API Overview
/orders/{id} and /orders/{id}/ are both currently available. The order ID is part of the payment link and should be treated as a sensitive opaque identifier; do not distribute it publicly.
Anonymous Query
The payment page can read directly when the login session is lost:id, description, price, state, pay_way, pay_url, expired_at, and created_at. It does not return account, Application, Package, internal payment identifiers, or metadata.
Authenticated Query
application / applications, package / packages, bank_details, invoice_automation, and model fields. If authenticated but not the order owner, 403 is returned; super administrators are excluded.
Key Fields
The full response may include additional fields depending on the payment method. Clients should read them as needed and always avoid logging sensitive metadata in the full response.
Error Handling
404: The order ID does not exist.403: Logged in but not the order owner.- Anonymous requests do not return
401; they only receive the minimum public projection.

