Skip to content
cresvaDevelopers

Open a checkout session

POST/api/storefront/{brandId}/checkout/sessions
Secret keySend an sk_live_ key. Server side only.300 requests a minute

The request names products and quantities. EVERY PRICE IS READ FROM THE CATALOGUE and any price in the body is ignored; there is no field here a price can arrive in. A session that can never complete is created as `refused` rather than `open`, so an agent is told now instead of polling something that will never move.

Parameters

brandIdstring · pathrequiredThe storefront's brand id. There is no public endpoint that maps a domain to a brand id; ask the merchant for their storefront URL, the id is in it.

Request body

itemsarray of object
productIdstringrequired
quantityintegerrequired
negotiationIdstring
bundleIdstring
offerClaimIdstring

Request

bash
BRAND_ID=cmqmr1f6j0003la04nu93f4k4
curl -X POST "https://cresva.ai/api/storefront/$BRAND_ID/checkout/sessions" \
  -H "Authorization: Bearer $CRESVA_SECRET_KEY" \
  -H "Content-Type: application/json" \
  -d '{"items":[…],"negotiationId":"<negotiationId>","bundleId":"<bundleId>","offerClaimId":"<offerClaimId>"}'

The body above is a template: the field names are the schema's own and the values are placeholders. It is not a captured request, and nothing on this page invents a value a real call would carry.

Response

No captured response. This operation needs a key. A captured response would mean either printing a real merchant's credential or printing a redacted command nobody can run.

The response schema below is the contract. It comes from the same document the router is checked against, so it is what the endpoint returns even though nobody has printed one here.

Response codes

200The session.
object
401The key does not match any active key.
erroranyTwo shapes exist across this API and that is deliberate rather than untidy. Each route kept the error shape it already used, so an existing client's error handling keeps working. See x-cresva-error-shapes.
403Either the key belongs to a different brand, or this store is not accepting this verb. Lever refusal message: "This store is not accepting agent checkout." Machine-readable code where the route carries one: "levers_not_enabled" A refusal here is about the MERCHANT'S configuration, not about our pricing, and there is more than one reason for it. See x-cresva-refusal-reasons.
erroranyTwo shapes exist across this API and that is deliberate rather than untidy. Each route kept the error shape it already used, so an existing client's error handling keeps working. See x-cresva-error-shapes.
404No such brand.
erroranyTwo shapes exist across this API and that is deliberate rather than untidy. Each route kept the error shape it already used, so an existing client's error handling keeps working. See x-cresva-error-shapes.
429Over the rate limit.
erroranyTwo shapes exist across this API and that is deliberate rather than untidy. Each route kept the error shape it already used, so an existing client's error handling keeps working. See x-cresva-error-shapes.
503The rate limiter could not be reached, so the request was refused rather than served unmetered. Deliberately not a 429: the caller has done nothing wrong and the fault is ours.
erroranyTwo shapes exist across this API and that is deliberate rather than untidy. Each route kept the error shape it already used, so an existing client's error handling keeps working. See x-cresva-error-shapes.

Generated from the storefront OpenAPI document at growthagents 269d7898b, sha256 047fe4d301258100. Nothing on this page was typed by hand.