> ## Documentation Index
> Fetch the complete documentation index at: https://docs.firedrill.run/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a provider-hosted billing checkout redirect

> A request carrying promotionCode redeems that code, whether it came from a campaign link or the customer typed it; the code is resolved and validated against the selected plan and price before any session exists, and an unknown, expired, fully redeemed or inapplicable code returns 400 control.PROMOTION_CODE_INVALID with details.reason and creates nothing. A code must be bound to the plan being bought — by the coupon's own product restriction or by firedrill_plan metadata — or it is refused. A request without a code creates a full-price session that carries no discount; the provider's own promotion-code field is never opened, so no code can bypass that binding. A payment method is always collected, so a subscription whose first invoice is discounted to zero still renews at full price when the discount ends. Top-up packs are never discounted.



## OpenAPI

````yaml /api-reference/openapi.json post /v1/organization/billing/checkout
openapi: 3.1.0
info:
  title: Firedrill Control API
  version: 1.0.0
  description: >-
    The control plane for drills, drill runs, and the worlds they run in. Errors
    always carry the canonical envelope; unsafe operations require an
    Idempotency-Key; long work returns an operation resource.
servers:
  - url: https://api.firedrill.run
security:
  - controlCredential: []
paths:
  /v1/organization/billing/checkout:
    post:
      summary: Create a provider-hosted billing checkout redirect
      description: >-
        A request carrying promotionCode redeems that code, whether it came from
        a campaign link or the customer typed it; the code is resolved and
        validated against the selected plan and price before any session exists,
        and an unknown, expired, fully redeemed or inapplicable code returns 400
        control.PROMOTION_CODE_INVALID with details.reason and creates nothing.
        A code must be bound to the plan being bought — by the coupon's own
        product restriction or by firedrill_plan metadata — or it is refused. A
        request without a code creates a full-price session that carries no
        discount; the provider's own promotion-code field is never opened, so no
        code can bypass that binding. A payment method is always collected, so a
        subscription whose first invoice is discounted to zero still renews at
        full price when the discount ends. Top-up packs are never discounted.
      operationId: billing.createCheckout
      parameters:
        - name: Idempotency-Key
          in: header
          required: true
          schema:
            type: string
            minLength: 8
            maxLength: 128
            pattern: ^[A-Za-z0-9._:-]+$
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateBillingCheckoutRequest'
      responses:
        '200':
          description: Existing checkout redirect
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/BillingRedirect'
        '201':
          description: Checkout redirect
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/BillingRedirect'
        default:
          description: Canonical error envelope
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
components:
  schemas:
    CreateBillingCheckoutRequest:
      type: object
      properties:
        planId:
          type: string
          minLength: 1
          maxLength: 40
          pattern: ^[a-z][a-z0-9]*(?:-[a-z0-9]+)*$
        interval:
          type: string
          enum:
            - monthly
            - yearly
        promotionCode:
          description: >-
            A promotion code to redeem, from a campaign link or typed by the
            customer. It is resolved and validated before the checkout session
            is created; an unknown, expired, exhausted or inapplicable code is
            refused with 400 control.PROMOTION_CODE_INVALID and no session is
            created. Omit it and the session carries no discount: the provider's
            own promotion-code field is never opened, so every code is bound to
            the plan being bought here.
          type: string
          minLength: 1
          maxLength: 200
          pattern: ^[A-Za-z0-9-]+$
      required:
        - planId
      additionalProperties: false
    BillingRedirect:
      type: object
      properties:
        schemaVersion:
          type: number
          enum:
            - 1
        billingRedirectId:
          type: string
          pattern: ^billredirect_[0-9a-z]{12,32}$
        kind:
          type: string
          enum:
            - checkout
            - portal
            - topup
        url:
          type: string
          format: uri
          pattern: ^https:\/\/.*
        expiresAtMs:
          type: integer
          minimum: -9007199254740991
          maximum: 9007199254740991
      required:
        - schemaVersion
        - billingRedirectId
        - kind
        - url
      additionalProperties: false
    ErrorEnvelope:
      type: object
      properties:
        code:
          type: string
          pattern: ^(control|world)\.[A-Z][A-Z0-9]*(_[A-Z0-9]+)*$
        message:
          type: string
          minLength: 1
        correlationId:
          type: string
          minLength: 1
        retryable:
          type: boolean
        retryAfterMs:
          type: integer
          exclusiveMinimum: 0
          maximum: 9007199254740991
        operationId:
          type: string
        source:
          type: string
          enum:
            - platform
            - simulated_provider
        issues:
          type: array
          items:
            type: object
            properties:
              path:
                type: string
              code:
                type: string
              message:
                type: string
            required:
              - path
              - code
              - message
            additionalProperties: false
        details:
          type: object
          propertyNames:
            type: string
          additionalProperties: {}
        evidence:
          type: object
          properties:
            sessionId:
              type: string
            runId:
              type: string
            journalSeq:
              type: integer
              minimum: 0
              maximum: 9007199254740991
            buildHash:
              type: string
          additionalProperties: false
      required:
        - code
        - message
        - correlationId
        - retryable
        - source
      additionalProperties: true
  securitySchemes:
    controlCredential:
      type: http
      scheme: bearer
      description: Opaque control credential

````