Text the add-a-card link
Create a vault session on your server and send itsurl in the conversation. Say whatever your agent would say, but keep the URL alone on the last line, or send it as its own message: anything glued onto the token turns it into a broken link, and a broken link lands the user on the Vault’s sign-in page instead of the card form.
user_id) is card-first, and a returning user taps “Unlock with your passkey” on the same page. One link is one enrollment: send it to one person, and bind the user_id you receive to that phone number. Sessions last 24 hours by default; if the user comes back later, create a new one rather than resending an old link.
If you would rather not build the message, have Agentcard deliver it. POST /api/v2/checkout/vault_link texts or emails a connected user their link from Agentcard.
Text the approval link
When your agent reaches the payment form,onApprovalUrl fires with a link. Text it with what the user is approving:
checkout_authorization.expired.
Send through a provider
If your agent texts through an iMessage provider, the link is the message body and nothing more. Two providers, same message:Confirm with webhooks
The user saying “done” is a claim. The webhook is the fact:vault.session_linkedcarries theuser_idto bind to the phone number. It fires the moment the passkey binds the session, before any card is stored.vault.card_storedwhen the card lands in the vault, in practice ten to twenty seconds aftersession_linked. It fires once per card, including a second card added through the same link. A returning user who only unlocks an existing vault never produces it, so treatsession_linkedas the sign they are in andcard_storedas the sign a new card exists.checkout_authorization.approved,checkout_authorization.declinedandcheckout_authorization.expiredfor each purchase.
status is linked.