Platitun · API · The deal · Read the buyer’s vault

Read the buyer’s vault

POST /api/v1/orders/{id}/handover/reveal

Key scope: orders · changes data, the Idempotency-Key header is required

The buyer also uses a vault — for instance for the email a subscription should be issued to. Someone else’s vault can be read EXACTLY ONCE: a repeat honestly answers “already opened”. Your own vault cannot be read at all.

Once read, keep it. There is no second time, and the marketplace cannot repeat it: it does not know the content.

Request fields

FieldTypeWhat it is
handover requiredstringThe vault id from the order vault list.

Response fields

FieldTypeWhat it is
secretstringThe content — for the first and last time.

Refusal reasons

A rule refusal arrives as {"error":"rejected","refusal":{"kind":"…"}} with status 409. Refusals common to all endpoints are in the rules section.

CodeWhat happened and what to do
not_foundThe record does not exist or is not yours. The ownership condition is in the database query itself, so someone else’s record looks like a missing one.
vault_emptyThe vault was already opened or is empty. Someone else’s vault can be read exactly once, and a repeat says so honestly.
vault_offThe marketplace vault is not configured, so there is nowhere to keep secrets. That is our problem, not yours: contact support.

Nearby in this section