# checkoutStorefront

Source: <https://telegafirst.com/docs/api-op-checkoutstorefront>
Locale: ru
releaseGitSha: ea133cd4ad87fe549ef000b139be145be9bd1717
sourceContentDigest: 399d65c4fe5b553bc03765f900df3069d31d6cc9f3de4fe9061a2705775fb549
Version: 2

# checkoutStorefront

`POST /api/v1/storefront/checkout`

Start anonymous checkout for an admitted public form

## Авторизация и права

Scopes: ALL. Auth alternatives: OR; scopes внутри альтернативы: ALL.

| Поле | Значение |
| - | - |
| security.0.hubApiKey | \[] |
| security.1.hubBearer | \[] |
| securitySchemes.hubApiKey.in | "header" |
| securitySchemes.hubApiKey.name | "X-Api-Key" |
| securitySchemes.hubApiKey.type | "apiKey" |
| securitySchemes.hubBearer.scheme | "bearer" |
| securitySchemes.hubBearer.type | "http" |
| x-required-scopes | \["orders"] |

## Параметры запроса

| Поле | Значение |
| - | - |
| 0.description | "Form-bound allowed origin; an empty allowlist admits nothing; checked before replay" |
| 0.in | "header" |
| 0.name | "Origin" |
| 0.required | true |
| 0.schema | [0.schema](https://telegafirst.com/docs/schema-00404e686415370f1711c4d7acfa2905444d3cf23cef2e10c47d445ebe690f96) |
| 1.description | "Nonempty caller key isolated by tenant/credential/storefront-checkout profile, retaining results for 86400 seconds" |
| 1.in | "header" |
| 1.name | "Idempotency-Key" |
| 1.required | true |
| 1.schema | [1.schema](https://telegafirst.com/docs/schema-9ac136edb99a2063b3091602181c8d2022fdccb5b514991319d58544c2e57e95) |

## Тело запроса

| Поле | Значение |
| - | - |
| content.application/json.schema | [StorefrontCheckoutRequest](https://telegafirst.com/docs/schema-de67a20b9f95f6f139ffd17dbf09600a72c9ac7832a0c5d13a746b42df2ef161) |
| required | true |

## Ответы

| Поле | Значение |
| - | - |
| 201.content.application/json.schema | [StorefrontCheckoutResponse](https://telegafirst.com/docs/schema-00645ce3549a2e8dd5a85e29283746db09087d7d5877bfefa04c5fad1f2dc9a5) |
| 201.description | "Opaque anonymous order code and provider payment URLs" |
| 201.headers.X-Bot-Username.description | "Authenticated public bot username, when available" |
| 201.headers.X-Bot-Username.schema | [201.headers.X-Bot-Username.schema](https://telegafirst.com/docs/schema-00404e686415370f1711c4d7acfa2905444d3cf23cef2e10c47d445ebe690f96) |
| 201.headers.X-Client-Slug.description | "Authenticated active tenant slug, when available" |
| 201.headers.X-Client-Slug.schema | [201.headers.X-Client-Slug.schema](https://telegafirst.com/docs/schema-00404e686415370f1711c4d7acfa2905444d3cf23cef2e10c47d445ebe690f96) |
| 201.headers.X-RateLimit-Limit.description | "Effective request budget" |
| 201.headers.X-RateLimit-Limit.schema | [201.headers.X-RateLimit-Limit.schema](https://telegafirst.com/docs/schema-00404e686415370f1711c4d7acfa2905444d3cf23cef2e10c47d445ebe690f96) |
| 201.headers.X-RateLimit-Remaining.description | "Remaining budget or unknown" |
| 201.headers.X-RateLimit-Remaining.schema | [201.headers.X-RateLimit-Remaining.schema](https://telegafirst.com/docs/schema-00404e686415370f1711c4d7acfa2905444d3cf23cef2e10c47d445ebe690f96) |
| 201.headers.X-RateLimit-Reset.description | "Window reset Unix seconds" |
| 201.headers.X-RateLimit-Reset.schema | [201.headers.X-RateLimit-Reset.schema](https://telegafirst.com/docs/schema-00404e686415370f1711c4d7acfa2905444d3cf23cef2e10c47d445ebe690f96) |

## Ошибки

| Поле | Значение |
| - | - |
| 400.content.application/problem+json.schema | [ProblemDetails](https://telegafirst.com/docs/schema-c4113f3de00d728702a8663612e2074cbe3e8b3bb70d2b0dee6f3503fe89bd41) |
| 400.description | "VALIDATION\_ERROR: invalid strict code-only body; IDEMPOTENCY\_KEY\_REQUIRED: missing nonempty POST key" |
| 401.content.application/problem+json.schema | [ProblemDetails](https://telegafirst.com/docs/schema-c4113f3de00d728702a8663612e2074cbe3e8b3bb70d2b0dee6f3503fe89bd41) |
| 401.description | "INVALID\_API\_KEY: missing, invalid, revoked or conflicting credential headers; surface-session JWT is refused" |
| 403.content.application/problem+json.schema | [ProblemDetails](https://telegafirst.com/docs/schema-c4113f3de00d728702a8663612e2074cbe3e8b3bb70d2b0dee6f3503fe89bd41) |
| 403.description | "FORBIDDEN: current form/origin/product admission refused; INSUFFICIENT\_SCOPE, NO\_ACTIVE\_BOT or typed Orders authority refusal; plan fences also normalize to FORBIDDEN" |
| 404.content.application/problem+json.schema | [ProblemDetails](https://telegafirst.com/docs/schema-c4113f3de00d728702a8663612e2074cbe3e8b3bb70d2b0dee6f3503fe89bd41) |
| 404.description | "ORDER\_NOT\_FOUND: typed Orders creation result unavailable" |
| 409.content.application/problem+json.schema | [ProblemDetails](https://telegafirst.com/docs/schema-c4113f3de00d728702a8663612e2074cbe3e8b3bb70d2b0dee6f3503fe89bd41) |
| 409.description | "IDEMPOTENCY\_CONFLICT: different canonical request, CONFLICT: in-flight key, or typed Orders conflict" |
| 413.content.application/problem+json.schema | [ProblemDetails](https://telegafirst.com/docs/schema-c4113f3de00d728702a8663612e2074cbe3e8b3bb70d2b0dee6f3503fe89bd41) |
| 413.description | "PAYLOAD\_TOO\_LARGE or ITEM\_COUNT\_EXCEEDED: per-tool resource limits" |
| 422.content.application/problem+json.schema | [ProblemDetails](https://telegafirst.com/docs/schema-c4113f3de00d728702a8663612e2074cbe3e8b3bb70d2b0dee6f3503fe89bd41) |
| 422.description | "Typed Orders validation refusal, or VALIDATION\_ERROR for an unexpected checkout-start failure" |
| 429.content.application/problem+json.schema | [ProblemDetails](https://telegafirst.com/docs/schema-c4113f3de00d728702a8663612e2074cbe3e8b3bb70d2b0dee6f3503fe89bd41) |
| 429.description | "RATE\_LIMIT\_EXCEEDED or RATE\_LIMIT\_UNAVAILABLE: resource budget refusal" |
| 429.headers.Retry-After.description | "Retry delay in seconds, when supplied by the limiter" |
| 429.headers.Retry-After.schema | [429.headers.Retry-After.schema](https://telegafirst.com/docs/schema-f0765dbf409c74f001806c446f2cf171d8c46b5b15779d54423dde921a4b0670) |
| 500.content.application/problem+json.schema | [ProblemDetails](https://telegafirst.com/docs/schema-c4113f3de00d728702a8663612e2074cbe3e8b3bb70d2b0dee6f3503fe89bd41) |
| 500.description | "INTERNAL\_ERROR: unexpected failure; no internal payload is exposed" |

## Дополнительные условия

| Поле | Значение |
| - | - |
| description | "P1 server-side checkout relay, accepting server credentials or a publishable key only on this explicitly marked surface. Requires orders scope, not orders:write. The strict body names only the opaque form code; the guard resolves (tenant, code), verifies the live enabled checkout form, tenant product and form-bound Origin before every initial request and cached replay. Product, pricing, user identity, redirect and external\_order\_ref cannot be supplied. Anonymous order creation uses the existing Orders quote/create road. order\_id is an opaque public code; Gateway buyer checkout remains a separate P2 surface behind StorefrontCustomerGuard and per-tenant order number/ownership checks. Surface-session JWT is refused." |
| operationId | "checkoutStorefront" |
| summary | "Start anonymous checkout for an admitted public form" |
| tags | \["storefront"] |
| x-idempotency.conflictCode | "IDEMPOTENCY\_CONFLICT" |
| x-idempotency.conflictStatus | 409 |
| x-idempotency.mode | "required" |
| x-idempotency.profile | "storefront-checkout" |
| x-idempotency.replayStatus | 201 |
| x-idempotency.ttlSeconds | 86400 |
| x-pagination.queryParameters | \[] |
| x-pagination.supported | false |
| x-publishable-surface | true |
