Vault sessions
Create a vault session
Create a single-use link the user opens to store a card behind their passkey.
POST
Create the session, then deliver
Errors.
url to the user in the thread or app you already share with them. One link is one enrollment: send it to one person and bind the user_id you receive to them. Send the URL exactly as returned, alone on its line: the token is signed, and a link with anything appended fails verification and opens the Vault’s sign-in page instead of the card form.
string
Omit for a new user: the session is open, the user is created at enrollment, and their id arrives in
vault.session_linked (or on the session read). Pass an id you already hold and the session is connected: opening the link sends a one-time code to the contact on that account and verifying it signs the user in.string
Connected sessions only, E.164. Used only when the account has no contact on file at all. Refused on open sessions.
number
Lifetime in seconds, 60 to 172800. Default 24 hours. Sessions are single use.
string
partner asks the user to let your app pay with the card they save or pick, without an approval link for each purchase. customer leaves the choice to the user. Omit it to use your app’s default from Settings → Vault → Customize in the dashboard, which is customer until you change it. Only production client credentials can send partner: under sandbox credentials, partner is refused with 403 partner_enrollment_disabled. See Enable auto-approval.string
Read the session by this id, never by the token inside
url.string
The link to send the user.
string | null
Null on an open session until it links.
number
Seconds to wait between reads if you poll.
400 client_credentials_required (API key used), 422 contact_missing (connected session, nothing to send a code to), 403 partner_enrollment_disabled (app auto-approval isn’t available to this app in this mode: send approval_mode: "customer"), 429 rate_limited (open sessions are budgeted at 200 per organization per rolling 24 hours).