public
POST /v1/public/cart/{token}/extra
Add one purchasable service (an addon) to an anonymous cart.
Authentication
This endpoint is public. It takes no credential and no organisation — it is what our own marketing site and AI answer engines read.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X POST https://api.zinndigital.com/v1/public/cart/{token}/extra \
-H "Content-Type: application/json" \
-d '{ "code": <string> }'Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
Owner ruling 2026-09-09: the order configuration page upsells addons "suitable for the hosting type", and its running total has to match what checkout charges to the minor unit. That second half is what makes an addon a basket LINE rather than a second purchase path — a total including something the basket cannot hold would be a second place that adds money up. The price is computed by the server from the catalogue in the cart's own currency; anything sent by the client is ignored. Which addons this basket may buy is read from its own plan line, never from the request: this endpoint is anonymous, so a caller-supplied product line would put every PBN-only addon one request away from any basket. A basket with no plan in it can buy only the addons sold on every line. 422 covers all three refusals — withdrawn (no fulfilment handler is registered, so we could take the money and run nothing), not sold on this product line, or already in the basket. One of each service per basket.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
token (path) | string | Yes | The anonymous cart's opaque bearer token (zgc_…), as returned by createPublicCart. It is a credential — anyone holding it can read and modify the cart — and it travels in… |
Request body
| Name | Type | Required | What it is |
|---|---|---|---|
code | string | Yes | The catalogue code of the service being added (managed_migration, site_speedup_standard, …), from OrderConfig.addons. One field, and deliberately no product line beside it:… |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
id | Uuid | Yes | UUIDv7 identifier — sortable by creation time (docs/02 §8). |
token | string | No | The bearer token. Returned only from createPublicCart — it is absent on every subsequent read, because only its digest is stored. |
status | string<open, converted, expired> | Yes | — |
currency | CurrencyCode | Yes | ISO 4217 currency code (money is minor units + this code — CLAUDE.md §2.8). |
product_line | string | No | — |
expires_at | string | Yes | After this the cart is gone — reads 404 whether or not it has been purged. |
items | PublicCartItem[] | Yes | — |
totals | PublicCartTotals | Yes | Pre-tax totals. Tax appears on the order, once a billing country exists. |
Errors this endpoint can return
404 · 422 · 429