Application UUID.
OptionalbaseWorkspace environment UUID the quote token was minted for.
OptionalfetchOptionalinit: RequestInitOptionaloriginOrigin to send. Browsers set the Origin header automatically (and it can't
be overridden from JS), so this is only needed for non-browser callers
(SSR, tests). It must be on the application's allowlist.
Storefront quote token (qt_…), from the dashboard Shipping & Tax page or
POST /api/v1/shipping-tax/quote-tokens. Tokens minted before qt_ start
with pk_ and keep working. A pk_ publishable API key is a different
credential and is refused (401 invalid_quote_token).
Optionaltimeout
Browser client for backend-less cart ownership. Unlike CartClient (which needs a server-side
sk_key),CartSessionClientruns in the browser: it creates and mutates a Throttle cart authorized by a storefront quote token (qt_…, or a legacypk_…quote token; the same token used by StorefrontQuoteClient, not apk_publishable API key) plus the application origin allowlist, and an opaquecart_…session id scoped to that one cart.Typical use: