/x-cart-connector** 0.5.0
- **Cart** wired
- **Checkout** wired
- **Sign-in (auth)** wired

### What works on X-Cart today

Cart, checkout and sign-in are wired; vendors are the one recorded gap. Cart and checkout need X-Cart’s read/write API key, and the connector takes it from a `PUBLIC_` variable, which the browser receives.

#### Cart

Wired: issues a real request to X-Cart.

#### Checkout

Wired: issues a real request to X-Cart.

#### Sign-in (auth)

Wired: issues a real request to X-Cart.

**Known gaps:** `vendor` — each is explained under Limitations below.

26 of 43 services wired, read from [CONNECTORS.md](https://github.com/itswadesh/svelte-commerce/blob/main/docs/CONNECTORS.md) on 21 September 2026, where the package version is recorded too; npm may carry a newer patch. Coverage is traced by a script in the Svelte Commerce repository: a service counts as wired only if it transitively issues an HTTP request, or delegates to one that does. It is not hand-asserted. Some services are Litekart-native concepts with no equivalent elsewhere (reels, deals, chat, gallery, popularity, demo-request, feedback, plugins, banner). They stay documented placeholders on every connector and are excluded from known gaps.

### Quick start

From nothing to a Svelte Commerce storefront reading X-Cart. You need Node.js and a X-Cart to point it at; the storefront holds no data of its own.

Clone it, choose the connector, point it at X-Cart

```
# 1 — get the storefront
git clone https://github.com/itswadesh/svelte-commerce
cd svelte-commerce

# 2 — one connector at a time: remove the two the storefront ships with, add this one
npm uninstall @misiki/litekart-connector @misiki/vendure-connector
npm i @misiki/x-cart-connector

# 3 — point it at your X-Cart store
echo PUBLIC_X_CART_API_URL=https://your-store.example.com >> .env
echo PUBLIC_X_CART_API_KEY=... >> .env

# 4 — run it
npm run dev
```

The guide removes only `@misiki/litekart-connector`. A fresh clone’s `package.json` also lists `@misiki/vendure-connector`, and with two connectors installed and neither of them Litekart’s, the build stops and asks for `PUBLIC_CONNECTOR` — so this removes both.

### Environment variables

*What Svelte Commerce reads to reach X-Cart*

| Variable | Required | What it does |
| --- | --- | --- |
| `PUBLIC_X_CART_API_URL` | Yes | Your X-Cart store’s URL. Boot fails, naming this variable, if it is missing. |
| `PUBLIC_X_CART_API_KEY` | No | The store API key from X-Cart’s Settings › API, sent as `X-Auth-Token` on every call. A read-only key rejects writes, so cart and checkout need the read/write key. See the limitations. |
| `PUBLIC_X_CART_ACCESS_TOKEN` | No | Sent as a bearer token when set; a shopper’s token after sign-in travels the same way. |
| `PUBLIC_CONNECTOR` | No | Only when more than one connector is installed: `@misiki/x-cart-connector` names the one this build runs on. |

`init.ts` hands the connector every `PUBLIC_X_CART_*` variable that is set, camel-cased. The guide also lists `PUBLIC_X_CART_API_SECRET`, `PUBLIC_X_CART_ACCESS_KEY`, `PUBLIC_X_CART_STORE_ID` and `PUBLIC_X_CART_CHANNEL_ID`; the connector’s source does not read them.

Every variable here begins `PUBLIC_`, and SvelteKit sends `PUBLIC_` variables to the browser: treat each value you set as published.

### What to set up on X-Cart

- Run X-Cart 5.5.1 or later. The connector follows the modern API; the `_key` query parameter of the 5.3/5.4 admin API does not exist there and is not used.
- Create the API key under Settings › API — the read/write one, because a read-only key rejects every cart and checkout write.
- Let the storefront’s origin make cross-origin requests to X-Cart (CORS): in production the browser calls `PUBLIC_X_CART_API_URL` directly, not only the server.

### How the integration works

X-Cart 5.5.1 and later want two headers: `X-Auth-Token`, the store API key, on every call, and `Authorization: Bearer`, the shopper’s token, once they have signed in. A read-only key is enough to browse but rejects every POST, PATCH and DELETE.

Installing the package is the whole switch. `vite.config.ts` resolves whichever `@misiki/*-connector` is installed, and `src/lib/core/connectors/init.ts` hands it every `PUBLIC_X_CART_*` variable that is set, camel-cased, at boot — in the server hook for server rendering and in the client hook for the browser, which must reach the same URL in production.

There is no Litekart API behind the storefront here, so store identity — name, logo, currency, menus, plugin toggles, theme colours — comes from `src/lib/core/connectors/default-store.json` merged under the default export of `kitcommerce.config.ts`. Until you override it, the store is called “Test”. Any Litekart REST path the connector still inherits is answered from that local data, or resolved empty, rather than requested.

### Limitations

- Vendors: not wired.
- Pages that depend on a service that is not wired render their empty state rather than failing.
- The store API key, sent as `X-Auth-Token`, comes from `PUBLIC_X_CART_API_KEY` — and cart and checkout need the read/write key. SvelteKit sends `PUBLIC_` variables to the browser, so every visitor to the store can read it.
- Homepage sections other than the live product list come from the active theme’s static content — the standing rule for themes.
- The Conversational Shopping assistant is Litekart-only; its widget stays hidden when another connector is active.

### Troubleshooting

*Errors you may meet running Svelte Commerce on X-Cart, and what fixes them*

| When you see | What to do |
| --- | --- |
| Boot fails with “the x-cart connector is active but PUBLIC_X_CART_API_URL is not set” | Add `PUBLIC_X_CART_API_URL` to `.env`. A production Node build and Docker read `PUBLIC_*` from the process environment rather than `.env`, so set it on your deploy platform too. |
| The build stops with “Several commerce connectors are installed … Set PUBLIC_CONNECTOR to pick one” | More than one `@misiki/*-connector` is in `package.json` and none is Litekart’s. Uninstall the ones you do not run — a fresh clone also lists `@misiki/vendure-connector` — or set `PUBLIC_CONNECTOR='@misiki/x-cart-connector'`. |
| Boot fails with “PUBLIC\_…\_API_URL is set, but it configures a different backend than the one this build runs on” | Another backend’s variable is still set, usually left over from the one you switched from. Remove it, or install that backend’s connector. `PUBLIC_LITEKART_API_URL` is exempt: it only points the dev proxy. |
| The store is called “Test”, or shows the wrong name and logo | Store identity is static on this backend. Set `name`, `logo`, `currencyCode` and the rest in the default export of `kitcommerce.config.ts`; `src/lib/core/connectors/default-store.json` lists every field. |
| `[x-cart] no native implementation for get /api/...` in the console | The connector’s REST guard caught a path inherited from Litekart and answered it empty instead of requesting it. Each path is reported once. Harmless if X-Cart has no such feature; if it has one, the fix belongs in the connector’s matching service. |
| `http proxy error: api/... ECONNREFUSED` in dev | A Litekart REST path was requested from outside the connector, so its guard never saw it. Vite proxies `/api` to `PUBLIC_LITEKART_API_URL`, or to `localhost:7000`. |
| The build fails on `@misiki/litekart-connector` | `@misiki/kitcommerce-core` declares it as a peer, and `vite.config.ts` redirects that specifier to whichever connector is installed. Make sure exactly one `@misiki/*-connector` is listed in `package.json`. |

### Before you rely on it

#### The one caveat that matters

Read this before choosing

Every connector was written by reading its platform’s authoritative source — an OpenAPI spec, a RAML file, a router registration or the controller source — rather than by running against a store. **No connector has been exercised against a live production instance of its platform.**

[Offer a sandbox or a correction](https://github.com/itswadesh/svelte-commerce/discussions/new/choose)

FAQ

### Questions about Svelte Commerce on X-Cart

**Can I run an X-Cart store on Svelte Commerce today?**

Cart, checkout and sign-in are wired, and vendors are the only recorded gap. The obstacle is the key: cart and checkout need X-Cart’s read/write API key, which the connector reads from a PUBLIC\_ variable that every visitor’s browser receives.

**How do I switch Svelte Commerce to X-Cart?**

Remove the connectors the storefront ships with, install @misiki/x-cart-connector, set PUBLIC_X_CART_API_URL in .env and start the dev server. vite.config.ts resolves whichever connector is installed, so no file in the storefront changes.

**Which X-Cart versions and keys does the connector need?**

X-Cart 5.5.1 or later, and the read/write store API key from Settings › API, sent as X-Auth-Token. A read-only key can browse but rejects cart and checkout writes.

**Has the X-Cart connector been run against a real X-Cart store?**

Not against a live production instance — no Svelte Commerce connector has been. It was written by reading X-Cart’s authoritative API source, and the Svelte Commerce maintainers ask X-Cart’s own maintainers for a sandbox to run it against.

### Sources

This page summarises X-CART.md in the Svelte Commerce repository and the X-Cart connector’s source, read on 25 September 2026, and the coverage in CONNECTORS.md, read on 21 September 2026. Where they disagree with this page, they are right and this page is out of date. X-Cart is a trademark of its owner, named here only to describe compatibility; no endorsement or affiliation is implied — see [trademarks](https://kitcommerce.store/about/#trademarks).

- [X-CART.md — the full guide for X-Cart](https://github.com/itswadesh/svelte-commerce/blob/main/docs/X-CART.md)
- [CONNECTORS.md — coverage for all 26 connectors](https://github.com/itswadesh/svelte-commerce/blob/main/docs/CONNECTORS.md)
- [@misiki/x-cart-connector on npm](https://www.npmjs.com/package/@misiki/x-cart-connector)
- [X-Cart](https://www.x-cart.com)

### Read the whole guide

The storefront is the same on every backend; the connector is what changes. X-CART.md has the X-Cart setup in full, beside the connector’s source.

[The X-Cart guide on GitHub](https://github.com/itswadesh/svelte-commerce/blob/main/docs/X-CART.md) · [All 26 backends](https://kitcommerce.store/svelte-commerce/backends/)
