Skip to main content

Place Order

Places an order for a listing. This is the endpoint that spends real money, and it is designed around one assumption: a reply can be lost after the order was placed.
Two submissions with the same reference can mean two real purchases unless your system deduplicates on it. reference is a search key for reconciliation, not a guarantee. Retail calls this endpoint once per order and never retries it.

What happens when a call fails

Retail cannot tell “the request never arrived” from “it arrived and the reply was lost”. So any failure here, whether a timeout, a dropped connection or a non-2xx status, is treated the same way: the order becomes unknown, and Retail finds out what happened by calling Search orders with the reference. It only submits again if that search proves no order exists. That makes two things your job:
  1. Make a replay safe. Before placing anything, check whether an order already exists for this reference. If it does, return that order with 200. Never place a second one.
  2. Do not retry internally. If your upstream call fails or times out, return 502 and let Retail search. An internal retry is exactly the double purchase this design exists to prevent.

Body

string
required
Your supplier identifier.
string
required
Retail’s reference for this order. Store it on your order so Search orders can find it. It is the same value the quote carried.
string
required
The listing being bought.
integer
required
Tickets to buy. One of the listing’s splits.
number
required
The per-ticket wholesale price Retail expects to pay, from the listing. Refuse the order if your price is now higher.
string
required
ISO 4217 code for unitCost.
string
required
The signature from the quote this order was priced from. Refuse the order if it does not match: it was priced against a different quote, or none.
number
The retail sales tax from that same quote, for your order record.
string
The price-lock token from the listing, if you issued one.
string
default:"eticket"
The listing’s delivery format, so you can address the order correctly. The same values as on Listings. Taken from the listing at the moment the buyer paid.
object
Where to courier a physical ticket. Present only when format is physical.
string
The buyer’s own email, for a seat transferred into their account. Present only when format is mobile_transfer or flash_seats. The box office moves the seat into the account that owns this mailbox, so it must be the buyer’s real address.

Refuse what you cannot deliver

  • format: "physical" without shippingAddress: refuse with 400. Many systems treat a missing recipient as “ship to the buying account”, which is right for an e-ticket and wrong for a parcel: it ships to Gomry Retail, silently, and the buyer never gets a ticket.
  • mobile_transfer or flash_seats without buyerEmail: refuse with 400. Never fall back to any address of your own or of Gomry’s.
shippingAddress and buyerEmail are the only buyer data that ever reaches your integration. Pass them to your system on this order and nowhere else. Do not store them, and keep them out of logs and error reports.

Response

string
required
Your id for the order. Retail uses it on Fulfilment and Credentials.
string
required
The order’s state in your system right now:
number
required
What Gomry Retail will pay for the whole order.
string
required
ISO 4217 code for totalCost.
any
Your system’s order payload, stored as evidence. Must not echo the shipping address or buyer email.