sdk.nextintent.ai fill that in: the cart from the page, orders and refunds from the store’s server, checkout steps from a pixel, and erasure requests. None of them stores anything but the order ledger; each becomes a signal on the bus with source: "sdk".
Authentication
Public routes are rate-limited per site and IP.
The cart beacon
_nextintent_uid on Shopify) so the order that follows can name the visitor.
Orders
created_at, currency, total_price, subtotal_price, total_discounts, total_price_usd where the platform states one, financial_status, discount_codes, line_items as handle, product and variant ids, price and quantity, the note_attributes entry that carries the visitor id, and the customer id as a number. Send nothing else: no name, email, phone, addresses or note. NextIntent hashes the customer id on arrival with a per-site key.
The order lands in the site’s ledger whether or not the visitor is known. When the cart carried the visitor id it also becomes an order signal, and the engine marks the visitor as bought, withdraws any waiting card, and credits the order to a moment if one qualifies. The order signal is published once per order: a redelivered webhook updates the ledger row and does not count twice.
Refunds
refund signal tells the engine the outcome changed. Each refund id is counted once.
Checkout steps
completed, to go quiet for that visitor. A completed step is never treated as a credited purchase on its own; the order feed is the only source of credit, because anyone who knows a site id and a visitor id can post a step.
Erasure
scope: "customer" clears the customer reference and visitor id from the matching ledger rows, removes the visitor records those rows named (and any visitor row that carried the email as a trait), and publishes an erase signal so the engine forgets the visitor’s fold and moments. scope: "shop" erases everything for the site. A failure answers with a 5xx so the caller retries; an erasure is never acknowledged before it has happened.
