commerce
POST /v1/orders/{orderId}/customer-action
Reopen the checkout for a payment that is waiting on the customer.
Authentication
Send an API key as a bearer token. This endpoint does not state a specific permission in the specification, so give your key the least it needs and check the response rather than assuming.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X POST https://api.zinndigital.com/v1/orders/{orderId}/customer-action \
-H "Authorization: Bearer zdk_live_…"Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
Returns where the customer finishes paying an order that is already part-way through a payment — the NOWPayments hosted crypto invoice, a PayPal approval page, or a fresh Stripe SCA credential. This is what makes a crypto order payable: the gateway supplies that link once, at the instant the invoice is opened, and until this endpoint existed nothing gave it to the customer. **It never charges.** `POST /v1/orders/{orderId}/pay` is the guarded surface that opens a payment; this one only reopens the checkout for a payment already in progress, so it sits behind none of the card-testing defences and needs none. Call `/pay` first; come back here to send the customer to the checkout, and again whenever they return to it later. **A crypto action always returns the SAME invoice.** The confirming IPN is matched on the invoice id recorded against the payment, so a second invoice for one order would take the customer's money against a record that does not exist. NOWPayments has no read-invoice endpoint either, so the link captured when the invoice was opened is the only one there is.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
orderId (path) | Uuid | Yes | The order's id. |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
kind | string<pay, approve, authenticate> | Yes | What the customer is being asked to do. `pay` — open a crypto invoice and send payment; `approve` — approve the payment in their PayPal account; `authenticate` — confirm the pay… |
url | string | No | The hosted page to send the customer to, or `""` when this action is a credential instead. For crypto this is the NOWPayments invoice and it is **stable for the life of the orde… |
token | string | No | A short-lived client-side credential for the gateway's browser SDK (Stripe's client secret), or `""`. Never stored by the platform — it is re-read from the gateway each time thi… |
provider | string | Yes | The payments driver that owns this action (`nowpayments`, `paypal`, `stripe`). |
Errors this endpoint can return
401 · 403 · 404 · 422 · 429