REST API endpoints for checkout bootstrapping, transient quote pricing, field resolution, order submission, receipt lookup, and pay-order flows.
Overview
The WooNooW Checkout API powers the customer-facing checkout application. It coordinates quote estimation, field rendering, multi-currency verification, fraud protection, order creation, session clearing, and existing order payments.
Controller:WooNooW\Api\CheckoutController
Namespace:woonoow/v1
Base URL:https://your-store.com/wp-json/woonoow/v1
Response Envelopes & Error Semantics
Endpoints
1. Checkout Bootstrap
Delivers personalized, non-cacheable configuration and cart state for the initial checkout page render.
{"ok":true,"items":[{"product_id":42,"name":"WooNooW Pro License","qty":2,"price":99.0,"line_total":198.0}],"totals":{"subtotal":"198.00","discount_total":"19.80","shipping_total":"5.00","tax_total":"0.00","grand_total":"183.20","currency":"USD","currency_symbol":"$","currency_pos":"left","decimals":2,"decimal_sep":".","thousand_sep":","}}
Error Response (HTTP 200)
json
{"error":"Product not purchasable"}
3. Get Checkout Fields
Returns checkout fields formatted with labels, validation rules, and classes after applying WordPress filters and addon extensions.
http
POST /wp-json/woonoow/v1/checkout/fields
Content-Type:application/json
{"ok":true,"rates":[{"id":"flat_rate:1","label":"Standard Shipping","cost":5.0,"method_id":"flat_rate","instance_id":1}],"zone_name":"United States Domestic"}
6. Submit Order
Creates a WooCommerce order, evaluates security checks, provisions accounts, links payment methods, and purges the active cart.
http
POST /wp-json/woonoow/v1/checkout/submit
Content-Type:application/json
Request Payload
json
{"items":[{"product_id":42,"variation_id":0,"qty":1,"meta":[]}],"billing":{"first_name":"Jane","last_name":"Doe","email":"jane@example.com","phone":"555-0199","address_1":"123 Main St","city":"New York","state":"NY","postcode":"10001","country":"US"},"shipping":{"ship_to_different":false},"coupons":["SUMMER10"],"shipping_method":"flat_rate:1","shipping_cost":5.0,"shipping_title":"Standard Shipping","payment_method":"stripe","customer_note":"Please leave at front door","custom_fields":{},"referral_code":"AFFILIATE10","captcha_token":"0.abcdef..."}
Submission Execution Order
Cart Hydration: Invokes CartController::ensure_cart_initialized() to load session data and obtain any active guest session ID.
Invisible CAPTCHA: Validates captcha_token via SecuritySettingsProvider::validate_captcha().
Subscription Check: Disallows guest subscription checkout (You must be logged in to purchase a subscription).
Multi-Currency Validation: Checks exchange rate freshness (currency_rate_stale) and verifies payment gateway currency support (currency_gateway_mismatch).
Order Creation: Calls wc_create_order(['created_via' => 'checkout']).
Auto-Registration:
If auto_register_members is enabled and billing email is new: creates user account, calls wp_set_auth_cookie() and wp_set_current_user(), and flags user_logged_in: true.
If email matches an existing user: links $order->set_customer_id(), but keeps user_logged_in: false for security.
Items & Addresses: Appends items, recurring price metadata, and billing/shipping addresses. Auto-saves addresses to user meta via auto_save_checkout_addresses().
Coupon Re-validation: Validates coupons against the persisted order. If validation fails, deletes the order immediately to prevent orphans.
Cart Purge: If order succeeds, calls WC()->cart->empty_cart(true), saves session, and purges the old guest session ID via WC()->session->delete_session($guest_session_id). If order fails, the cart is preserved.
Quota Tracking: Increments rate-limit counter via SecuritySettingsProvider::record_order_attempt().
Payment Completion Hand-off: The endpoint returns pay_url and thankyou_url. Credit cards and tokens are not charged synchronously inside /checkout/submit; the client navigates to pay_url (or the order-pay flow) for gateway processing, or directly to thankyou_url for offline payment methods (e.g. BACS, COD).
Access: Validated via key or authenticated order owner / admin.
Paid Check: Rejects if order has already been paid (Order already paid).
Renewal Payment Window: If order is a renewal (SubscriptionManager::get_order_type() === 'renewal'), checks SubscriptionManager::is_renewal_payment_window_open($order).
If the collection window has expired, cancels all linked renewal invoices and returns:
json
{"error":"This renewal invoice has expired. Purchase a new subscription at the current catalog price, or contact support if an exception is appropriate.","error_code":"renewal_window_expired"}
Gateway Locking: Must match the order's original gateway ID (This order must be paid using its original payment gateway.).