> ## Documentation Index
> Fetch the complete documentation index at: https://api.vitarelay.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Place an order for a customer

> Create an order for one of your **customers**: no patient, intake or prescription is created.
Prices are always read from your store, never from the request. The order is unpaid until you call
`POST /store/orders/{id}/pay`; the response includes the Accept.js keys (`checkout`). Send your own
`external_order_id` to make retries safe. The buyer must confirm they are 21+, will use the
products for research only, and accept the terms (`attestation`, all three `true`). Needs `store:write`.




## OpenAPI

````yaml /partner-api/openapi.yaml post /store/orders
openapi: 3.1.0
info:
  title: VitaRelay Partner API
  version: 1.0.0
  description: >-
    The Partner API is for rep organizations (a Vita Rep, or a dual Rep + Clinic
    account) that recruit clinics and other reps. Create the invite you would
    otherwise send from the "Refer a Tele Clinic" form, get the signup link
    back, track whether it was accepted, and revoke it.
servers:
  - url: https://vitarelay.com/api/public/partner/v1
security:
  - bearerAuth: []
tags:
  - name: Wholesale
    description: >-
      Order research-use products for your own customers at VitaRelay's
      wholesale price, charged to your card on file. You show your own prices
      and collect from your customer yourself. Rep accounts only.
  - name: Store
    description: >-
      Sell research-use products to your own customers from your own landing
      page, using VitaRelay for fulfillment and payment processing. Customers
      are not patients: no patient, intake or prescription is created. Rep
      accounts only. Needs `store:read` / `store:write`.
  - name: Invites
    description: Clinic and rep invites sent by your organization.
paths:
  /store/orders:
    post:
      tags:
        - Store
      summary: Place an order for a customer
      description: >
        Create an order for one of your **customers**: no patient, intake or
        prescription is created.

        Prices are always read from your store, never from the request. The
        order is unpaid until you call

        `POST /store/orders/{id}/pay`; the response includes the Accept.js keys
        (`checkout`). Send your own

        `external_order_id` to make retries safe. The buyer must confirm they
        are 21+, will use the

        products for research only, and accept the terms (`attestation`, all
        three `true`). Needs `store:write`.
      operationId: createStoreOrder
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateStoreOrder'
      responses:
        '200':
          description: A retry of an order already created with this `external_order_id`.
        '201':
          description: The unpaid order.
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    $ref: '#/components/schemas/StoreOrder'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '409':
          $ref: '#/components/responses/DuplicateRequest'
        '422':
          $ref: '#/components/responses/ValidationFailed'
components:
  schemas:
    CreateStoreOrder:
      type: object
      additionalProperties: false
      required:
        - items
        - customer
        - shipping_address
        - attestation
      properties:
        items:
          type: array
          items:
            type: object
            required:
              - product_id
              - quantity
            properties:
              product_id:
                type: string
                format: uuid
              quantity:
                type: integer
                minimum: 1
                maximum: 99
        customer:
          type: object
          required:
            - email
            - first_name
            - last_name
          properties:
            email:
              type: string
            first_name:
              type: string
            last_name:
              type: string
            phone:
              type: string
        shipping_address:
          type: object
          required:
            - line1
            - city
            - state
            - postal_code
          properties:
            line1:
              type: string
            line2:
              type: string
            city:
              type: string
            state:
              type: string
            postal_code:
              type: string
            country:
              type: string
              default: US
        shipping_method:
          type: string
          enum:
            - ground_rnd
            - overnight
          default: ground_rnd
        attestation:
          type: object
          required:
            - age_confirmed
            - research_use_only
            - terms_accepted
          properties:
            age_confirmed:
              type: boolean
            research_use_only:
              type: boolean
            terms_accepted:
              type: boolean
        external_order_id:
          type: string
          maxLength: 128
          description: Your own id for the order. Makes the call safe to retry.
    StoreOrder:
      type: object
      properties:
        id:
          type: string
          format: uuid
        order_number:
          type: string
          nullable: true
        status:
          type: string
        payment_status:
          type: string
        external_order_id:
          type: string
          nullable: true
        subtotal_cents:
          type: integer
          nullable: true
        shipping_cents:
          type: integer
          nullable: true
        tax_cents:
          type: integer
          nullable: true
        total_cents:
          type: integer
          nullable: true
        currency:
          type: string
        your_markup_cents:
          type: integer
          description: What you earn on this order (your price minus VitaRelay's).
        customer:
          type: object
          properties:
            email:
              type: string
              nullable: true
            first_name:
              type: string
              nullable: true
            last_name:
              type: string
              nullable: true
            phone:
              type: string
              nullable: true
        ship_to:
          type: object
          nullable: true
          description: The full shipping address the order was placed with.
        items:
          type: array
          items:
            type: object
            properties:
              product_id:
                type: string
                nullable: true
              name:
                type: string
              quantity:
                type: integer
              unit_price_cents:
                type: integer
        checkout:
          type: object
          nullable: true
          description: Accept.js keys, present when the order was just created.
          properties:
            public_client_key:
              type: string
            api_login_id:
              type: string
            accept_js_url:
              type: string
            environment:
              type: string
            amount_cents:
              type: integer
        created_at:
          type: string
          format: date-time
    Error:
      type: object
      properties:
        error:
          type: object
          properties:
            code:
              type: string
            message:
              type: string
  responses:
    Unauthorized:
      description: Missing, invalid or revoked API key (`unauthorized`).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    Forbidden:
      description: >-
        `insufficient_scope` (the key lacks the scope) or `not_available` (your
        organization is not a rep or dual Rep + Clinic account).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    DuplicateRequest:
      description: >-
        A conflicting request with the same external id is in flight
        (`duplicate_request`).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    ValidationFailed:
      description: >-
        `validation_failed` — a field is missing or invalid; the message says
        which.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        VitaRelay API key (`vr_live_...` or `vr_test_...`) with the `invites:*`
        scopes.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.