Confirm a checkout intent
The shopper’s approval. Send the confirmation_token with the shopper’s credential, or — for a guest —
with contact (email and name).
The basket is re-priced first. If anything the shopper pays has changed — a line price, the discount,
shipping, tax or the total — the response is 409 quote_changed with the new quote in error.details,
and nothing is placed; show the shopper the new figures and create a new intent. Otherwise the order is
placed with payment pending, using the held stock, and the response carries what
POST /v1/payments/initialize needs to take payment, plus the store’s payment methods.
The token is single use: a second confirmation returns 409 intent_not_pending. A wrong token returns
403 invalid_token and discloses nothing about the intent.
curl --request POST \
--url https://api.tybritelabs.com/v1/agent/checkout-intents/{id}/confirm \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"confirmation_token": "Vq3yJ9mXo1bT0c8r2Hk5uW7eZ4sA6dLfN1pG8iQ3xYk",
"contact": {
"email": "john.doe@example.com",
"name": "John Doe"
}
}
'import requests
url = "https://api.tybritelabs.com/v1/agent/checkout-intents/{id}/confirm"
payload = {
"confirmation_token": "Vq3yJ9mXo1bT0c8r2Hk5uW7eZ4sA6dLfN1pG8iQ3xYk",
"contact": {
"email": "john.doe@example.com",
"name": "John Doe"
}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
confirmation_token: 'Vq3yJ9mXo1bT0c8r2Hk5uW7eZ4sA6dLfN1pG8iQ3xYk',
contact: {email: 'john.doe@example.com', name: 'John Doe'}
})
};
fetch('https://api.tybritelabs.com/v1/agent/checkout-intents/{id}/confirm', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.tybritelabs.com/v1/agent/checkout-intents/{id}/confirm",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'confirmation_token' => 'Vq3yJ9mXo1bT0c8r2Hk5uW7eZ4sA6dLfN1pG8iQ3xYk',
'contact' => [
'email' => 'john.doe@example.com',
'name' => 'John Doe'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.tybritelabs.com/v1/agent/checkout-intents/{id}/confirm"
payload := strings.NewReader("{\n \"confirmation_token\": \"Vq3yJ9mXo1bT0c8r2Hk5uW7eZ4sA6dLfN1pG8iQ3xYk\",\n \"contact\": {\n \"email\": \"john.doe@example.com\",\n \"name\": \"John Doe\"\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.tybritelabs.com/v1/agent/checkout-intents/{id}/confirm")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"confirmation_token\": \"Vq3yJ9mXo1bT0c8r2Hk5uW7eZ4sA6dLfN1pG8iQ3xYk\",\n \"contact\": {\n \"email\": \"john.doe@example.com\",\n \"name\": \"John Doe\"\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.tybritelabs.com/v1/agent/checkout-intents/{id}/confirm")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"confirmation_token\": \"Vq3yJ9mXo1bT0c8r2Hk5uW7eZ4sA6dLfN1pG8iQ3xYk\",\n \"contact\": {\n \"email\": \"john.doe@example.com\",\n \"name\": \"John Doe\"\n }\n}"
response = http.request(request)
puts response.read_body{
"data": {
"intent": {
"id": "0ff91bd6-aa86-4ef6-8242-fe8644bca1bb",
"status": "confirmed",
"confirmation_mode": "token",
"expires_at": "2026-09-28T22:24:09.629+00:00",
"order_id": "74a3221b-a5dc-4e56-9b9e-2d0c55611bd5",
"customer_id": null,
"total": 1548,
"currency": "EUR",
"items": [
{
"quantity": 1,
"variant_id": "fbe89cdf-90a3-4050-a43b-e4c42302484a"
}
],
"quote": {
"tax": {
"amount": 213.52,
"source": "fallback",
"status": "quoted",
"prices_include_tax": true
},
"lines": [
{
"sku": "FEED-HOODIE-GRY-M",
"name": "Galactic Zip Hoodie",
"stock": 25,
"quantity": 1,
"available": true,
"line_total": 48,
"list_price": 48,
"product_id": "289533e8-f5b6-4d4f-bb23-2127875feb70",
"unit_price": 48,
"variant_id": "fbe89cdf-90a3-4050-a43b-e4c42302484a",
"variant_name": "Grey / M",
"category_name": "Wearables",
"unavailable_reason": null
}
],
"currency": "EUR",
"discount": {
"amount": 0,
"promotion": null
},
"shipping": {
"amount": 1500,
"status": "quoted",
"is_free": false,
"description": "USA",
"free_threshold": 100000
},
"subtotal": 48,
"grand_total": 1548,
"total_is_final": true,
"shipping_address": {
"city": "New York",
"name": "John Doe",
"line1": "350 Fifth Avenue",
"state": "NY",
"country": "US",
"postal_code": "10118"
},
"unavailable_count": 0
},
"created_at": "2026-09-28T21:54:09.713316+00:00",
"confirmed_at": "2026-09-28T21:54:17.256+00:00",
"cancelled_at": null
},
"order": {
"id": "74a3221b-a5dc-4e56-9b9e-2d0c55611bd5",
"order_number": "ORD-1790632457762",
"total_amount": 1548,
"currency": "EUR",
"payment_status": "pending",
"order_status": "pending"
},
"payment": {
"next_step": "POST /v1/payments/initialize",
"initialize_body": {
"order_id": "74a3221b-a5dc-4e56-9b9e-2d0c55611bd5",
"amount": 1548,
"currency": "EUR",
"email": "john.doe@example.com"
},
"methods": [
{
"provider": "cash",
"display_name": "Cash on Delivery",
"type": "manual",
"environment": "production",
"is_configured": true
},
{
"provider": "stripe",
"display_name": "Stripe",
"type": "redirect",
"environment": "test",
"is_configured": true
},
{
"provider": "paypal",
"display_name": "PayPal",
"type": "popup",
"environment": "sandbox",
"is_configured": true
},
{
"provider": "paystack",
"display_name": "Paystack",
"type": "popup",
"environment": "test",
"is_configured": true
}
]
}
},
"evidence": [
{
"source": "pricing",
"operation": "GET /v1/prices/products/{id}",
"id": "fbe89cdf-90a3-4050-a43b-e4c42302484a",
"field": "resolved_price"
},
{
"source": "promotions",
"operation": "POST /v1/promotions/calculate-best",
"field": "discount"
},
{
"source": "shipping",
"operation": "shipping quote",
"field": "fee"
},
{
"source": "tax",
"operation": "POST /v1/tax/preview",
"field": "tax_amount"
},
{
"source": "orders",
"operation": "order create",
"id": "74a3221b-a5dc-4e56-9b9e-2d0c55611bd5",
"field": "total_amount"
},
{
"source": "payments",
"operation": "GET /v1/payments/methods",
"field": "methods"
}
],
"computed_at": "2026-09-28T21:54:23.191Z",
"currency": "EUR",
"environment": "sandbox"
}{
"error": {
"code": "invalid_request",
"message": "A guest confirmation needs contact.email"
}
}{
"error": {
"code": "unauthorized",
"message": "Missing or invalid Authorization header"
}
}{
"error": {
"code": "invalid_token",
"message": "The confirmation token does not match this checkout intent"
}
}{
"error": {
"code": "not_found",
"message": "Checkout intent not found: 00000000-0000-4000-8000-000000000000"
}
}{
"error": {
"code": "quote_changed",
"message": "The price changed since the checkout was prepared. Show the shopper the new quote and create a new intent.",
"details": {
"changes": [
"grand total: 1549 → 1548"
],
"quote": {
"tax": {
"amount": 213.52,
"source": "fallback",
"status": "quoted",
"prices_include_tax": true
},
"lines": [
{
"sku": "FEED-HOODIE-GRY-M",
"name": "Galactic Zip Hoodie",
"stock": 25,
"quantity": 1,
"available": true,
"line_total": 48,
"list_price": 48,
"product_id": "289533e8-f5b6-4d4f-bb23-2127875feb70",
"unit_price": 48,
"variant_id": "fbe89cdf-90a3-4050-a43b-e4c42302484a",
"variant_name": "Grey / M",
"category_name": "Wearables",
"unavailable_reason": null
}
],
"currency": "EUR",
"discount": {
"amount": 0,
"promotion": null
},
"shipping": {
"amount": 1500,
"status": "quoted",
"is_free": false,
"description": "USA",
"free_threshold": 100000
},
"subtotal": 48,
"grand_total": 1548,
"total_is_final": true,
"shipping_address": {
"city": "New York",
"name": "John Doe",
"line1": "350 Fifth Avenue",
"state": "NY",
"country": "US",
"postal_code": "10118"
},
"unavailable_count": 0
}
}
}
}{
"error": {
"code": "rate_limited",
"message": "Too many requests for this API key. Please slow down and try again shortly.",
"remaining": 0,
"reset": 1706198400
}
}{
"error": {
"code": "server_error",
"message": "An unexpected error occurred"
}
}Authorizations
API Key Authentication
Use your API key in the Authorization header:
Authorization: Bearer tybrite_sk_live_YOUR_KEY
Key Types:
Secret Keys (Server-Side Only):
- Format:
tybrite_sk_live_*(production) ortybrite_sk_test_*(sandbox) - Full read/write access to all endpoints
- ⚠️ NEVER expose in client-side code or public repositories
- Required for: write operations, authentication, payment verification, AI recommendations
Publishable Keys (Client-Safe):
- Format:
tybrite_pk_live_*(production) ortybrite_pk_test_*(sandbox) - Read-only access (GET requests only, plus POST semantic search)
- ✅ Safe for client-side JavaScript, mobile apps, and public code
- Allowed for: browsing products, search, CMS content, pricing queries
Endpoint-Specific Requirements:
- Authentication endpoints (
/v1/auth/*): Secret key required - Payment verification (
POST /v1/payments/verify): Secret key required - AI Recommendations (
POST /v1/recommendations): Secret key required - Semantic Search (
POST /v1/search): Both key types allowed (read-only operation) - All write operations: Secret key required
- All read operations: Both key types allowed
Using a publishable key for restricted operations returns 403 Forbidden.
Headers
Customer session token from POST /v1/auth/login or POST /v1/auth/verify-otp. Provide exactly one of x-auth-token, x-external-auth, or x-idp-token.
Bring-your-own-auth assertion identifying the customer. Provide exactly one of x-auth-token, x-external-auth, or x-idp-token.
A raw token from the store's own identity provider, verified by the store's configured Auth verifier. Provide exactly one of x-auth-token, x-external-auth, or x-idp-token.
Path Parameters
The checkout intent.
Body
Response
The order, placed with payment pending
Show child attributes
Show child attributes
Where each figure in data was read from.
Show child attributes
Show child attributes
production, sandbox ISO 4217 code every amount in data is expressed in.
curl --request POST \
--url https://api.tybritelabs.com/v1/agent/checkout-intents/{id}/confirm \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"confirmation_token": "Vq3yJ9mXo1bT0c8r2Hk5uW7eZ4sA6dLfN1pG8iQ3xYk",
"contact": {
"email": "john.doe@example.com",
"name": "John Doe"
}
}
'import requests
url = "https://api.tybritelabs.com/v1/agent/checkout-intents/{id}/confirm"
payload = {
"confirmation_token": "Vq3yJ9mXo1bT0c8r2Hk5uW7eZ4sA6dLfN1pG8iQ3xYk",
"contact": {
"email": "john.doe@example.com",
"name": "John Doe"
}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
confirmation_token: 'Vq3yJ9mXo1bT0c8r2Hk5uW7eZ4sA6dLfN1pG8iQ3xYk',
contact: {email: 'john.doe@example.com', name: 'John Doe'}
})
};
fetch('https://api.tybritelabs.com/v1/agent/checkout-intents/{id}/confirm', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.tybritelabs.com/v1/agent/checkout-intents/{id}/confirm",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'confirmation_token' => 'Vq3yJ9mXo1bT0c8r2Hk5uW7eZ4sA6dLfN1pG8iQ3xYk',
'contact' => [
'email' => 'john.doe@example.com',
'name' => 'John Doe'
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.tybritelabs.com/v1/agent/checkout-intents/{id}/confirm"
payload := strings.NewReader("{\n \"confirmation_token\": \"Vq3yJ9mXo1bT0c8r2Hk5uW7eZ4sA6dLfN1pG8iQ3xYk\",\n \"contact\": {\n \"email\": \"john.doe@example.com\",\n \"name\": \"John Doe\"\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.tybritelabs.com/v1/agent/checkout-intents/{id}/confirm")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"confirmation_token\": \"Vq3yJ9mXo1bT0c8r2Hk5uW7eZ4sA6dLfN1pG8iQ3xYk\",\n \"contact\": {\n \"email\": \"john.doe@example.com\",\n \"name\": \"John Doe\"\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.tybritelabs.com/v1/agent/checkout-intents/{id}/confirm")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"confirmation_token\": \"Vq3yJ9mXo1bT0c8r2Hk5uW7eZ4sA6dLfN1pG8iQ3xYk\",\n \"contact\": {\n \"email\": \"john.doe@example.com\",\n \"name\": \"John Doe\"\n }\n}"
response = http.request(request)
puts response.read_body{
"data": {
"intent": {
"id": "0ff91bd6-aa86-4ef6-8242-fe8644bca1bb",
"status": "confirmed",
"confirmation_mode": "token",
"expires_at": "2026-09-28T22:24:09.629+00:00",
"order_id": "74a3221b-a5dc-4e56-9b9e-2d0c55611bd5",
"customer_id": null,
"total": 1548,
"currency": "EUR",
"items": [
{
"quantity": 1,
"variant_id": "fbe89cdf-90a3-4050-a43b-e4c42302484a"
}
],
"quote": {
"tax": {
"amount": 213.52,
"source": "fallback",
"status": "quoted",
"prices_include_tax": true
},
"lines": [
{
"sku": "FEED-HOODIE-GRY-M",
"name": "Galactic Zip Hoodie",
"stock": 25,
"quantity": 1,
"available": true,
"line_total": 48,
"list_price": 48,
"product_id": "289533e8-f5b6-4d4f-bb23-2127875feb70",
"unit_price": 48,
"variant_id": "fbe89cdf-90a3-4050-a43b-e4c42302484a",
"variant_name": "Grey / M",
"category_name": "Wearables",
"unavailable_reason": null
}
],
"currency": "EUR",
"discount": {
"amount": 0,
"promotion": null
},
"shipping": {
"amount": 1500,
"status": "quoted",
"is_free": false,
"description": "USA",
"free_threshold": 100000
},
"subtotal": 48,
"grand_total": 1548,
"total_is_final": true,
"shipping_address": {
"city": "New York",
"name": "John Doe",
"line1": "350 Fifth Avenue",
"state": "NY",
"country": "US",
"postal_code": "10118"
},
"unavailable_count": 0
},
"created_at": "2026-09-28T21:54:09.713316+00:00",
"confirmed_at": "2026-09-28T21:54:17.256+00:00",
"cancelled_at": null
},
"order": {
"id": "74a3221b-a5dc-4e56-9b9e-2d0c55611bd5",
"order_number": "ORD-1790632457762",
"total_amount": 1548,
"currency": "EUR",
"payment_status": "pending",
"order_status": "pending"
},
"payment": {
"next_step": "POST /v1/payments/initialize",
"initialize_body": {
"order_id": "74a3221b-a5dc-4e56-9b9e-2d0c55611bd5",
"amount": 1548,
"currency": "EUR",
"email": "john.doe@example.com"
},
"methods": [
{
"provider": "cash",
"display_name": "Cash on Delivery",
"type": "manual",
"environment": "production",
"is_configured": true
},
{
"provider": "stripe",
"display_name": "Stripe",
"type": "redirect",
"environment": "test",
"is_configured": true
},
{
"provider": "paypal",
"display_name": "PayPal",
"type": "popup",
"environment": "sandbox",
"is_configured": true
},
{
"provider": "paystack",
"display_name": "Paystack",
"type": "popup",
"environment": "test",
"is_configured": true
}
]
}
},
"evidence": [
{
"source": "pricing",
"operation": "GET /v1/prices/products/{id}",
"id": "fbe89cdf-90a3-4050-a43b-e4c42302484a",
"field": "resolved_price"
},
{
"source": "promotions",
"operation": "POST /v1/promotions/calculate-best",
"field": "discount"
},
{
"source": "shipping",
"operation": "shipping quote",
"field": "fee"
},
{
"source": "tax",
"operation": "POST /v1/tax/preview",
"field": "tax_amount"
},
{
"source": "orders",
"operation": "order create",
"id": "74a3221b-a5dc-4e56-9b9e-2d0c55611bd5",
"field": "total_amount"
},
{
"source": "payments",
"operation": "GET /v1/payments/methods",
"field": "methods"
}
],
"computed_at": "2026-09-28T21:54:23.191Z",
"currency": "EUR",
"environment": "sandbox"
}{
"error": {
"code": "invalid_request",
"message": "A guest confirmation needs contact.email"
}
}{
"error": {
"code": "unauthorized",
"message": "Missing or invalid Authorization header"
}
}{
"error": {
"code": "invalid_token",
"message": "The confirmation token does not match this checkout intent"
}
}{
"error": {
"code": "not_found",
"message": "Checkout intent not found: 00000000-0000-4000-8000-000000000000"
}
}{
"error": {
"code": "quote_changed",
"message": "The price changed since the checkout was prepared. Show the shopper the new quote and create a new intent.",
"details": {
"changes": [
"grand total: 1549 → 1548"
],
"quote": {
"tax": {
"amount": 213.52,
"source": "fallback",
"status": "quoted",
"prices_include_tax": true
},
"lines": [
{
"sku": "FEED-HOODIE-GRY-M",
"name": "Galactic Zip Hoodie",
"stock": 25,
"quantity": 1,
"available": true,
"line_total": 48,
"list_price": 48,
"product_id": "289533e8-f5b6-4d4f-bb23-2127875feb70",
"unit_price": 48,
"variant_id": "fbe89cdf-90a3-4050-a43b-e4c42302484a",
"variant_name": "Grey / M",
"category_name": "Wearables",
"unavailable_reason": null
}
],
"currency": "EUR",
"discount": {
"amount": 0,
"promotion": null
},
"shipping": {
"amount": 1500,
"status": "quoted",
"is_free": false,
"description": "USA",
"free_threshold": 100000
},
"subtotal": 48,
"grand_total": 1548,
"total_is_final": true,
"shipping_address": {
"city": "New York",
"name": "John Doe",
"line1": "350 Fifth Avenue",
"state": "NY",
"country": "US",
"postal_code": "10118"
},
"unavailable_count": 0
}
}
}
}{
"error": {
"code": "rate_limited",
"message": "Too many requests for this API key. Please slow down and try again shortly.",
"remaining": 0,
"reset": 1706198400
}
}{
"error": {
"code": "server_error",
"message": "An unexpected error occurred"
}
}
