Authentication
This endpoint is public. It takes no credential and no organisation — it is what our own marketing site and AI answer engines read.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X POST https://api.zinndigital.com/v1/public/cart/{token}/items \
-H "Content-Type: application/json" \
-d '{ "kind": <string<domain_register>>, "domain": <string>, "tld": <string>, "years": <integer>, "availability_token": <string> }'Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
Adds one `domain_register` item and returns the updated cart. `availability_token` is the `token` from a search result for **this exact name** and is required: it is what proves the item came out of a real, rate-limited search rather than being invented, so a name that search would not sell cannot be added here either. A stale, forged or now-taken name is a `409`. A cart holds at most 20 items, and one name may appear only once. The price is computed by the server; anything sent by the client is ignored.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
token (path) | string | Yes | The anonymous cart's opaque bearer token (`zgc_…`), as returned by `createPublicCart`. **It is a credential** — anyone holding it can read and modify the cart — and it travels i… |
Request body
| Name | Type | Required | What it is |
|---|---|---|---|
kind | string<domain_register> | Yes | — |
domain | string | Yes | The full FQDN (`acme.com`) or just the second-level label (`acme`) alongside `tld`. Both resolve to the same name; a sub-domain is rejected. |
tld | string | Yes | — |
years | integer | Yes | — |
availability_token | string | Yes | The `token` from a search result **for this exact name**. Required — it is what proves the item came from a real search, so nothing that search declines to sell can be added by… |
privacy | boolean | No | — |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
id | Uuid | Yes | UUIDv7 identifier — sortable by creation time (docs/02 §8). |
token | string | No | The bearer token. Returned **only** from `createPublicCart` — it is absent on every subsequent read, because only its digest is stored. |
status | string<open, converted, expired> | Yes | — |
currency | CurrencyCode | Yes | ISO 4217 currency code (money is minor units + this code — CLAUDE.md §2.8). |
product_line | string | No | — |
expires_at | string | Yes | After this the cart is gone — reads 404 whether or not it has been purged. |
items | PublicCartItem[] | Yes | — |
totals | PublicCartTotals | Yes | Pre-tax totals. Tax appears on the order, once a billing country exists. |
Errors this endpoint can return
404 · 409 · 422 · 429