Order placed
Send an order to Privy when a customer completes a purchase.
Privy uses order_id to decide whether to create or update the order.
The first request for an order_id creates the order and returns 201 Created.
Later requests with the same order_id update it and return 200 OK.
When updating an order, send its latest data. If you leave out an optional
field, Privy keeps its existing value.
Privy links the order to a contact using email. If you do not send an email
address, it uses phone instead. If no matching contact exists, Privy creates one.
accepts_email_marketing can subscribe the contact to email but cannot
unsubscribe an existing contact. accepts_sms_marketing records an SMS opt-in
only for newly created contacts and requires phone. It does not change the SMS
consent of an existing contact.
To associate the order with a specific Custom Integration, include the optional
X-Privy-Integration-Token header. See the header description below for setup
instructions and fallback behavior.
Required scope: orders_write
Authorizations
Send either an API token or an OAuth access token as
Authorization: Bearer <token>. See the Authentication page for details.
Headers
Optional. The integration token of a Custom Integration, sent in addition to
the Authorization: Bearer token, to tie the order to that specific
integration. Find it in your Privy dashboard under
Settings → Integrations Hub → Connected, or generate a new one in the
same Integrations Hub section under Custom Integration.
When omitted and the business has exactly one Custom Integration, the order
is auto-tied to it; otherwise no integration is attributed. If the value
doesn't match an active Custom Integration for your business, the request
returns 422. This token only narrows attribution within the business
already established by the bearer token — it is not a standalone credential.
Body
order_id, total, currency, and order_date are required on every call,
plus at least one of email or phone. All other fields are optional;
on an update, omitted optional fields keep their previously stored value.
Your unique identifier for the order. Must be a positive integer (a digits-only string is also accepted).
This is the idempotency key: the first call for an order_id creates the order, subsequent calls update it.
1001
Order grand total. Required.
95
ISO 4217 three-letter currency code. Required.
"USD"
ISO 8601 date-time the order was placed. Required. Expected to be in UTC
(zero offset) — end the timestamp with Z (e.g. 2026-06-01T12:00:00Z).
"2026-06-01T12:00:00Z"
Buyer's email. Used to find or create the associated contact.
At least one of email or phone is required.
"buyer@example.com"
Buyer's phone number. Loosely formatted input is accepted and normalized to E.164.
Required when accepts_sms_marketing is true.
"+12025550123"
Your external identifier for the customer.
"ext-42"
Order subtotal before tax, shipping, and discounts.
90
Discounts applied to the order.
Tax lines applied to the order.
Total number of items in the order.
2
Payment status of the order.
authorized, expired, paid, partially_paid, partially_refunded, pending, refunded, voided "paid"
The order's overall fulfillment state (mirrors Shopify's OrderDisplayFulfillmentStatus).
Stored on the order but does not affect delivery-based flow triggers — use shipment_status for that.
fulfilled, in_progress, on_hold, open, partially_fulfilled, pending, pending_fulfillment, request_declined, restocked, scheduled, unfulfilled "fulfilled"
Carrier delivery status of the shipment (mirrors Shopify's FulfillmentEventStatus).
Setting this to delivered triggers any "Order Received" flows for the customer.
attempted_delivery, carrier_picked_up, confirmed, delayed, delivered, failure, in_transit, label_printed, label_purchased, out_for_delivery, picked_up, ready_for_pickup "delivered"
The products purchased.
A billing or shipping address. Stored and echoed back verbatim.
When a new contact is created, its name is taken from the address —
shipping first, billing as fallback — using first_name/last_name,
or a single name field split on whitespace.
A billing or shipping address. Stored and echoed back verbatim.
When a new contact is created, its name is taken from the address —
shipping first, billing as fallback — using first_name/last_name,
or a single name field split on whitespace.
Whether the buyer opted into email marketing. Subscribes the contact on signup; never unsubscribes an existing contact.
true
Whether the buyer opted into SMS marketing. Requires phone.
Records an SMS opt-in for newly created contacts only;
existing contacts' SMS consent is left untouched.
true
Set to true for bulk historical imports. Suppresses real-time side effects
(Flows and other automations, and campaign-revenue attribution) while still
recording the order, associating the contact, and updating the contact's
order_count, first_order_at, and last_order_at values.
false
Response
Existing order updated.
An order as persisted. Echoes back the fields you sent (column-backed fields normalized, the rest verbatim). Empty values are omitted from the response.