# Layout > Layout places real pickup orders at essentially any restaurant, by API or MCP, by driving the > restaurant's own ordering site. No merchant integration, and the person ordering never installs > anything. Partners provision a user, build a cart, and hand off a link where that person adds a > card and confirms. Base URL: https://api.layout.link/v1 — bearer auth, JSON. MCP: https://mcp.layout.link (OAuth, PKCE). Every page below is also available as Markdown at the same path with .md appended. ## Docs - [Layout for Developers](https://developer.layout.link/reference/index.md): Layout API and MCP documentation. - [Quickstart](https://developer.layout.link/reference/quickstart.md): Your first sandbox order, end to end, in about five minutes. Nothing you do here places an order or charges anyone. - [Environments and approval](https://developer.layout.link/reference/environments.md): Sandbox works the minute you create an application. Production needs a human yes from us, and while you wait nothing about your sandbox changes. - [Authentication](https://developer.layout.link/reference/authentication.md): One bearer token on every request. Your secret is the identity, so there is no session to keep, no cookie to carry, and no token exchange to build. - [API reference](https://developer.layout.link/reference/api.md): Five endpoints. Base URL https://api.layout.link/v1, bearer auth on every call, JSON in and out. - [Provisioning users](https://developer.layout.link/reference/provisioning.md): Someone you can order for. You vouch for a name and a phone number; they prove the phone themselves the first time they open the link. - [Ordering over MCP](https://developer.layout.link/reference/mcp.md): Ordering runs over MCP. Mint a build session for a provisioned user, point an MCP client at our server, and drive the order tool. The session builds and reads a cart; the person confirms and pays on Layout’s hosted page. - [Webhooks](https://developer.layout.link/reference/webhooks.md): Layout POSTs a signed event when an order you initiated changes state. Delivery is fire-and-forget with retry, and never delays or alters an order. - [Event types](https://developer.layout.link/reference/events.md): The full catalog of webhook events. The vocabulary carries the truth: order.unconfirmed is first-class, and must never be collapsed into order.failed. - [Errors & status](https://developer.layout.link/reference/errors.md): Layout never claims an order is placed without evidence, and a confident false failure is just as dangerous. Handle the uncertain state deliberately. - [Rate limits and idempotency](https://developer.layout.link/reference/limits.md): Where the ceilings are, when to come back after a 429, and the one field that stops a retry from costing you twice. ## Changelog - [Card-free sandbox builds](https://developer.layout.link/changelog/card-free-sandbox-builds.md): 2026-09-22, Sandbox. Sandbox builds never ask for a card. Each application has its own daily sandbox allowance, and a new Usage page shows what you have used and lets you ask for more. - [Week of September 21](https://developer.layout.link/changelog/week-of-september-21.md): 2026-09-22, Console. Reset a forgotten console password from the sign-in page, and a one-screen Quickstart in the top navigation. - [Orders in the console](https://developer.layout.link/changelog/orders-in-the-console.md): 2026-09-21, Console. A new Orders page lists every order your keys caused in the selected environment, with the outcome in words and the reason when one did not complete. - [Week of September 14](https://developer.layout.link/changelog/week-of-september-14.md): 2026-09-15, Console. A disconnected person can be invited again, the console sends the right link to the right person and explains what it did, console search matches the docs, and four guides were corrected. - [A signing secret per environment](https://developer.layout.link/changelog/a-signing-secret-per-environment.md): 2026-09-13, Webhooks, breaking. Sandbox and production deliveries are now signed with different secrets, and every delivery says which environment it came from. Production verification needs the new production secret. - [Check readiness with whoami](https://developer.layout.link/changelog/check-readiness-with-whoami.md): 2026-09-13, API. GET /v1/whoami says which application and environment a key opens and whether production is approved, so going live is a check instead of a 403. - [Connections that last](https://developer.layout.link/changelog/connections-that-last.md): 2026-09-13, API. A person's connection to your app now survives them signing in to Layout. People who already have Layout can connect by approving you, and Layout texts them the approval link itself. - [Headless phone verification](https://developer.layout.link/changelog/headless-phone-verification.md): 2026-09-13, API. Two new calls let a provisioned person prove their phone without opening a Layout page. Layout texts them a code, they read it to you, and you pass it back. - [Ordering moves to MCP](https://developer.layout.link/changelog/ordering-moves-to-mcp.md): 2026-09-13, MCP, breaking. POST /v1/orders is retired and answers 410. Carts are built over MCP with a build grant, and a build grant session now lists only the three tools it can use. - [Week of September 7](https://developer.layout.link/changelog/week-of-september-7.md): 2026-09-13, Console. Webhook subscriptions open in a side drawer, logo uploads go through, the sandbox test phone cannot be mistyped, and the guides cover cardless builds and connections. - [Builds before a card](https://developer.layout.link/changelog/builds-before-a-card.md): 2026-09-12, API. Someone you just provisioned can see a real, priced cart before they have a card on file, up to a daily allowance set for your application. When a card is needed, Layout's card page names your app. - [Docs for people and agents](https://developer.layout.link/changelog/docs-for-people-and-agents.md): 2026-09-12, Docs. Search that reads every page, an endpoint reference, three new guides, and the whole reference as llms.txt, Markdown twins and an OpenAPI 3.1 file. - [Keys you can read again](https://developer.layout.link/changelog/keys-you-can-read-again.md): 2026-09-12, Console. Client secrets can be revealed on demand instead of once at creation, the console says plainly what your approval status allows, and logos upload as files. - [Send a test webhook](https://developer.layout.link/changelog/send-a-test-webhook.md): 2026-09-12, Webhooks. Send test event fires a real, signed delivery at your endpoint, so you can prove the whole path before a single order exists. - [Why a key was refused](https://developer.layout.link/changelog/why-a-key-was-refused.md): 2026-09-12, Console. The API still answers every refused key with the same sentence. Your console now shows the real reason, which key it was, how many times, and when it last happened. - [Layout for Developers opens](https://developer.layout.link/changelog/developer-platform-opens.md): 2026-09-11, API. Sign up, create an application and build against sandbox the same day. Provision a person, build a real cart for them, and follow every order on signed webhooks. - [Your logo on consent](https://developer.layout.link/changelog/your-logo-on-consent.md): 2026-09-04, MCP. When a person connects an MCP client to Layout through OAuth, the consent screen shows that client's logo beside the Layout mark, drawn from the host its redirect URI points at. ## Optional - [OpenAPI 3.1 specification](https://developer.layout.link/openapi.json): the five REST endpoints, machine-readable. - [Full documentation as one file](https://developer.layout.link/llms-full.txt): every page above, concatenated. - [Changelog feed](https://developer.layout.link/changelog/feed.xml): every change above as Atom, newest first.