Connecting is agreeing

API

A build grant used to need the person's code on their first order through your application, because that code was how they agreed to let it order for them. The agreement now happens when they connect your application, and Layout says so at that moment. After that, a build grant's confirm asks for the code exactly when ordering anywhere else in Layout would.

What changed

  • The connect screen now says, in Layout's words: Acme Assistant will be able to place orders for you, paid with your Layout card. To approve each order with a code, turn on order codes in Layout. You can disconnect Acme Assistant anytime in Layout. Approving it is the person's agreement.
  • The headless verify text now reads Layout: 123456 links this number to Acme Assistant, which can then place orders for you. It expires in 3 minutes. If you didn't ask for this, ignore this text. Reading that code back to you is the person's agreement. Both name your application as it appears in the console.
  • Once a person has connected, a build grant's confirm needs the code when they keep codes on, the total is over Layout's amount limit for codes, which can change, Layout's risk checks ask for one, or a code is already out for the cart. Otherwise the confirm without a code answers 202 placing over REST and placing over MCP. codeRequired on the cart reads the same rule.
  • People who connected before this change have not agreed yet. Their first order through your application still needs the code, and its text still says that sharing it lets your application place their future orders without one.
  • The agreement ends when the person disconnects your application or you deprovision them. Connecting again gives it again.

Why it matters

The person agrees once, at the moment they choose to connect your application, and is told plainly what that allows. Their first small order then places when they say yes in your product, the same as every order after it.

What to do

Nothing. Keep calling confirm with no code first and handle code_required on every confirm: the confirm decides. See Confirming with a build grant and Provisioning.

Breaking changes

None. A confirm that already handles code_required and 202 placing works unchanged. If your product told people to expect a code on their first order, that is no longer always true.

All changes