Resolves a widget token into the order, the PSP's public client configuration, and the shopper's saved cards — everything a client needs to render checkout before the shopper pays. Both the browser widget and the mobile SDK call this on mount.
This does not spend the token. The same token is still required by POST /api/v1/checkout to charge, so a shopper who abandons the form keeps a usable token. Authentication is the widget_token in the body — no merchant headers.
| Field | Type | Required | Description |
|---|---|---|---|
| widget_token | string | Yes | Active widget token from POST /api/v1/checkout/init. |
| customer_email | string | No | The shopper. Minimum 3 characters. Omit for guest checkout — order details and provider_config still return, but saved_payment_methods is always empty. |
Email binding: A token minted with a customer_email requires that exact email. A token minted anonymously is bound to the first email supplied here, and later calls with a different one are rejected. This is what stops a stolen widget token enumerating saved cards across shoppers.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||

