Public previewSee what changed →
All guides

Attaching the person's account

Page 7 of 9

Attaching is optional and only worth doing when the person asks. The person needs no LivingSocial account: if they want their purchases attached to them, the assistant asks for their phone number or their email, and only uses what the person gives it.

  1. link_phone with action: "start" and a phone (with its country code, like +1 312 555 0100), or link_email with action: "start" and an email, sends one text message or one email. It carries a six-digit code, which works for 10 minutes, and a confirmation link, which works for 60 minutes. The answer is the same whether or not the mailbox or number exists.
  2. The person tells the assistant the code, or the assistant reads it itself when it can see the person's messages. The assistant calls the same tool with action: "confirm" and code. Spaces and dashes in the code are ignored.
  3. Instead of the code, the person may open the link and confirm on LivingSocial's page. Or, if they prefer, they sign in with Google or Facebook on the cart page (cartUrl) and choose "Attach" when the page asks, which attaches their account the same way. Signing in alone attaches nothing.

A contact the assistant supplies proves nothing: the session stays anonymous until the code, the link or the person's "Attach" after signing in confirms it. A wrong or expired code is refused with invalid_input and one sentence that does not say why; each message's code allows five tries, and after the fifth wrong one the person has to start again. Each session may try ten codes an hour.

When the person confirms, their LivingSocial account is found by that contact, or created, and attached to the session. An account created this way may hold only that phone number or only that email, and no name. The session token now acts for the account, and the cart the assistant filled is the account's cart. Attaching lets the assistant shop with the person's account: the cart, checkout and their order history. action: "status" answers identity.state (anonymous, verification_pending, verified), identity.contact (email or phone) and identity.bound (whether the account is attached); a confirm with the right code answers the same. Attaching is not marketing consent and does not let the assistant pay.