Verification of the binding of a basket
The article contains a description of the method used to verify the binding of a basket together with an example implementation of the method in PHP.
On this page:
Description of the method
The method is used to verify whether or not the basket is linked, and whether or not the browser the customer currently uses is among the trusted ones.
Field name | Description | Type | Requirement status | Additional remarks |
| Basket's unique ID assigned by the merchant | string | Y |
| The Id of a trusted browser assigned by InPost Pay, which was returned back in the basket binding request of the method POST/v1/izi/basket/{basket_id}/confirmation. | string | O |
Request – none
Field name | Description | Type | Requirement status | Additional remarks |
| A flag which informs whether or not the basket is bound | boolean | Y |
| The identifier of the basket assigned by the InPost Pay app. The data piece not to be used by the merchant. The identifier eventually used by the widget in order to make it possible to correctly redirect from the widget level to the InPost Pay app
| string | O |
| A flag which informs, whether or not the browser is trusted | boolean | Y |
| An object which returns the client's information | object | O |
| An object which returns the number bound to the basket or/and the number bound to the trusted browser | object | O | |
| Prefix | string | Y | |
| Telephone number | string | Y | |
| Masked phone number in the format 60*****00 | string | O | |
| The user's first name associated with the phone number in the InPost Pay App | string | O | |
| The user's surname associated with the phone number in the InPost Pay App | string | O |
GET /v1/izi/basket/{basket_id}/binding
"basket_linked": true,
"browser_trusted": true,
"inpost_basket_id": "38ca5c3e-3wsd-34rd-8651-12f7afe7cc24",
"client_details": {
"phone_number": {
"country_prefix": "+48",
"phone": "600000000"
"masked_phone_number": "60*****00",
"name": "Jan",
"surname": "Kowalski"
Example implementation in PHP
Entering the code -
Only the getBasketBinding function has been added in the implementacjaKlienta.txt file.
* Client symfony implementation used for communication between Merchant and InPost Pay application.
* @param InpostPayBearerServiceInterface $inpostPayBearerService <p> Bearer service interface,
* with contains creating bearer token which is required for communication with Inpost Pay </p>
final class InpostPayClient implements InpostPayClientInterface
private ClientInterface $client;
private InpostPayURLCreatorInterface $URLCreator;
private InpostPayBearerServiceInterface $bearerService;
public function __construct(
ClientInterface $client,
InpostPayURLCreatorInterface $URLCreator,
InpostPayBearerServiceInterface $bearerService
) {
$this->client = $client;
$this->URLCreator = $URLCreator;
$this->bearerService = $bearerService;
public function getBasketBinding(string $basketId, string $browserId = null): BindingBasket
$path = sprintf('basket/%s/binding', $basketId);
$uri = (new Uri($this->buildUri($path)))
->withQuery(Psr7\Query::build(['browser_id' => $browserId]));
$request = new Request(
try {
$response = $this->client->sendRequest($request);
$content = $response->getBody()->getContents();
* @var BindingBasketArray $data
$data = json_decode($content, true, 512, JSON_THROW_ON_ERROR);
return BindingBasket::fromArray($data);
} catch (\Throwable $throwable) {
throw InpostPayGetBasketBindingException::createResponseException($throwable);
public function postBasketBinding(string $basketId, BasketBindingRequest $requestBody): ?QrCodeData
if (BindingMethod::PHONE()->equals($requestBody->getBindingMethod()) && !$requestBody->getPhoneNumber()) {
throw InpostPayPostBasketBindingException::createNoPhoneForPhoneBindingMethodException();
$path = sprintf('basket/%s/binding', $basketId);
$uri = new Uri($this->buildUri($path));
/** @var string $body */
$body = json_encode($requestBody);
$request = new Request(
try {
$response = $this->client->sendRequest($request);
$statusCode = $response->getStatusCode();
$content = $response->getBody()->getContents();
if (HttpResponseStatus::ACCEPTED()->getValue() === $statusCode) {
return null;
if (HttpResponseStatus::OK()->getValue() === $statusCode) {
* @var QrCodeDataArray $data
$data = json_decode($content, true, 512, JSON_THROW_ON_ERROR);
return QrCodeData::fromArray($data);
} catch (\Throwable $throwable) {
throw InpostPayPostBasketBindingException::createResponseException($throwable);
throw InpostPayPostBasketBindingException::createBadStatusCodeException($statusCode, $content);
public function putBasket(string $basketId, Basket $basket): InpostBasketId
$path = sprintf('basket/%s', $basketId);
$uri = new Uri($this->buildUri($path));
/** @var string $body */
$body = json_encode($basket);
$request = new Request(
try {
$response = $this->client->sendRequest($request);
$content = $response->getBody()->getContents();
* @var array{inpost_basket_id: string} $responseData
$responseData = json_decode($content, true, 512, JSON_THROW_ON_ERROR);
return InpostBasketId::fromArray($responseData);
} catch (\Throwable $throwable) {
throw InpostPayPutBasketException::createResponseException($throwable);
public function deleteBasketBinding(string $basketId, bool $ifBasketRealized = null): void
$path = sprintf('basket/%s/binding', $basketId);
$uri = (new Uri($this->buildUri($path)))
->withQuery(Psr7\Query::build(['if_basket_realized' => $ifBasketRealized]));
$request = new Request(
try {
$response = $this->client->sendRequest($request);
$statusCode = $response->getStatusCode();
$content = $response->getBody()->getContents();
} catch (\Throwable $throwable) {
throw InpostPayDeleteBasketBindingException::createResponseException($throwable);
if (HttpResponseStatus::NO_CONTENT()->getValue() === $statusCode) {
throw InpostPayDeleteBasketBindingException::createBadStatusCodeException($statusCode, $content);
public function deleteBrowserBinding(string $browserId): void
$path = sprintf('browser/%s/binding', $browserId);
$uri = new Uri($this->buildUri($path));
$request = new Request(
try {
$response = $this->client->sendRequest($request);
$statusCode = $response->getStatusCode();
$content = $response->getBody()->getContents();
} catch (\Throwable $throwable) {
throw InpostPayDeleteBrowserBindingException::createResponseException($throwable);
if (HttpResponseStatus::NO_CONTENT()->getValue() === $statusCode) {
throw InpostPayDeleteBrowserBindingException::createBadStatusCodeException($statusCode, $content);
public function getSigningKey(string $version): SigningKeyResponse
$path = sprintf('signing-keys/public/%s', $version);
$uri = new Uri($this->buildUri($path));
$request = new Request(
try {
$response = $this->client->sendRequest($request);
$statusCode = $response->getStatusCode();
$content = $response->getBody()->getContents();
if (HttpResponseStatus::OK()->getValue() === $statusCode) {
* @var SigningKeyResponseArray $data
$data = json_decode($content, true, 512, JSON_THROW_ON_ERROR);
return SigningKeyResponse::fromArray($data);
} catch (\Throwable $throwable) {
throw InpostPayGetSigningKeyException::createResponseException($throwable);
throw InpostPayGetSigningKeyException::createBadStatusCodeException($statusCode, $content);
public function getSigningKeys(): SigningKeysResponse
$path = 'signing-keys/public';
$uri = new Uri($this->buildUri($path));
$request = new Request(
try {
$response = $this->client->sendRequest($request);
$statusCode = $response->getStatusCode();
$content = $response->getBody()->getContents();
if (HttpResponseStatus::OK()->getValue() === $statusCode) {
* @var SigningKeysResponseArray $data
$data = json_decode($content, true, 512, JSON_THROW_ON_ERROR);
return SigningKeysResponse::fromArray($data);
} catch (\Throwable $throwable) {
throw InpostPayGetSigningKeysException::createResponseException($throwable);
throw InpostPayGetSigningKeysException::createBadStatusCodeException($statusCode, $content);
* @return array{
* Authorization: string,
* Content-Type: string
* }
* @throws InpostPayEndpointException
private function provideDefaultClientHeaders(): array
return [
'Authorization' => sprintf('Bearer %s', $this->bearerService->getBearerToken()),
'Content-Type' => 'application/json',
private function buildUri(string $path): string
return sprintf(
} contains a code which includes the object of the request and of the endpoint response.