2026 · Reverse engineering

Squarespace Checkout Client

A headless checkout client for Squarespace stores. It skips the browser, replays checkout as seven HTTP requests, and finishes a full order in 2 to 5 seconds.

Stack
Node.js, plain HTTP, Stripe's API
Requests
Seven per order, no browser
Speed
2 to 5 seconds, end to end
node index.js
0.00sProduct locked for "limited lp": https://store.example/shop/p/limited-lp
0.00sStep 1: Getting session cookies & crumb...
0.29s Crumb: BZ9kqW2xT0vLm4RcA8yN...
0.29sStep 2: Adding item to cart...
0.71s Cart created: 6ef1c2a9d8e7b3f...
0.71sStep 3: Loading checkout bootstrap...
1.30s Bootstrap loaded
1.30s Stripe: pk_live_•••••••••••••••••... | SQSP Payments: true
1.30s Total: $32.00 USD
1.30sStep 4: Setting shipping location...
1.68s Shipping location set (2 options)
1.68sStep 5: Selecting fulfillment option...
1.97s Selecting: "Standard" - $6.00
1.97sStep 6: Creating Stripe PaymentMethod...
2.41s PaymentMethod: pm_1Q•••••••••••• (visa *4242)
2.41sStep 7: Submitting order...
3.06s ORDER SUBMITTED SUCCESSFULLY!
3.06s Order ID: 66f1•••••••••••
Replay of one checkoutsample store

The log lines follow the client's own output. The store and product are samples, and the card is Stripe's test card.

Seven requests

In a browser, checkout is a few pages of forms and scripts. Underneath, it comes down to seven HTTP requests:

  1. Load any store page for the session cookies and the crumb, Squarespace's CSRF token.
  2. Add the item to the cart and keep the cart token.
  3. Load the checkout page and parse its bootstrap JSON for the store's Stripe key, the cart, and the shipping setup.
  4. Send the shipping address and get back the delivery options.
  5. Pick the cheapest rate.
  6. Create a Stripe PaymentMethod for the card.
  7. Submit the order.

Card details go straight to Stripe with the store's public key, the same way they do in a browser, so they never touch Squarespace's servers.

Finding the product

Add ?format=json to almost any Squarespace page and it returns structured data. The client uses that to scan a store's navigation, find the collections that sell things, and poll for a keyword until the product appears. It can run several checkouts in parallel from saved profiles.

Where it stops

Some checkouts need a real browser: cards that trigger 3D Secure, Apple Pay and Google Pay, PayPal, and the few stores that turn on reCAPTCHA. The client doesn't try to fake those.