# Codes on first orders

October 2, 2026 · API

A build grant used to need the code Layout texts the person on every live confirm. It now needs it until the person approves an order through your application with it. After that the code is asked for exactly when ordering anywhere else in Layout would ask for it.

## What changed

- Until a person has placed an order through your application with the code Layout texts them, every live confirm needs the code, whatever the total and whatever their own code setting. Only that code counts: an order placed by replying to Layout's text, in the Layout app, or through an OAuth connection does not, and consent to another application does not carry over. It ends when the person disconnects your application, you deprovision them, or they connect again.
- That code's text says what sharing it unlocks: `Sharing this code places the order and lets Acme Assistant place future orders for you without a code. Turn on order codes in Layout to stop that.` It names your application as it appears in the console. Codes Layout texts once the person has consented keep the plain wording.
- After that, a build grant's confirm needs the code when the person keeps codes on, the total is over Layout's amount limit for codes, which can change, Layout's risk checks ask for one, or a code is already out for the cart. Otherwise the confirm without a code answers `202 placing` over REST and `placing` over MCP.
- A build grant's cart reads `codeRequired` from the same rule. `resend-code` on a cart that needs no code answers `409 code_not_needed` and texts nothing.
- A `403 build_only` confirm now carries `error.next`: `step` is `sign_up_required`, `connect_required`, `link_expired`, `phone_required` or `card_required`, and `url`, when present, is the Layout page where the person finishes it. The MCP `confirm` result carries the same `next`.
- Provisioning's `session.expiresIn` now states 900, the 15 minutes a build session lasts.

```
403 {
  "error": {
    "code": "build_only",
    "message": "This person has not finished joining Layout, so the cart cannot be confirmed yet. They need to sign up to Layout with this number and add a card, then you confirm again. Nothing was charged.",
    "orderId": "ord_7c21e4b9a0d3",
    "next": { "step": "sign_up_required", "url": "https://account.layout.link/join" }
  }
}
```

## Why it matters

The first code is how the person agrees to let your application order for them. Once they have, a second small order does not need a text, the same as in the Layout app. And your code can tell the person what to do next without reading the message.

## What to do

Keep calling confirm with no code first, and handle `code_required` on every confirm: the confirm decides. On `build_only`, switch on `error.next.step` and send the person `error.next.url` when there is one. See [Confirming with a build grant](https://developer.layout.link/reference/carts#relayed-code) and [Errors](https://developer.layout.link/reference/errors).

## Breaking changes

None. A confirm that already handles `code_required` and `202 placing` works unchanged. On MCP, a grant's `build_only` confirm result used to carry `next` as the string `"connect"` or `"provision"`; it is now the object above.
