Grants read their own orders
Three fixes from developer feedback, plus build time guidance on the Carts page.
What changed
- A build grant reads its own orders.
GET /v1/orders/:idwith a build grant used to answer403. It now returns the order when a build grant from your application built it for that same person, in the same environment. Any other order, including one another application built or one built for another person, is a404, the same answer as an order that does not exist. See GET /v1/orders/:id. - whoami lists each scope once. With your application secret,
GET /v1/whoamireturnedorder_statusbesideorder:status.scopesis now["order:preview", "order:build", "order:status", "places"]. See GET /v1/whoami. - A fired test webhook names its order.
POST /v1/sandbox/webhooks/firewith anorderIdsends that sandbox order's real id, store, item count and total, still with"test": true. The response now carriesorder, the id, state and store the event described, so you can see which order was sent. AnorderIdthat is not one of your application's sandbox orders is still a404. See Fire a test webhook. - How long a build takes. The Carts page now gives typical build times and how to poll: every 2 to 3 seconds, and stop holding the person after about 4 minutes. See How long a build takes.
Breaking changes
None. If your code looked for the bare order_status string in scopes, look for order:status instead.