# Storefront · Cart

Part of AppEngine API Documentation. Full index: https://appengine.appmint.io/documentation.md
## GET /storefront/cart/get/{authorid}/{cartid}

**Get a cart**

`operationId: StorefrontController_cart`

Returns a cart with its items and computed totals.

**The `authorid` segment is ignored.** The handler resolves the cart from `cartid` and the authenticated caller only — the path parameter is a historical artefact. It is still required by the route, so pass any non-empty value, but do not expect it to scope the lookup.

#### Signature

```http
GET /storefront/cart/get/{authorid}/{cartid} (authorid: string, cartid: string) -> The cart with items and totals
```

#### Access

Public — no credentials required.

#### Notes

- Because `authorid` is not used, do not rely on it to isolate carts between customers.

#### Errors

Plus the standard platform errors: `429`, `500`.

#### See also

- `POST /storefront/cart/update/{cartid}`
- `POST /storefront/checkout-cart`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |
| `cartid` | path | string | yes | Cart id. Optional segment — omitted resolves the caller's current cart. |
| `authorid` | path | string | yes | Ignored by the handler. Required by the route; pass the customer id for readability. |

### Responses

| Status | Meaning |
| --- | --- |
| `200` | The cart with items and totals |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

## POST /storefront/cart/update/{cartid}

**Update a cart**

`operationId: StorefrontController_cartUpdate`

Writes the cart contents and recomputes subtotal, discount, tax and total. This is the single mutation endpoint for carts — adding, changing quantity and removing a line are all expressed as an updated `items` array.

Send a coupon with `couponCode` to have it validated and applied as part of the same call.

#### Signature

```http
POST /storefront/cart/update/{cartid} (cartid: string, body) -> The updated cart with recomputed totals
```

#### Access

Public — no credentials required.

#### Notes

- `items` replaces the stored array rather than merging. Read the cart, modify the list, send it back.

#### Errors

| Status | Code | Message | When | What to do |
| --- | --- | --- | --- | --- |
| `404` | CART_NOT_FOUND | Cart not found | No cart in the org has that id. | Create a cart by updating one with a new id, or re-read the customer's cart. |

Plus the standard platform errors: `429`, `500`.

#### See also

- `GET /storefront/cart/get/{authorid}/{cartid}`
- `GET /storefront/cart/clear/{cartid}`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |
| `cartid` | path | string | yes | Cart id. |

### Request body

The cart contents to store.

```json
{
  "items": [
    {
      "sku": "DRK-COLA-330",
      "quantity": 2,
      "price": 12
    }
  ]
}
```

### Responses

| Status | Meaning |
| --- | --- |
| `201` | The updated cart with recomputed totals |
| `404` | Cart not found — No cart in the org has that id. |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

## GET /storefront/cart/clear/{cartid}

**Clear a cart**

`operationId: StorefrontController_cartClear`

Empties the cart, leaving the record in place so the same id stays usable.

This mutation is mounted on `GET`, so anything that follows links — a crawler, a link preview, a browser prefetch — can empty a customer's cart. Do not expose the URL where it may be fetched automatically.

#### Signature

```http
GET /storefront/cart/clear/{cartid} (cartid: string) -> The emptied cart
```

#### Access

Public — no credentials required.

#### Errors

| Status | Code | Message | When | What to do |
| --- | --- | --- | --- | --- |
| `404` | CART_NOT_FOUND | Cart not found | No cart in the org has that id. | Create a cart by updating one with a new id, or re-read the customer's cart. |

Plus the standard platform errors: `429`, `500`.

#### See also

- `POST /storefront/cart/update/{cartid}`

### Parameters

| Name | In | Type | Required | Description |
| --- | --- | --- | --- | --- |
| `orgid` | header | string | yes | Organization (tenant) identifier. Every request is scoped to this org; data from other orgs is never visible. Issued with your API credentials. |
| `cartid` | path | string | yes | Cart id. |

### Responses

| Status | Meaning |
| --- | --- |
| `200` | The emptied cart |
| `404` | Cart not found — No cart in the org has that id. |
| `429` | Too Many Requests — More than 100,000 requests from one IP within 5 minutes (configurable per deployment). CORS preflights and requests from inside the platform cluster are not counted. The limiter answers before the error filter, so the body is `{ statusCode, error, message }` with no `path`, `method` or `timeStamp`; the `RateLimit-*` response headers say when the window resets. |
| `500` | An unexpected error occurred. Our team has been notified. — An unhandled server-side failure. |

