API overview
Place an order from the customer API cart
Choose an operation to see its request, response shape, access rules and implementation source.
WriteAuthenticated
POST/api/v1/checkout
Place an order from the customer API cart
Sanctum session or bearer token. Required bearer ability: orders.create
Request
| Field | In | Rule |
|---|---|---|
billing | JSON body | Required address object: name and line1 strings max 255; city max 120; postal_code max 20; country exactly 2. Nullable company/line2 max 255, region max 120, phone max 40. |
payment_method, discount_code | JSON body | Nullable strings; max 40 each. Use a discovered payment method. |
idempotency_key | JSON body | Nullable string; max 64. JSON only here, not the Idempotency-Key header. Reuse for the same intended checkout only. |
shipping | JSON body | Nullable address array, converted to AddressData. No duplicate nested billing validation; domain rules still apply. |
shipping_same_as_billing | JSON body | Optional boolean; default true. |
shipping_method_id | JSON body | Nullable integer. |
custom_properties | JSON body | Nullable array; domain requirements apply. Products, customer identity and totals are not client overrides. |
curl --request POST "https://shop.example.test/api/v1/checkout" \
--header 'Accept: application/json' \
--header "Authorization: Bearer $API_TOKEN" \
--header 'Content-Type: application/json' \
--data '{"billing":{"name":"Alex Example","line1":"Example Street 1","city":"Brussels","postal_code":"1000","country":"BE"},"shipping_same_as_billing":true,"payment_method":"<discovered-method-id>","idempotency_key":"example-checkout-01"}'Response200 / 201
Success: 200 / 201
Response shape (notation, not a captured response)
{ data: Order }Common errors
| HTTP status | Meaning |
|---|---|
401 | unauthenticated: missing or invalid authentication. |
403 | unauthorized, insufficient_scope or ip_not_allowed: check account context, required ability and token IP policy. |
422 | validation_error: invalid input or unmet domain requirements. Payment initiation can also return payment_failed. |
429 | rate_limited: back off before retrying, especially writes. |