marketplace
POST /v1/marketplace/orders/{sale_id}/messages
Send a message on an order.
Authentication
Send an API key as a bearer token. This endpoint does not state a specific permission in the specification, so give your key the least it needs and check the response rather than assuming.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X POST https://api.zinndigital.com/v1/marketplace/orders/{sale_id}/messages \
-H "Authorization: Bearer zdk_live_…" \
-H "Content-Type: application/json" \
-d '{ "body": <string> }'Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
docs/133 D26. The on-platform contact policy applies and is **proportionate**: a message may be sent as written, sent and flagged quietly, sent with contact details masked, or held for review. There is no rung that refuses to send — a hard block is what generates the false positives honest sellers leave over, and they do not complain first. After an order exists, exchanging details is often the work itself — a guest post needs the target URL and the anchor, an asset transfer needs the registrar and the DNS — so the policy leans far less here than on a pre-sales enquiry, and least of all on an asset transfer. `held` is reported to the sender. It is the one case where "sent" would be a lie.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
sale_id (path) | string | Yes | — |
Request body
| Name | Type | Required | What it is |
|---|---|---|---|
body | string | Yes | — |
locale | string | No | — |
attachments | object[] | No | Refused entirely on a pre-sales thread: an attachment bypasses text scanning and we have no OCR, so on the one surface where nobody has paid there are no files. |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
id | string | Yes | — |
body | string | Yes | What the reader sees — the masked form where the policy masked it. The original is always kept in the order record and is what a dispute reads; it is not in this payload, becaus… |
mine | boolean | Yes | — |
from_staff | boolean | No | — |
source_locale | string | No | BCP-47. Participants write in their own language; a message is translated FOR THE READER and the original is always shown, never replaced. |
masked | boolean | No | — |
policy_notice | string | No | A message KEY, rendered in every locale by the client. Set only for the SENDER of a masked message — telling the recipient "they tried to give you an email address" would be an… |
held | boolean | No | Only on the send response. The one case where reporting "sent" would be a lie. |
created_at | string | Yes | — |
Errors this endpoint can return
401 · 404 · 422