Place an order
A draft order with a contact and at least one unit line moves to awaiting_payment and is assigned an order number. A consumer (B2C) order additionally requires the CCR pre-contract consent recorded via the order's checkout_state.ccr — without it placement is refused with the ccr_consent_required 409 (a total-changing basket edit clears the recorded consent and re-gates).
A draft order with a contact and at least one unit line moves to awaiting_payment and is assigned an order number. A consumer (B2C) order additionally requires the CCR pre-contract consent recorded via the order's checkout_state.ccr — without it placement is refused with the ccr_consent_required 409 (a total-changing basket edit clears the recorded consent and re-gates).
Present an API key (sb_live_… / sb_test_…), an OAuth2 access token, or a static token as a Bearer credential. The operator is implied by the credential; it is never in the path. Only a SHA-256 hash of an API key is stored server-side.
In: header
Path Parameters
UUIDv7 identifier of the resource.
uuidHeader Parameters
A unique key that makes this mutation safe to retry. Repeats replay the stored response; reuse with a different body returns 409 idempotency_conflict.
length <= 255Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Optional context for a state-changing action.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/orders/497f6eca-6276-4993-bfeb-53cbbbba6f08/place" \ -H "Content-Type: application/json" \ -d '{}'{ "data": { "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "object": "order", "site_id": "72771e6a-6f5e-4de4-a5b9-1266c4197811", "contact_id": "f245e2a3-e141-4d41-912c-b1c1f5bd5598", "reservation_id": "b947feb5-3593-40ee-8244-4428da3fe32d", "number": "string", "status": "draft", "channel": "storefront", "subtotal_minor": 0, "tax_minor": 0, "total_minor": 0, "currency": "str", "coupon_id": "97ffaabb-eb3d-43ed-8769-a889d53b9a3d", "placed_at": "2019-08-24T14:15:22Z", "lines": [ { "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "object": "order_line", "order_id": "93101167-9065-4b9c-b98b-5d789a3ed9fe", "line_type": "unit", "description": "string", "product_id": "0d012afa-f885-4e65-aeca-37e27701e2d1", "coverage_product_id": "0e95c9ac-638a-4481-a2a0-6c1a0f8ac15e", "unit_id": "5becc822-b69e-4e66-a762-ad8e868dcab6", "quantity": 0, "unit_price_minor": 0, "amount_minor": 0, "tax_minor": 0, "ipt_minor": 0, "vat_treatment": "standard_20", "tax_kind": "vat", "currency": "str", "recurring": true, "created_at": "2019-08-24T14:15:22Z", "updated_at": "2019-08-24T14:15:22Z" } ], "created_at": "2019-08-24T14:15:22Z", "updated_at": "2019-08-24T14:15:22Z" }}{ "error": { "code": "unauthorized", "message": "Missing or invalid credential." }}{ "error": { "code": "insufficient_scope", "message": "The credential lacks a scope required by this endpoint." }}{ "error": { "code": "not_found", "message": "Resource not found." }}{ "error": { "code": "conflict", "message": "The request conflicts with current resource state." }}{ "error": { "code": "validation_error", "message": "string", "details": [ { "field": "string", "issue": "string" } ] }}Start (or idempotently re-read) an order's payment session POST
Enqueues a card charge or a Bacs Direct Debit mandate setup through the outbox — never a provider call inline. Re-entry with a live session already attached to the order returns that SAME session, never a second charge/mandate intent.
Provision a paid order POST
A paid order (a secured card payment or Bacs DD mandate) is provisioned — welcome and portal-invite comms are enqueued. Idempotent no-op once already provisioned.