- A vault session is a single-use link you send the user. They open it, type their card, and save it with a passkey. A master password is offered afterwards as a backup. The page asks for a master password before the card is stored when the card will open only in this browser. When it links you get their
user_id. - A checkout authorization is a paused payment. Your browser (or the SDK) captured the request the merchant’s page sent to its payment processor with a placeholder card; you post it here, the user approves on their own device, and that device pays with the real card.
- A checkout preparation lets the user approve before your browser starts a short-lived card request. The SDK applies that approval to one fresh request on Square, Braintree, Worldpay, Bambora or Mercado Pago.
400 client_credentials_required.
The vault session object
The vault card object
Display fields only. Never a card number or anything that could decrypt one.The checkout authorization object
Approve before Pay
Ask for approval before starting the merchant’s card request. A preparation carries the same displayed amount and merchant fields as an authorization, plus:
Adyen (
cse) preparations name the host family: sandbox is checkoutshopper-test.adyen.com with a test_ client key, production is the live hosts with a live_ key, and the bound request is the Sessions /payments call carrying a fresh card’s four encrypted fields. Prepare before Pay: Adyen Web abandons its Sessions payment request 60 seconds after Pay (observed on Adyen Web 6.41 and 6.44, not enforced by Agentcard), and a prepared approval leaves only the device-side encryption inside that window.
Endpoints
Webhooks:
vault.session_linked, vault.card_stored, vault.payment_permission.updated, checkout_authorization.approved, checkout_authorization.submitted, checkout_authorization.declined, checkout_authorization.expired, checkout_authorization.amount_mismatch, checkout_authorization.settled, checkout_authorization.settlement_unconfirmed, checkout_authorization.outcome_reported.
The @agent-cards/checkout SDK wraps the authorization and preparation calls for Playwright and CDP browsers. See Creating a cart.