# Grants read their own orders

October 2, 2026 · API

Three fixes from developer feedback, plus build time guidance on the Carts page.

## What changed

- **A build grant reads its own orders.** `GET /v1/orders/:id` with a build grant used to answer `403`. It now returns the order when a build grant from your application built it for that same person, in the same environment. Any other order, including one another application built or one built for another person, is a `404`, the same answer as an order that does not exist. See [GET /v1/orders/:id](https://developer.layout.link/reference/api#get-v1-orders-id).
- **whoami lists each scope once.** With your application secret, `GET /v1/whoami` returned `order_status` beside `order:status`. `scopes` is now `["order:preview", "order:build", "order:status", "places"]`. See [GET /v1/whoami](https://developer.layout.link/reference/api#get-v1-whoami).
- **A fired test webhook names its order.** `POST /v1/sandbox/webhooks/fire` with an `orderId` sends that sandbox order's real id, store, item count and total, still with `"test": true`. The response now carries `order`, the id, state and store the event described, so you can see which order was sent. An `orderId` that is not one of your application's sandbox orders is still a `404`. See [Fire a test webhook](https://developer.layout.link/reference/sandbox#fire-a-test-webhook).
- **How long a build takes.** The Carts page now gives typical build times and how to poll: every 2 to 3 seconds, and stop holding the person after about 4 minutes. See [How long a build takes](https://developer.layout.link/reference/carts#build-time).

## Breaking changes

None. If your code looked for the bare `order_status` string in `scopes`, look for `order:status` instead.
