curl --request POST \
--url https://app.sideshift.app/api/commerce/orders \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"orderId": "order-1042",
"visitorId": "8ac8d41e-8e6e-433c-bec7-19c4e027f2e7",
"totalCents": 6500,
"refundedCents": 0,
"currency": "USD",
"occurredAt": "2026-09-11T12:30:00.000Z",
"status": "paid",
"items": [
{
"productId": "shirt-blue",
"title": "Blue shirt",
"quantity": 2,
"priceCents": 3250
}
]
}
'import requests
url = "https://app.sideshift.app/api/commerce/orders"
payload = {
"orderId": "order-1042",
"visitorId": "8ac8d41e-8e6e-433c-bec7-19c4e027f2e7",
"totalCents": 6500,
"refundedCents": 0,
"currency": "USD",
"occurredAt": "2026-09-11T12:30:00.000Z",
"status": "paid",
"items": [
{
"productId": "shirt-blue",
"title": "Blue shirt",
"quantity": 2,
"priceCents": 3250
}
]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
orderId: 'order-1042',
visitorId: '8ac8d41e-8e6e-433c-bec7-19c4e027f2e7',
totalCents: 6500,
refundedCents: 0,
currency: 'USD',
occurredAt: '2026-09-11T12:30:00.000Z',
status: 'paid',
items: [{productId: 'shirt-blue', title: 'Blue shirt', quantity: 2, priceCents: 3250}]
})
};
fetch('https://app.sideshift.app/api/commerce/orders', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.sideshift.app/api/commerce/orders",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'orderId' => 'order-1042',
'visitorId' => '8ac8d41e-8e6e-433c-bec7-19c4e027f2e7',
'totalCents' => 6500,
'refundedCents' => 0,
'currency' => 'USD',
'occurredAt' => '2026-09-11T12:30:00.000Z',
'status' => 'paid',
'items' => [
[
'productId' => 'shirt-blue',
'title' => 'Blue shirt',
'quantity' => 2,
'priceCents' => 3250
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.sideshift.app/api/commerce/orders"
payload := strings.NewReader("{\n \"orderId\": \"order-1042\",\n \"visitorId\": \"8ac8d41e-8e6e-433c-bec7-19c4e027f2e7\",\n \"totalCents\": 6500,\n \"refundedCents\": 0,\n \"currency\": \"USD\",\n \"occurredAt\": \"2026-09-11T12:30:00.000Z\",\n \"status\": \"paid\",\n \"items\": [\n {\n \"productId\": \"shirt-blue\",\n \"title\": \"Blue shirt\",\n \"quantity\": 2,\n \"priceCents\": 3250\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.sideshift.app/api/commerce/orders")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"orderId\": \"order-1042\",\n \"visitorId\": \"8ac8d41e-8e6e-433c-bec7-19c4e027f2e7\",\n \"totalCents\": 6500,\n \"refundedCents\": 0,\n \"currency\": \"USD\",\n \"occurredAt\": \"2026-09-11T12:30:00.000Z\",\n \"status\": \"paid\",\n \"items\": [\n {\n \"productId\": \"shirt-blue\",\n \"title\": \"Blue shirt\",\n \"quantity\": 2,\n \"priceCents\": 3250\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.sideshift.app/api/commerce/orders")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"orderId\": \"order-1042\",\n \"visitorId\": \"8ac8d41e-8e6e-433c-bec7-19c4e027f2e7\",\n \"totalCents\": 6500,\n \"refundedCents\": 0,\n \"currency\": \"USD\",\n \"occurredAt\": \"2026-09-11T12:30:00.000Z\",\n \"status\": \"paid\",\n \"items\": [\n {\n \"productId\": \"shirt-blue\",\n \"title\": \"Blue shirt\",\n \"quantity\": 2,\n \"priceCents\": 3250\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"accepted": true,
"duplicate": false,
"orderId": "9ec67b93-ed49-49d6-aa0e-c420d9498673"
}{
"error": "<string>"
}{
"error": "<string>"
}{
"error": "<string>"
}{
"error": "<string>"
}{
"error": "<string>"
}{
"error": "<string>"
}{
"error": "<string>"
}{
"error": "<string>"
}Submit or update a verified order
Call from a trusted server after payment verification. Maximum 256 KiB; 600 requests per minute per store. Order identity is unique within the authenticated store. Preserve original purchase fields on retries and refunds. There is no dry-run parameter.
curl --request POST \
--url https://app.sideshift.app/api/commerce/orders \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"orderId": "order-1042",
"visitorId": "8ac8d41e-8e6e-433c-bec7-19c4e027f2e7",
"totalCents": 6500,
"refundedCents": 0,
"currency": "USD",
"occurredAt": "2026-09-11T12:30:00.000Z",
"status": "paid",
"items": [
{
"productId": "shirt-blue",
"title": "Blue shirt",
"quantity": 2,
"priceCents": 3250
}
]
}
'import requests
url = "https://app.sideshift.app/api/commerce/orders"
payload = {
"orderId": "order-1042",
"visitorId": "8ac8d41e-8e6e-433c-bec7-19c4e027f2e7",
"totalCents": 6500,
"refundedCents": 0,
"currency": "USD",
"occurredAt": "2026-09-11T12:30:00.000Z",
"status": "paid",
"items": [
{
"productId": "shirt-blue",
"title": "Blue shirt",
"quantity": 2,
"priceCents": 3250
}
]
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
orderId: 'order-1042',
visitorId: '8ac8d41e-8e6e-433c-bec7-19c4e027f2e7',
totalCents: 6500,
refundedCents: 0,
currency: 'USD',
occurredAt: '2026-09-11T12:30:00.000Z',
status: 'paid',
items: [{productId: 'shirt-blue', title: 'Blue shirt', quantity: 2, priceCents: 3250}]
})
};
fetch('https://app.sideshift.app/api/commerce/orders', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.sideshift.app/api/commerce/orders",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'orderId' => 'order-1042',
'visitorId' => '8ac8d41e-8e6e-433c-bec7-19c4e027f2e7',
'totalCents' => 6500,
'refundedCents' => 0,
'currency' => 'USD',
'occurredAt' => '2026-09-11T12:30:00.000Z',
'status' => 'paid',
'items' => [
[
'productId' => 'shirt-blue',
'title' => 'Blue shirt',
'quantity' => 2,
'priceCents' => 3250
]
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.sideshift.app/api/commerce/orders"
payload := strings.NewReader("{\n \"orderId\": \"order-1042\",\n \"visitorId\": \"8ac8d41e-8e6e-433c-bec7-19c4e027f2e7\",\n \"totalCents\": 6500,\n \"refundedCents\": 0,\n \"currency\": \"USD\",\n \"occurredAt\": \"2026-09-11T12:30:00.000Z\",\n \"status\": \"paid\",\n \"items\": [\n {\n \"productId\": \"shirt-blue\",\n \"title\": \"Blue shirt\",\n \"quantity\": 2,\n \"priceCents\": 3250\n }\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.sideshift.app/api/commerce/orders")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"orderId\": \"order-1042\",\n \"visitorId\": \"8ac8d41e-8e6e-433c-bec7-19c4e027f2e7\",\n \"totalCents\": 6500,\n \"refundedCents\": 0,\n \"currency\": \"USD\",\n \"occurredAt\": \"2026-09-11T12:30:00.000Z\",\n \"status\": \"paid\",\n \"items\": [\n {\n \"productId\": \"shirt-blue\",\n \"title\": \"Blue shirt\",\n \"quantity\": 2,\n \"priceCents\": 3250\n }\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.sideshift.app/api/commerce/orders")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"orderId\": \"order-1042\",\n \"visitorId\": \"8ac8d41e-8e6e-433c-bec7-19c4e027f2e7\",\n \"totalCents\": 6500,\n \"refundedCents\": 0,\n \"currency\": \"USD\",\n \"occurredAt\": \"2026-09-11T12:30:00.000Z\",\n \"status\": \"paid\",\n \"items\": [\n {\n \"productId\": \"shirt-blue\",\n \"title\": \"Blue shirt\",\n \"quantity\": 2,\n \"priceCents\": 3250\n }\n ]\n}"
response = http.request(request)
puts response.read_body{
"accepted": true,
"duplicate": false,
"orderId": "9ec67b93-ed49-49d6-aa0e-c420d9498673"
}{
"error": "<string>"
}{
"error": "<string>"
}{
"error": "<string>"
}{
"error": "<string>"
}{
"error": "<string>"
}{
"error": "<string>"
}{
"error": "<string>"
}{
"error": "<string>"
}Authorizations
Store-specific secret generated in Website & sales. Never expose in browser code.
Body
Stable identifier, trimmed before validation.
1 - 200SideShift visitor ID captured at checkout. Required for this custom-store endpoint.
^[a-zA-Z0-9_-]{16,128}$Amount in the currency minor unit, despite the Cents suffix.
0 <= x <= 100000000000Supported uppercase ISO 4217 currency code.
"USD"
Original payment time in UTC. Cannot exceed current time by more than five minutes. Keep unchanged on refunds and retries.
Cumulative refunded amount, at most totalCents. Never decreases on replay.
0 <= x <= 100000000000A refunded order requires refundedCents equal to totalCents. Cancellation cannot be undone by replay.
paid, partially_refunded, refunded, cancelled Sample orders do not earn commissions or send managed advertising purchases. Once true, cannot be undone by replay.
Optional stable checkout correlation token.
16 - 200Order line items.
500Show child attributes
Show child attributes
Optional context returned by getAdvertisingContextAsync(). This identity differs from the top-level SideShift visitor ID.
Show child attributes
Show child attributes
Response
Accepted. duplicate is true for both replays and updates to existing orders. Acceptance does not guarantee creator attribution, payout, or advertising delivery.