Job maps-address-autocomplete-on-checkout-form · revised 11 October 2026
Add Google address autocomplete to your checkout form with a locked-down key
Customers type an address on one form, pick a suggestion and see the street, town, postcode and country filled in; typing by hand still works and the key works only on your site.
You might be seeing
- Customers abandon the address step or enter a postcode that does not match the street
- Staff retype addresses before printing labels
- A previous autocomplete fills the town into the street box or leaves the country empty
No passwords, keys, card details or admin invites needed to start.
What usually happened
Address autocomplete is a browser widget calling a paid service with a key that sits in the page. If the key is unrestricted anyone can use it on your bill. If the widget is the outdated one, it may not be available to a new project. If the returned parts are mapped to form boxes carelessly, units, accents and countries with different address shapes land in the wrong place, and if Google is unreachable the form must still work.
Who it’s for: A founder or shop owner whose checkout or booking form asks customers to type a full address by hand, and who sees abandoned forms, mistyped postcodes or delivery problems from badly entered addresses.
Usually starts when: Orders arrive with missing flat numbers or wrong postcodes, or a first attempt at address autocomplete used an unrestricted key, an outdated widget or fields that fill the wrong boxes.
The result: On the agreed form, choosing a suggestion for each of ten agreed sample addresses fills the street, town, postcode and country boxes as expected, and entering the same address by hand still submits. The key is limited to your site's addresses and to the two Google services the form uses, the Maps JavaScript API and Places API (New), and the form asks Google only for the fields it uses.
Check whether this job fits
Answer from what you know about your form and Google set-up. It needs no keys or billing details.
Checks you can run yourself
Check whether your key is restricted
In your Google Cloud console, open the key's page and read its application and API restriction settings. Do not copy the key into an enquiry.
Look for: Whether it lists your website addresses and only the services you use. A key with no restrictions can be used by anyone who finds it.
What you get
- A pull request with the form change, the mapping table and tests
- Written, step-by-step settings for your Google Cloud administrator: key restrictions (website addresses; Maps JavaScript API and Places API (New) only), the services to enable and a quota cap suggestion
- A table of ten sample addresses with expected and observed form values
- Undo steps
Included
- One address form in one existing web app, using Google's current place autocomplete element (loaded from the places library of the Maps JavaScript API and served by Places API (New)) or an equivalent client call, loaded only on that form
- Mapping of the returned address parts to your form's boxes for the agreed countries, with an agreed rule for unit numbers and missing parts
- A fallback so the form works with the service blocked, slow or declined
- A key restricted by HTTP referrer to your website's addresses and by API restriction to the Maps JavaScript API and Places API (New), set up by your Google Cloud administrator following our written steps; the older Places API is Legacy and is not enabled
- A request that names only the address fields the form needs, and a test that checks the network request
Not included
- Checking that an address is deliverable or correcting it: Google's separate address validation product is a different job
- Maps display, geocoding, distance or delivery-fee calculation
- Creating your Google Cloud account, billing set-up or any promise about the bill
- Mobile apps and native SDKs
- Converting every address form on the site, or rebuilding the checkout
- Storing returned place data beyond what Google's terms allow; what you keep is your decision
How we know it’s done
Agreed with you before work starts. Each check produces evidence you keep.
With the restricted staging key in place (website addresses; Maps JavaScript API and Places API (New) only), the form loads Google's script, and for each of ten agreed sample addresses choosing the suggestion fills the street, town, postcode and country boxes with the expected values, or the table records the specific mismatch.
Evidence: A table of expected against observed box values with screenshots for the unit-number and accented-character cases.
With requests to the Google service blocked in the browser, the form accepts a manually typed address and submits it.
Evidence: A recorded run with the block in place and the submitted values.
The place-details request the page makes after one suggestion is picked (the fetchFields call) names only the agreed address fields and no others.
Evidence: A redacted capture of that request showing its field list. The suggestion requests the element sends while typing are not part of this check.
A request using the staging key from a website not on its allowed list is refused, and the key is restricted to your website addresses and to the Maps JavaScript API and Places API (New) only.
Evidence: The refusal message from a test page on a non-allowed address and your administrator's screenshot of the key's website and API restrictions.
Sign-off. You read the sample table, the captures and the key restrictions, then sign off in writing and merge. Payment follows sign-off; your team deploys and holds the production key.
If it fails. If the agreed checks do not pass you do not pay for this fixed scope. If the cause is billing, a closed checkout or an address shape the form cannot hold, we explain the evidence and stop. Wider work needs a new written agreement.
When it fits, and when we stop
It fits when
- The form is a standard web form whose boxes can be filled by script
- You have, or can create, a Google Cloud project with billing enabled, and a person who can create and restrict a key
- The form runs on a staging address that you can add to the key's allowed sites
- You can name the countries to support and supply ten sample addresses with the expected box values
- Your maintainer can review, merge and deploy the change
We stop and tell you if
- Nobody can enable billing or create the key, so the service cannot be called
- The form is a closed third-party checkout whose boxes you cannot change
- The real need is deliverability checking rather than easier typing
- The countries in scope have address shapes that cannot be mapped onto your boxes without redesigning the form
What could go wrong
Before merge, closing the pull request changes nothing. After merge, reverting the commit returns the form to typing only; the Google key can be disabled or deleted by your administrator at any time.
Scroll the table sideways to read it all.
| Risk | How we handle it |
|---|---|
| An unrestricted or leaked key is used by others and charged to you. | Written steps restrict the key to your websites and to the two services in use, the Maps JavaScript API and Places API (New), the key is kept out of the repository, and Google's guidance on separate keys and quotas is followed. Restricting to the Places service alone would stop the Maps script loading, so the staging key is tested in its restricted form. |
| The wrong part fills the wrong box for some countries or unit addresses. | The mapping is tested against ten agreed sample addresses that include a unit number, a missing street number and accented characters; mismatches are listed. |
| The form stops working if Google is slow or blocked. | Manual entry is always available and a test blocks the service. |
A reviewer separate from the builder checks the diff, that no key is in the repository, that only the agreed fields are requested and that the form still submits when the service fails. Your authorised maintainer merges.
How we deliver
We arrange the work and independent review, then show you the result against the agreed checks. You keep authority over your systems.
- Agree the form, countries, box mapping and who creates and restricts the key
- Read the form's code and identify the boxes, validation and submit path
- Write the mapping table and the ten sample cases before building, with expected box values
- Build the autocomplete, mapping and fallback on a branch with tests
- Give your administrator the key settings, then run the ten cases and the blocked-service case on staging and capture the evidence
- Have an independent reviewer check the diff and evidence, then hand over with undo steps
An enquiry books nothing and charges nothing. Scope, access route and checks are agreed in writing first.
Need to keep it working?
If the bill or key matters to you, ask about the monthly service that watches credentials, quotas and provider deprecations.
Ongoing work is separately scoped and quoted: no monitoring, response-time guarantee or automatic subscription is included in this job.
Explore an ongoing engineering lane, or mention the responsibility you need in your enquiry.
What you can check
This is a new service. We have not delivered this job for a client yet.
Other ways to get this done
- Google documents its current autocomplete component and says it manages sessions automatically; a developer on your team can follow that page. developers.google.com
- Check whether your shop platform or checkout already offers an address-lookup option before adding a custom one.
Questions
Will this tell me whether an address exists?
No. Autocomplete suggests places as someone types. Whether a parcel can be delivered there is a different question and product.
How much will Google charge me?
No figure is promised. Billing depends on usage and the fields requested; the job limits the fields and gives your administrator quota settings to apply.
What if my existing autocomplete stopped working?
Some older Google place services are labelled legacy and may be unavailable to new projects. Tell us the browser error and the job can include replacing it on the one form.
Which Google services does the key need?
Two: the Maps JavaScript API, which loads the script on the page, and Places API (New), which serves the suggestions and place details. Google says to authorise the Maps JavaScript API on the key if the page uses it, so a key restricted to Places alone would stop the script loading. The older Places API is Legacy and is not used.
Do you need my Google login?
No. Your administrator creates a restricted staging key. We never need your account login.
Send an enquiry
Send us
- The page or form, as a description, and the countries served
- The names of the address boxes the form has today
- Whether a Google Cloud project with billing exists, as a yes or no
- Do not send API keys, billing details, real customer addresses or code in the first enquiry
Later, once you agree
- Read access to the code through a company-controlled repository or export, and a staging environment you control
- A restricted staging key created by your Google Cloud administrator and kept in your configuration
- Ten sample addresses that are not real customers, with the expected value of each form box
- The staging and production site addresses to allow
You own the Google Cloud project, billing and every key. We work on a branch through a company-controlled identity and use a restricted staging key that you create. Production keys and billing stay with you.
Email fallback: open your mail app
If website submission is unavailable, review and send the fallback email yourself. An email fallback is not a website receipt. Or write to hello@syntheticindustry.ai with “maps-address-autocomplete-on-checkout-form” as the subject.