POST/api/public/access-request/paypal/create-order
Creates a PayPal order for the selected access package.
The page “POST /api/public/access-request/paypal/create-order — API Reference” covers the function identified by this URL. The existing summary is expanded with the actual workflow, prerequisites and known limitations. The form builder supports freely configurable forms with trigger keywords, field types and required-field flags. The feature is covered by end-to-end tests. `POST /api/public/access-request/paypal/create-order` must be implemented as the specific operation documented on this page. The client should follow the declared method, path, authentication model, required fields and error responses rather than copying only the example payload. Zentor has no general developer API-key system; a route is either public or relies on the documented Widget token and origin validation. For `/api/public/access-request/paypal/create-order`, evaluate the HTTP status together with the JSON body. Validation failures, missing resources, rejected origins, expired one-time values and server errors require different handling. A technically successful request confirms only this processing step; it does not automatically prove that an email was delivered, a payment completed or an identity provider finished an SSO flow. Use anonymised test values for `POST /api/public/access-request/paypal/create-order`. Public examples must not contain real customer data, production-like UUIDs, session JWTs, Widget tokens or concrete historical timestamps. The known platform-wide limit is 2,000 requests per 15 minutes. No separate limit for this individual endpoint is proven, so clients still need to cap retries and avoid uncontrolled polling. Idempotency matters when retrying this route. A non-idempotent POST must not be sent again automatically after an ambiguous network interruption, because the original request may already have created a side effect. Logs should record status, error code and a safe request reference, but never passwords, reset tokens or other credentials. This is directly relevant to “POST /api/public/access-request/paypal/create-order”. The source of truth for “POST /api/public/access-request/paypal/create-order — API Reference” is the API registry under `app/frontend/src/content/api-reference/` together with the corresponding backend route and tests. A negative test or a similarity to another code path does not represent a complete live verification. The page has to state precisely whether a claim comes from schema, automated test or safely observed live behaviour.
Auth & Security
No authentication required
Idempotent: No
Parameters
package(body, string, required)— Package codeExample Request
{"package":"starter"}Example Response
{"ok":false,"error":"PAYPAL_NOT_READY","message":"PayPal ist derzeit nicht verfügbar."}Error Codes
503 PAYPAL_NOT_READY — PayPal is not configured/not available.Live Test Proof
Only the controlled error case with missing PayPal configuration (503) was tested — a real success case would trigger an actual PayPal sandbox payment transaction, which was excluded under the test specification (no real payment provider calls).