# Build checklist

- [ ] API key stored as a server-side secret; never sent to the browser.
- [ ] The key you created in this portal went straight to your secret store.
- [ ] Full product load works and pages until `hasMore` is false.
- [ ] Delta refresh runs every few hours using `updatedSince` and a persisted last-refresh time,
      and tolerates a full-catalog delta.
- [ ] Listing hides products that are not active, that have `availabilityRequired: true`, and
      options with `active: false`.
- [ ] First add creates a cart; later edits use add, change quantity and remove; your local cart
      is overwritten from each response.
- [ ] `expectedPrice` is sent on every cart write; `PRICE_MISMATCH` updates the price and
      re-prompts the shopper.
- [ ] `item_declined`, `price_unavailable` and `available: false` are surfaced to the shopper.
- [ ] Buy now uses the latest `buyLink` verbatim, with or without CJ, and is hidden when the cart
      has unavailable lines.
- [ ] Your redirect handler validates `grouponOrderUuid`, calls the booking endpoint
      server-side, and polls while the status is `ON_HOLD` or `PENDING`.
- [ ] The confirmation page reads `items[]` (not a single product), shows each item joined on
      `optionId`, and one "View on Groupon" button per entry of that item's `unitItems`.
- [ ] `cartId` is discarded after abandon and after purchase.
- [ ] Every request sends `x-request-id`; error logs keep `requestId`.
- [ ] Tested end to end with your API key: one small real order through your storefront,
      checking the redirect, the booking read, and the voucher buttons.
