## GET /api/v2/me/pending-orders

**List pending orders**

Return the pending order, if any, that currently requires customer action. There is no general `GET /api/v2/orders` collection endpoint; use this route for pending-order discovery, `POST /api/v2/orders` to create an order, and `GET /api/v2/orders/{id}` when another response already gave you an `ord_...` id. Returns a bounded snapshot as `{ pendingOrders }`, not a paginated `data` list: the array contains at most one entry — the most recent order that is pending, unpaid, created within the last 30 days, and eligible for BankID activation. Older pending orders, orders whose invoice is already paid, and orders that cannot be activated with BankID are not included.

### Related Endpoints

- `GET /api/v2/me`: Get current account profile
- `PATCH /api/v2/me`: Update current account profile
- `GET /api/v2/me/preferences`: Get account preferences

### Headers

- `Accept`: application/json
- `Authorization`: Bearer YOUR_API_KEY
- Required API scope: `read:orders`

### Request Example

```bash
curl -X GET "https://cloud.hostup.se/api/v2/me/pending-orders" \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Accept: application/json"
```

### Response Schema

- `pendingOrders` (array<object>, required)
- `pendingOrders[].id` (string, required): Public order ID. Example: `ord_01hxa3b4c5d6e7f8g9h0j1k2m3`
- `pendingOrders[].number` (string, required, nullable): Human-facing order number when available.
- `pendingOrders[].createdAt` (string, required): When the order was placed.
- `pendingOrders[].type` (string, required): Kind of order.
  Allowed values: new, renew, transfer, upgrade
- `pendingOrders[].billing` (object, required)
- `pendingOrders[].billing.amount` (number, required): Order total in the currency named by `currencyCode`.
- `pendingOrders[].billing.currencyCode` (string, required): ISO 4217 currency code, e.g. `SEK`.
- `pendingOrders[].billing.billingCycle` (string, required): Billing cycle of the order. Currently always `monthly`.
- `pendingOrders[].items` (array<object>, required): Order line items. When no line detail is available a single synthesized line carries the order total.
- `pendingOrders[].items[].name` (string, required): Line item name.
- `pendingOrders[].items[].amount` (number, required): Line amount in the currency named by `currencyCode`.
- `pendingOrders[].items[].currencyCode` (string, required): ISO 4217 currency code, e.g. `SEK`.
- `pendingOrders[].invoice` (object | null, required): Linked unpaid invoice, or null when no invoice is linked.
- `pendingOrders[].invoice.id` (string, required): Public invoice ID. Example: `inv_01hxa3b4c5d6e7f8g9h0j1k2m3`
- `pendingOrders[].invoice.number` (string, required, nullable): Human-facing invoice number when available.
- `pendingOrders[].invoice.total` (number, required): Invoice total in the currency named by `currencyCode`.
- `pendingOrders[].invoice.currencyCode` (string, required): ISO 4217 currency code, e.g. `SEK`.
- `pendingOrders[].invoice.dueAt` (string, required, nullable): Invoice due date when available.

### Responses

#### 200 - Pending-order snapshot.
```json
{
  "pendingOrders": [
    {
      "id": "ord_01hxa3b4c5d6e7f8g9h0j1k2m3",
      "number": "100234",
      "createdAt": "2026-07-01T09:30:00.000Z",
      "type": "new",
      "billing": {
        "amount": 249,
        "currencyCode": "SEK",
        "billingCycle": "monthly"
      },
      "items": [
        {
          "name": "Cloud VPS S",
          "amount": 249,
          "currencyCode": "SEK"
        }
      ],
      "invoice": {
        "id": "inv_01hxa3b4c5d6e7f8g9h0j1k2m3",
        "number": "102345",
        "total": 249,
        "currencyCode": "SEK",
        "dueAt": "2026-07-15T00:00:00.000Z"
      }
    }
  ]
}
```

#### 400 - Invalid request. The response body is an RFC 7807 Problem Details document.
```json
{
  "type": "https://developer.hostup.se/errors/invalid_request",
  "title": "Invalid request",
  "status": 400,
  "detail": "The request body failed validation.",
  "code": "invalid_request",
  "instance": "/api/v2/resource",
  "requestId": "req_01hxa3b4c5d6e7f8g9h0j1k2m3",
  "timestamp": "2026-04-27T12:34:56.000Z",
  "errors": [
    {
      "pointer": "/items/0/domainName",
      "detail": "`domainName` is required.",
      "code": "invalid_request"
    }
  ]
}
```

#### 401 - Unauthorized. Authentication is required.
```json
{
  "type": "https://developer.hostup.se/errors/unauthorized",
  "title": "Unauthorized",
  "status": 401,
  "detail": "Authentication is required.",
  "code": "unauthorized",
  "instance": "/api/v2/resource",
  "requestId": "req_01hxa3b4c5d6e7f8g9h0j1k2m3",
  "timestamp": "2026-04-27T12:34:56.000Z"
}
```

#### 403 - Forbidden. The caller lacks a required scope or does not own the resource.
```json
{
  "type": "https://developer.hostup.se/errors/forbidden",
  "title": "Forbidden",
  "status": 403,
  "detail": "The caller lacks a required scope or does not own the resource.",
  "code": "forbidden",
  "instance": "/api/v2/resource",
  "requestId": "req_01hxa3b4c5d6e7f8g9h0j1k2m3",
  "timestamp": "2026-04-27T12:34:56.000Z"
}
```

#### 404 - Not found. The resource does not exist or is not owned by the caller.
```json
{
  "type": "https://developer.hostup.se/errors/not_found",
  "title": "Not found",
  "status": 404,
  "detail": "The requested resource could not be found.",
  "code": "not_found",
  "instance": "/api/v2/resource",
  "requestId": "req_01hxa3b4c5d6e7f8g9h0j1k2m3",
  "timestamp": "2026-04-27T12:34:56.000Z"
}
```

#### 429 - Rate limited. Retry after the limit resets. 429 responses include `Retry-After` seconds plus `X-RateLimit-*` headers.
```json
{
  "type": "https://developer.hostup.se/errors/rate_limit_exceeded",
  "title": "Too many requests",
  "status": 429,
  "detail": "Too many requests. Retry after the limit resets.",
  "code": "rate_limit_exceeded",
  "instance": "/api/v2/resource",
  "requestId": "req_01hxa3b4c5d6e7f8g9h0j1k2m3",
  "timestamp": "2026-04-27T12:34:56.000Z"
}
```

#### 500 - Internal error. Retry later or contact support if the issue persists.
```json
{
  "type": "https://developer.hostup.se/errors/internal_error",
  "title": "Internal server error",
  "status": 500,
  "detail": "An unexpected error occurred. Retry later or contact support if the issue persists.",
  "code": "internal_error",
  "instance": "/api/v2/resource",
  "requestId": "req_01hxa3b4c5d6e7f8g9h0j1k2m3",
  "timestamp": "2026-04-27T12:34:56.000Z"
}
```
