Skip to content

Read the merchant's terms

GET/v1/config

What a plugin reads on install to verify itself and render a badge. Call it once and cache what it returns.

Authentication — X-Client-Id and X-Api-Key.

This answers 200 even when layaway is unavailable. An install check asking "can I sell?" needs to be told why not, so read layaway.available rather than treating the status code as the answer.

terms is the range this merchant may sell in. Checking a cart against it locally keeps an out-of-bounds order from ever reaching session create.

Request

No parameters.

curl "$SHOTPAY_URL/v1/config" \
  -H "X-Client-Id: $SHOTPAY_CLIENT_ID" \
  -H "X-Api-Key: $SHOTPAY_API_KEY"
$config = Http::withHeaders([
    'X-Client-Id' => config('shotpay.client_id'),
    'X-Api-Key' => config('shotpay.api_key'),
])->get(config('shotpay.url').'/v1/config')->json('data');

cache()->put('shotpay.terms', $config['terms'], now()->addHour());

Response

200 OK

{
  "data": {
    "merchant": {
      "client_id": "mch_test_7fL2qXn4WbTzR9kD1sVyH6mCgA8eUpJ3",
      "legal_name": "Frontier Firearms LLC",
      "dba": "Frontier Range"
    },
    "mode": "sandbox",
    "layaway": { "available": true, "reason": null, "message": null },
    "terms": {
      "min_order_amount": 5000,
      "max_order_amount": 600000,
      "down_payment_percentage": 25
    },
    "session_ttl_minutes": 60
  }
}
Field Type Notes
merchant.client_id string
merchant.legal_name string
merchant.dba string or null Use it for display where it is set; fall back to the legal name.
mode enum Which half of the account this key runs in.
layaway Layaway Availability
terms.min_order_amount integer Integer cents.
terms.max_order_amount integer Integer cents.
terms.down_payment_percentage integer The share of the order total collected at checkout.
session_ttl_minutes integer How long a new session stays open before it lapses.

Errors

Status When
401 The key is missing, unknown, or revoked.
403 The merchant is not cleared to transact.
429 Rate limited. Back off for Retry-After seconds.

See Error Handling.