> This page is for Afterpay Online Developer, version v1.
> For other versions, use one of these documentation indexes:
> - Main (default): https://developers.afterpay.com/afterpay-online-developer/main/llms.txt
> - v1: https://developers.afterpay.com/afterpay-online-developer/v-1/llms.txt
> - Chinese: https://developers.afterpay.com/afterpay-online-developer/chinese/llms.txt

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://developers.afterpay.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://developers.afterpay.com/_mcp/server.

# Create Order

POST https://global-api-sandbox.afterpay.com/v1/orders/environment:{environment}
Content-Type: application/json

This endpoint creates an order that is used to initiate the Afterpay payment process. Afterpay uses the information in the order request to assist with the consumer’s pre-approval process.

**Warning**: The API Simulator includes form elements for both required and optional Body Params. If not populated with values, Readme will send empty strings to the Afterpay Online API. Any optional parameter that is validated against a Model will need to have all of its required sub-params populated with non-empty values. Therefore, to avoid receiving unexpected "400" responses from Afterpay, please fill out all fields of the simulation form with valid values. This is particularly important for the `amount` and `currency` sub-params of the `totalAmount`, `taxAmount` and `shippingAmount` params.

**Note**: It is not possible to update the order information (including `totalAmount`) after the order token is generated. If the consumer's cart changes on the merchant side after a token is generated, please discard this token. Use the current order information to generate a new order token. Use the new token to send the consumer through the Afterpay screenflow before attempting to Capture Payment.

### Connection Timeouts
| Timeout |	Time (Seconds) |
| ------- | ------------ |
| Open |	10 |
| Read	| 20 |

Reference: https://developers.afterpay.com/afterpay-online-developer/v-1/api-reference/orders/create-order

## Authentication

- `Authorization` header (basic auth, required) — Basic authentication of the form `Basic <base64(username:password)>`.

## Request

### Path parameters

- `environment` (string, required) — Use `api-sandbox` for AU/NZ, or `api.us-sandbox` for US.

### Headers

- `Accept` (string, optional, default: application/json)

### Body (application/json)

This endpoint expects an object.

- `totalAmount` (V1OrdersEnvironmentEnvironmentPostRequestBodyContentApplicationJsonSchemaTotalAmount, required) — Total amount for order to be charged to consumer.
- `consumer` (V1OrdersEnvironmentEnvironmentPostRequestBodyContentApplicationJsonSchemaConsumer, required) — The consumer requesting the order.
- `billing` (V1OrdersEnvironmentEnvironmentPostRequestBodyContentApplicationJsonSchemaBilling, optional) — Billing address.
- `shipping` (V1OrdersEnvironmentEnvironmentPostRequestBodyContentApplicationJsonSchemaShipping, optional) — Shipping address.
- `courier` (V1OrdersEnvironmentEnvironmentPostRequestBodyContentApplicationJsonSchemaCourier, optional) — Shipping Courier details.
- `description` (string, optional) — A description of the order.
- `items` (list of V1OrdersEnvironmentEnvironmentPostRequestBodyContentApplicationJsonSchemaItemsItems, optional) — An array of order items.
- `discounts` (list of V1OrdersEnvironmentEnvironmentPostRequestBodyContentApplicationJsonSchemaDiscountsItems, optional) — An array of discounts.
- `merchant` (V1OrdersEnvironmentEnvironmentPostRequestBodyContentApplicationJsonSchemaMerchant, optional)
- `merchantReference` (string, optional) — The merchant’s id/reference that this order corresponds to.
- `taxAmount` (V1OrdersEnvironmentEnvironmentPostRequestBodyContentApplicationJsonSchemaTaxAmount, optional) — The included tax amount after applying all discounts.
- `shippingAmount` (V1OrdersEnvironmentEnvironmentPostRequestBodyContentApplicationJsonSchemaShippingAmount, optional) — The shipping amount.

## Response

### 201

Returns a token and expiry date/time if successful. | Attribute | Type | Description | | --------- | ---- | ----------- | | expires | string | The UTC timestamp of when the order token will expire, in [ISO 8601](http://www.iso.org/iso/home/standards/iso8601.htm) format. | | token | string | Order token to be used to complete payment. |

## Errors

### 422 Unprocessable Entity Error

| HTTP Status Code | errorCode | Description | | ---------------- | --------- | ----------- | | Unprocessable Entity | `unsupported_payment_type` | The `totalAmount` is outside of the merchant's payment range for Afterpay, as returned by Get Configuration. | | Unprocessable Entity | `unsupported_currency` | One or more Money objects contained a currency that differs from the merchant's account currency. |

- `any`

## Types

### V1OrdersEnvironmentEnvironmentPostRequestBodyContentApplicationJsonSchemaTotalAmount

Total amount for order to be charged to consumer.

- `amount` (string, required, default: 0.00) — The amount as a string representation of a decimal number, rounded to 2 decimal places.
- `currency` (string, required) — The currency in [ISO 4217](https://en.wikipedia.org/wiki/ISO_4217) format. Supported values include "AUD", "NZD" and "USD". However, the value provided must correspond to the currency of the Merchant account making the request.

### V1OrdersEnvironmentEnvironmentPostRequestBodyContentApplicationJsonSchemaConsumer

The consumer requesting the order.

- `givenNames` (string, required, default: Joe) — The consumer’s first name and any middle names. Limited to 128 characters.
- `surname` (string, required, default: Consumer) — The consumer’s last name. Limited to 128 characters.
- `email` (string, required, default: test@example.com) — The consumer’s email address. Limited to 128 characters.
- `phoneNumber` (string, optional) — The consumer’s phone number. Limited to 32 characters.

### V1OrdersEnvironmentEnvironmentPostRequestBodyContentApplicationJsonSchemaBilling

Billing address.

- `name` (string, required, default: Joe Consumer) — Full name of contact. Limited to 255 characters.
- `line1` (string, required, default: 123 Fake Street) — First line of the address. Limited to 128 characters.
- `postcode` (string, required, default: 0000) — [ZIP](https://en.wikipedia.org/wiki/ZIP_Code) or [postal code](https://en.wikipedia.org/wiki/Postal_code). Limited to 128 characters.
- `line2` (string, optional) — Second line of the address. Limited to 128 characters.
- `suburb` (string, optional) — City or suburb name. Limited to 128 characters.
- `state` (string, optional) — State (or Town/City for NZ). Limited to 128 characters.
- `countryCode` (string, optional) — The two-character [ISO 3166-1](https://en.wikipedia.org/wiki/ISO_3166-1) country code.
- `phoneNumber` (string, optional) — The phone number, in [E.123](https://en.wikipedia.org/wiki/E.123) format. Limited to 32 characters.

### V1OrdersEnvironmentEnvironmentPostRequestBodyContentApplicationJsonSchemaShipping

Shipping address.

- `name` (string, required, default: Joe Consumer) — Full name of contact. Limited to 255 characters.
- `line1` (string, required, default: 123 Fake Street) — First line of the address. Limited to 128 characters.
- `postcode` (string, required, default: 0000) — [ZIP](https://en.wikipedia.org/wiki/ZIP_Code) or [postal code](https://en.wikipedia.org/wiki/Postal_code). Limited to 128 characters.
- `line2` (string, optional) — Second line of the address. Limited to 128 characters.
- `suburb` (string, optional) — City or suburb name. Limited to 128 characters.
- `state` (string, optional) — State (or Town/City for NZ). Limited to 128 characters.
- `countryCode` (string, optional) — The two-character [ISO 3166-1](https://en.wikipedia.org/wiki/ISO_3166-1) country code.
- `phoneNumber` (string, optional) — The phone number, in [E.123](https://en.wikipedia.org/wiki/E.123) format. Limited to 32 characters.

### V1OrdersEnvironmentEnvironmentPostRequestBodyContentApplicationJsonSchemaCourier

Shipping Courier details.

- `shippedAt` (string, optional) — The time at which the order was shipped, in [ISO 8601](http://www.iso.org/iso/home/standards/iso8601.htm) format.
- `name` (string, optional) — The name of the courier. Limited to 128 characters.
- `tracking` (string, optional) — The tracking number provided by the courier. Limited to 128 characters.
- `priority` (string, optional) — The shipping priority. If provided, must be either "STANDARD" or "EXPRESS".

### V1OrdersEnvironmentEnvironmentPostRequestBodyContentApplicationJsonSchemaItemsItems

- `name` (string, required) — Product name. Limited to 255 characters.
- `quantity` (integer, required) — The quantity of the item, stored as a signed 32-bit integer.
- `sku` (string, optional) — Product SKU. Limited to 128 characters.
- `price` (V1OrdersEnvironmentEnvironmentPostRequestBodyContentApplicationJsonSchemaItemsItemsPrice, optional) — The unit price of the individual item. Must be a positive value.

### V1OrdersEnvironmentEnvironmentPostRequestBodyContentApplicationJsonSchemaDiscountsItems

- `displayName` (string, required) — A display name for the discount. Limited to 128 characters.
- `amount` (V1OrdersEnvironmentEnvironmentPostRequestBodyContentApplicationJsonSchemaDiscountsItemsAmount, optional) — The discount amount.

### V1OrdersEnvironmentEnvironmentPostRequestBodyContentApplicationJsonSchemaMerchant

- `redirectConfirmUrl` (string, required, default: https://example.com/checkout/confirm) — The consumer is redirected to this URL on confirmation.
- `redirectCancelUrl` (string, required, default: https://example.com/checkout/cancel) — The consumer to redirected to this URL if the payment process is cancelled.

### V1OrdersEnvironmentEnvironmentPostRequestBodyContentApplicationJsonSchemaTaxAmount

The included tax amount after applying all discounts.

- `amount` (string, required, default: 0.00) — The amount as a string representation of a decimal number, rounded to 2 decimal places.
- `currency` (string, required) — The currency in [ISO 4217](https://en.wikipedia.org/wiki/ISO_4217) format. Supported values include "AUD", "NZD" and "USD". However, the value provided must correspond to the currency of the Merchant account making the request.

### V1OrdersEnvironmentEnvironmentPostRequestBodyContentApplicationJsonSchemaShippingAmount

The shipping amount.

- `amount` (string, required, default: 0.00) — The amount as a string representation of a decimal number, rounded to 2 decimal places.
- `currency` (string, required) — The currency in [ISO 4217](https://en.wikipedia.org/wiki/ISO_4217) format. Supported values include "AUD", "NZD" and "USD". However, the value provided must correspond to the currency of the Merchant account making the request.

### V1OrdersEnvironmentEnvironmentPostRequestBodyContentApplicationJsonSchemaItemsItemsPrice

The unit price of the individual item. Must be a positive value.

- `amount` (string, required, default: 0.00) — The amount as a string representation of a decimal number, rounded to 2 decimal places.
- `currency` (string, required) — The currency in [ISO 4217](https://en.wikipedia.org/wiki/ISO_4217) format. Supported values include "AUD", "NZD" and "USD". However, the value provided must correspond to the currency of the Merchant account making the request.

### V1OrdersEnvironmentEnvironmentPostRequestBodyContentApplicationJsonSchemaDiscountsItemsAmount

The discount amount.

- `amount` (string, required, default: 0.00) — The amount as a string representation of a decimal number, rounded to 2 decimal places.
- `currency` (string, required) — The currency in [ISO 4217](https://en.wikipedia.org/wiki/ISO_4217) format. Supported values include "AUD", "NZD" and "USD". However, the value provided must correspond to the currency of the Merchant account making the request.

## Examples

**Request**

```json
{
  "totalAmount": {
    "amount": "0.00",
    "currency": "string"
  },
  "consumer": {
    "givenNames": "Joe",
    "surname": "Consumer",
    "email": "test@example.com"
  }
}
```

**Response**

```json
{}
```

**SDK Code**

```python
import requests

url = "https://global-api-sandbox.afterpay.com/v1/orders/environment:environment"

payload = {
    "totalAmount": {
        "amount": "0.00",
        "currency": "string"
    },
    "consumer": {
        "givenNames": "Joe",
        "surname": "Consumer",
        "email": "test@example.com"
    }
}
headers = {
    "User-Agent": "User-Agent"
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers, auth=("<username>", "<password>"))

print(response.json())
```

```javascript
const url = 'https://global-api-sandbox.afterpay.com/v1/orders/environment:environment';
const credentials = btoa("<username>:<password>");

const options = {
  method: 'POST',
  headers: {
    'User-Agent': 'User-Agent',
    Authorization: `Basic ${credentials}`,
    'Content-Type': 'application/json'
  },
  body: '{"totalAmount":{"amount":"0.00","currency":"string"},"consumer":{"givenNames":"Joe","surname":"Consumer","email":"test@example.com"}}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://global-api-sandbox.afterpay.com/v1/orders/environment:environment"

	payload := strings.NewReader("{\n  \"totalAmount\": {\n    \"amount\": \"0.00\",\n    \"currency\": \"string\"\n  },\n  \"consumer\": {\n    \"givenNames\": \"Joe\",\n    \"surname\": \"Consumer\",\n    \"email\": \"test@example.com\"\n  }\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("User-Agent", "User-Agent")
	req.SetBasicAuth("<username>", "<password>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby
require 'uri'
require 'net/http'

url = URI("https://global-api-sandbox.afterpay.com/v1/orders/environment:environment")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["User-Agent"] = 'User-Agent'
request.basic_auth("<username>", "<password>")
request["Content-Type"] = 'application/json'
request.body = "{\n  \"totalAmount\": {\n    \"amount\": \"0.00\",\n    \"currency\": \"string\"\n  },\n  \"consumer\": {\n    \"givenNames\": \"Joe\",\n    \"surname\": \"Consumer\",\n    \"email\": \"test@example.com\"\n  }\n}"

response = http.request(request)
puts response.read_body
```

```java
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://global-api-sandbox.afterpay.com/v1/orders/environment:environment")
  .header("User-Agent", "User-Agent")
  .basicAuth("<username>", "<password>")
  .header("Content-Type", "application/json")
  .body("{\n  \"totalAmount\": {\n    \"amount\": \"0.00\",\n    \"currency\": \"string\"\n  },\n  \"consumer\": {\n    \"givenNames\": \"Joe\",\n    \"surname\": \"Consumer\",\n    \"email\": \"test@example.com\"\n  }\n}")
  .asString();
```

```php
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://global-api-sandbox.afterpay.com/v1/orders/environment:environment', [
  'body' => '{
  "totalAmount": {
    "amount": "0.00",
    "currency": "string"
  },
  "consumer": {
    "givenNames": "Joe",
    "surname": "Consumer",
    "email": "test@example.com"
  }
}',
  'headers' => [
    'Content-Type' => 'application/json',
    'User-Agent' => 'User-Agent',
  ],
    'auth' => ['<username>', '<password>'],
]);

echo $response->getBody();
```

```csharp
using RestSharp;
using RestSharp.Authenticators;

var client = new RestClient("https://global-api-sandbox.afterpay.com/v1/orders/environment:environment");
client.Authenticator = new HttpBasicAuthenticator("<username>", "<password>");
var request = new RestRequest(Method.POST);
request.AddHeader("User-Agent", "User-Agent");

request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"totalAmount\": {\n    \"amount\": \"0.00\",\n    \"currency\": \"string\"\n  },\n  \"consumer\": {\n    \"givenNames\": \"Joe\",\n    \"surname\": \"Consumer\",\n    \"email\": \"test@example.com\"\n  }\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift
import Foundation

let credentials = Data("<username>:<password>".utf8).base64EncodedString()

let headers = [
  "User-Agent": "User-Agent",
  "Authorization": "Basic \(credentials)",
  "Content-Type": "application/json"
]
let parameters = [
  "totalAmount": [
    "amount": "0.00",
    "currency": "string"
  ],
  "consumer": [
    "givenNames": "Joe",
    "surname": "Consumer",
    "email": "test@example.com"
  ]
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://global-api-sandbox.afterpay.com/v1/orders/environment:environment")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```