# Carts over REST

October 1, 2026 · API

The cart endpoints are part of [Introducing the REST API](https://developer.layout.link/changelog/introducing-the-rest-api), which walks through a whole order. This is the short version, for the cart calls alone.

## What changed

## The code

A live confirm asks for the 6-digit code Layout texts the person only when the person keeps codes on, the restaurant's total is over $50, Layout's risk checks ask for one, or a code is already out for this cart. Otherwise one confirm call places it. When a code is needed, confirm answers `400 code_required`, and you send the same request again with `code`.

## Who can confirm

A connected person's token confirms, resends and cancels. A live build grant builds and reads, and is refused `403 build_only` on confirm and cancel: the person confirms in Layout. In sandbox a grant's confirm is a simulation that places and charges nothing.

## What to do

Nothing, if you build over MCP. To use REST, read [Carts](https://developer.layout.link/reference/carts).

## Breaking changes

None. These are new endpoints.
