commerce

POST /v1/orders/{orderId}/pay

Pay an order that was placed but not charged.

All commerce endpoints

Authentication

Send an API key as a bearer token. This endpoint does not state a specific permission in the specification, so give your key the least it needs and check the response rather than assuming.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/orders/{orderId}/pay \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{  }'

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

Charges an order left `pending_payment` (or retries one that is `payment_failed`), wallet credit first and the remainder on the org's default mandate. This is where the guest funnel's `next: "payment"` step lands: checkout converts the cart when it places the order, so the cart endpoint cannot settle it afterwards and this is the only surface that can. **Idempotent without an `Idempotency-Key`**, unlike checkout. The order already exists and is itself the dedup scope, so a double-submit records the same capture rather than taking a second one. A pay attempt against an already-paid order returns that order unchanged rather than an error. A **declined card answers 200**, not 402: the attempt was processed exactly as asked and the order comes back `payment_failed` for the caller to read. Only the platform being unable to charge at all — no gateway configured, or one an operator has deliberately disabled — is a 503. **Choosing a gateway.** Send `gateway` to settle this order on a specific rail rather than the org's default mandate — the owner's *"settle overdue bills with any gateway they like"*. It must be one of `getOrderPaymentOptions`'s entries, which is why a reseller's client (who has exactly one) cannot be re-routed. Rails that finish in the browser — PayPal approval, a crypto invoice — answer `200` with the order still `pending_payment` and a `customer_action` carrying the URL to send the customer to; the order settles when the gateway's webhook confirms it.

Parameters

NameTypeRequiredWhat it is
orderId (path)UuidYesThe order's id.

Request body

NameTypeRequiredWhat it is
gatewaystringNoThe rail to settle on (`stripe`, `paypal`, `nowpayments`). Omit to use the org's nominated payment method. `422` if it is not one of this order's `getOrderPaymentOptions`.

Response

NameTypeRequiredWhat it is
idUuidYesUUIDv7 identifier — sortable by creation time (docs/02 §8).
org_idUuidYesUUIDv7 identifier — sortable by creation time (docs/02 §8).
human_refstringYesHuman-friendly order reference.
statusOrderStatusYesAn order's lifecycle state (docs/31 §4.3).
currencyCurrencyCodeYesISO 4217 currency code (money is minor units + this code — CLAUDE.md §2.8).
subtotal_minorintegerYes
tax_minorintegerYes
discount_minorintegerYes
total_minorintegerYes
billing_countryobjectNo
placed_atobjectNo
created_atstringYes
updated_atstringNo
linesOrderLine[]Yes
paymentsPayment[]Yes
customer_actionobjectNoPresent only when the attempt needs the customer to finish it in a browser (PayPal approval, a crypto invoice, a 3-D Secure step). Short-lived and never stored — request it agai…

Errors this endpoint can return

401 · 403 · 404 · 422 · 429 · 503