Open the Vault from your app
Create a vault session on your server, hand theurl to the app, and open it with Linking.
WebView you control. The Vault saves the user’s card behind a passkey, and the system browser is where that passkey lives, so a returning user unlocks with Face ID or fingerprint. Inside a WebView the page asks the user to open the link in Safari or Chrome instead. On iOS, expo-web-browser or a Safari view gives the same result without leaving your app.
Create the session on your server and give the app only the url. Your client_secret never ships in the app bundle.
Open the approval link the same way. When your agent reaches the payment form, onApprovalUrl fires with a link; open it with Linking, or send it by push notification if the user is not in the app.
When the user finishes, you receive vault.session_linked with their user_id, then vault.card_stored. Store the user_id: it is what you pass as user on every checkout. Without webhooks, poll the session instead.
Confirm with webhooks
The user returning to your app is a claim. Your server should act on webhooks, because the browser can close before your app hears anything:vault.card_storedwhen a card lands in the vault.checkout_authorization.approvedand the othercheckout_authorization.*events when purchases are approved or declined.