Confirm with the cart's total
expectedTotalMinor on POST /v1/carts/:id/confirm must be the cart's totalMinor. A confirm that sends the restaurant's total alone (fees.merchantTotalMinor) while Layout's service fee applies now answers 400 invalid_request, and nothing is confirmed or charged. When the fee is waived, the two totals are the same and either confirms.
Why it matters
The person's card is charged totalMinor. A confirm with a smaller number used to go through, so an app could show the restaurant's total, confirm it, and charge the person more than they saw.
What to do
Show the person the cart's totalMinor and send it back unchanged as expectedTotalMinor. If the price moved, the answer is still 409 price_changed.
Breaking changes
A confirm that sent fees.merchantTotalMinor now fails with 400 invalid_request. The reference has always asked for totalMinor. The MCP order tool is unchanged.