public

POST /v1/public/cart/{token}/server

Add one cloud machine to an anonymous cart.

All public endpoints

Authentication

This endpoint is public. It takes no credential and no organisation — it is what our own marketing site and AI answer engines read.

This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.

Try it

Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.

curl -X POST https://api.zinndigital.com/v1/public/cart/{token}/server \
  -H "Content-Type: application/json" \
  -d '{ "plan_code": <string>, "interval": <string<monthly, annual>>, "name": <string> }'

Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console

Details

The anonymous half of `POST /v1/carts/{cartId}/lines` with `kind=compute_server` (#1741). Before it existed a machine could not be bought without an account at all, so `/hosting/cloud` — ten published, priced Zinn® Cloud tiers — sent every visitor to `/auth/register` first. The price is computed by the server from the catalogue in the cart's own currency; anything sent by the client is ignored. Everything answerable **without an org** is answered now: the size is one we sell, it is a compute size, it has a vendor spec token, the cadence has a price, the machine's name is free within this basket. A refusal here is a `422` the visitor can act on while they are still looking at the configurator. Everything that **needs** an org — the provider, the data centre and the vendor account's funding — is validated at `createPublicCheckout` instead, which is the first instant an org exists and is still **before any card is taken**. So a vendor refusal arrives as a sentence, never as a charge with no machine behind it. There is deliberately no `zone`, `provider`, `disk` or `bandwidth` field: each is answered by an org-scoped live vendor read the anonymous funnel cannot make, and a guessed value is one only the vendor would disagree with, after the charge.

Parameters

NameTypeRequiredWhat it is
token (path)stringYesThe anonymous cart's opaque bearer token (`zgc_…`), as returned by `createPublicCart`. **It is a credential** — anyone holding it can read and modify the cart — and it travels i…

Request body

NameTypeRequiredWhat it is
plan_codestringYesThe catalogue code of the size, as `listCatalogCompute` publishes it (e.g. `cloud_20i_medium`). A **plan code** rather than a `plan_version_id`, because that is what the engine…
intervalstring<monthly, annual>YesThe term the machine is bought for. A cadence the chosen size is not priced at is a `422`; `listCatalogCompute` publishes every cadence each size is sold at, so a term picker bu…
namestringYesWhat the customer will call the machine. Unique within a basket — two lines naming the same machine each pass individually and collide only once both are fulfilled, which is aft…

Response

NameTypeRequiredWhat it is
idUuidYesUUIDv7 identifier — sortable by creation time (docs/02 §8).
tokenstringNoThe bearer token. Returned **only** from `createPublicCart` — it is absent on every subsequent read, because only its digest is stored.
statusstring<open, converted, expired>Yes
currencyCurrencyCodeYesISO 4217 currency code (money is minor units + this code — CLAUDE.md §2.8).
product_linestringNo
expires_atstringYesAfter this the cart is gone — reads 404 whether or not it has been purged.
itemsPublicCartItem[]Yes
totalsPublicCartTotalsYesPre-tax totals. Tax appears on the order, once a billing country exists.

Errors this endpoint can return

404 · 422 · 429