К содержанию
TelegaFirst

Для AI-агентов: markdown этой страницы — /docs/api-op-checkoutstorefront.mdиндекс документации — /llms.txt

checkoutStorefront

Обновлено

POST /api/v1/storefront/checkout

Start anonymous checkout for an admitted public form

Авторизация и права

Scopes: ALL. Auth alternatives: OR; scopes внутри альтернативы: ALL.

ПолеЗначение
security.0.hubApiKey[]
security.1.hubBearer[]
securitySchemes.hubApiKey.in"header"
securitySchemes.hubApiKey.name"X-Api-Key"
securitySchemes.hubApiKey.type"apiKey"
securitySchemes.hubBearer.scheme"bearer"
securitySchemes.hubBearer.type"http"
x-required-scopes["orders"]

Параметры запроса

ПолеЗначение
0.description"Form-bound allowed origin; an empty allowlist admits nothing; checked before replay"
0.in"header"
0.name"Origin"
0.requiredtrue
0.schema0.schema
1.description"Nonempty caller key isolated by tenant/credential/storefront-checkout profile, retaining results for 86400 seconds"
1.in"header"
1.name"Idempotency-Key"
1.requiredtrue
1.schema1.schema

Тело запроса

ПолеЗначение
content.application/json.schemaStorefrontCheckoutRequest
requiredtrue

Ответы

ПолеЗначение
201.content.application/json.schemaStorefrontCheckoutResponse
201.description"Opaque anonymous order code and provider payment URLs"
201.headers.X-Bot-Username.description"Authenticated public bot username, when available"
201.headers.X-Bot-Username.schema201.headers.X-Bot-Username.schema
201.headers.X-Client-Slug.description"Authenticated active tenant slug, when available"
201.headers.X-Client-Slug.schema201.headers.X-Client-Slug.schema
201.headers.X-RateLimit-Limit.description"Effective request budget"
201.headers.X-RateLimit-Limit.schema201.headers.X-RateLimit-Limit.schema
201.headers.X-RateLimit-Remaining.description"Remaining budget or unknown"
201.headers.X-RateLimit-Remaining.schema201.headers.X-RateLimit-Remaining.schema
201.headers.X-RateLimit-Reset.description"Window reset Unix seconds"
201.headers.X-RateLimit-Reset.schema201.headers.X-RateLimit-Reset.schema

Ошибки

ПолеЗначение
400.content.application/problem+json.schemaProblemDetails
400.description"VALIDATION_ERROR: invalid strict code-only body; IDEMPOTENCY_KEY_REQUIRED: missing nonempty POST key"
401.content.application/problem+json.schemaProblemDetails
401.description"INVALID_API_KEY: missing, invalid, revoked or conflicting credential headers; surface-session JWT is refused"
403.content.application/problem+json.schemaProblemDetails
403.description"FORBIDDEN: current form/origin/product admission refused; INSUFFICIENT_SCOPE, NO_ACTIVE_BOT or typed Orders authority refusal; plan fences also normalize to FORBIDDEN"
404.content.application/problem+json.schemaProblemDetails
404.description"ORDER_NOT_FOUND: typed Orders creation result unavailable"
409.content.application/problem+json.schemaProblemDetails
409.description"IDEMPOTENCY_CONFLICT: different canonical request, CONFLICT: in-flight key, or typed Orders conflict"
413.content.application/problem+json.schemaProblemDetails
413.description"PAYLOAD_TOO_LARGE or ITEM_COUNT_EXCEEDED: per-tool resource limits"
422.content.application/problem+json.schemaProblemDetails
422.description"Typed Orders validation refusal, or VALIDATION_ERROR for an unexpected checkout-start failure"
429.content.application/problem+json.schemaProblemDetails
429.description"RATE_LIMIT_EXCEEDED or RATE_LIMIT_UNAVAILABLE: resource budget refusal"
429.headers.Retry-After.description"Retry delay in seconds, when supplied by the limiter"
429.headers.Retry-After.schema429.headers.Retry-After.schema
500.content.application/problem+json.schemaProblemDetails
500.description"INTERNAL_ERROR: unexpected failure; no internal payload is exposed"

Дополнительные условия

ПолеЗначение
description"P1 server-side checkout relay, accepting server credentials or a publishable key only on this explicitly marked surface. Requires orders scope, not orders:write. The strict body names only the opaque form code; the guard resolves (tenant, code), verifies the live enabled checkout form, tenant product and form-bound Origin before every initial request and cached replay. Product, pricing, user identity, redirect and external_order_ref cannot be supplied. Anonymous order creation uses the existing Orders quote/create road. order_id is an opaque public code; Gateway buyer checkout remains a separate P2 surface behind StorefrontCustomerGuard and per-tenant order number/ownership checks. Surface-session JWT is refused."
operationId"checkoutStorefront"
summary"Start anonymous checkout for an admitted public form"
tags["storefront"]
x-idempotency.conflictCode"IDEMPOTENCY_CONFLICT"
x-idempotency.conflictStatus409
x-idempotency.mode"required"
x-idempotency.profile"storefront-checkout"
x-idempotency.replayStatus201
x-idempotency.ttlSeconds86400
x-pagination.queryParameters[]
x-pagination.supportedfalse
x-publishable-surfacetrue