public
POST /v1/public/cart/{token}/server
Add one cloud machine to an anonymous cart.
Authentication
This endpoint is public. It takes no credential and no organisation — it is what our own marketing site and AI answer engines read.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X POST https://api.zinndigital.com/v1/public/cart/{token}/server \
-H "Content-Type: application/json" \
-d '{ "plan_code": <string>, "interval": <string<monthly, annual>>, "name": <string> }'Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
The anonymous half of `POST /v1/carts/{cartId}/lines` with `kind=compute_server` (#1741). Before it existed a machine could not be bought without an account at all, so `/hosting/cloud` — ten published, priced Zinn® Cloud tiers — sent every visitor to `/auth/register` first. The price is computed by the server from the catalogue in the cart's own currency; anything sent by the client is ignored. Everything answerable **without an org** is answered now: the size is one we sell, it is a compute size, it has a vendor spec token, the cadence has a price, the machine's name is free within this basket. A refusal here is a `422` the visitor can act on while they are still looking at the configurator. Everything that **needs** an org — the provider, the data centre and the vendor account's funding — is validated at `createPublicCheckout` instead, which is the first instant an org exists and is still **before any card is taken**. So a vendor refusal arrives as a sentence, never as a charge with no machine behind it. There is deliberately no `zone`, `provider`, `disk` or `bandwidth` field: each is answered by an org-scoped live vendor read the anonymous funnel cannot make, and a guessed value is one only the vendor would disagree with, after the charge.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
token (path) | string | Yes | The anonymous cart's opaque bearer token (`zgc_…`), as returned by `createPublicCart`. **It is a credential** — anyone holding it can read and modify the cart — and it travels i… |
Request body
| Name | Type | Required | What it is |
|---|---|---|---|
plan_code | string | Yes | The catalogue code of the size, as `listCatalogCompute` publishes it (e.g. `cloud_20i_medium`). A **plan code** rather than a `plan_version_id`, because that is what the engine… |
interval | string<monthly, annual> | Yes | The term the machine is bought for. A cadence the chosen size is not priced at is a `422`; `listCatalogCompute` publishes every cadence each size is sold at, so a term picker bu… |
name | string | Yes | What the customer will call the machine. Unique within a basket — two lines naming the same machine each pass individually and collide only once both are fulfilled, which is aft… |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
id | Uuid | Yes | UUIDv7 identifier — sortable by creation time (docs/02 §8). |
token | string | No | The bearer token. Returned **only** from `createPublicCart` — it is absent on every subsequent read, because only its digest is stored. |
status | string<open, converted, expired> | Yes | — |
currency | CurrencyCode | Yes | ISO 4217 currency code (money is minor units + this code — CLAUDE.md §2.8). |
product_line | string | No | — |
expires_at | string | Yes | After this the cart is gone — reads 404 whether or not it has been purged. |
items | PublicCartItem[] | Yes | — |
totals | PublicCartTotals | Yes | Pre-tax totals. Tax appears on the order, once a billing country exists. |
Errors this endpoint can return
404 · 422 · 429