Skip to main content
POST
Create checkout session

Authorizations

X-API-KEY
string
header
required

Body

application/json

Checkout session parameters

allowed_origin
string

The registered origin permitted to frame this session. Embedded only — a hosted or lite checkout is not framed. May be omitted when the organisation has registered exactly one.

Example:

"https://shop.example"

amount
string

Amount to charge. Must currently match the payment link's own price.

Example:

"248.00"

cancel_url
string

Where a hosted or lite checkout sends a payer who abandons it. Same rules as success_url, but optional.

Maximum string length: 2048
Example:

"https://shop.example/cart"

config
object

Passed through to the checkout. No credentials and nothing about the payer — it is served to whoever holds the public embed handle.

currency
string

Currency to charge in. Must currently match the payment link's own.

Example:

"EUR"

customer_reference
string

Your own identifier for the payer. Not shown to them.

Maximum string length: 255
Example:

"user_4815"

expires_in
integer

Seconds until the session stops accepting new bindings. Defaults to 86400, bounded 1800-86400, as Stripe's.

Required range: 1800 <= x <= 86400
Example:

86400

locale
string

Preferred display locale.

Maximum string length: 35
Example:

"en-GB"

merchant_request_id
string

Your idempotency key. Repeating one with the same parameters returns the session it already created; repeating it with different parameters is a conflict.

Maximum string length: 255
Example:

"dep_92817"

mode
enum<string>

What the session collects. Only Payment is supported so far.

Available options:
Payment,
Subscription,
Rfq
Example:

"Payment"

Payment link the session opens. Omit for a session with no paylink behind it.

Example:

"2ZxK1qLm9vQnR7sT4uY6wB8cD0e"

redirect_on_completion
enum<string>

Whether an embedded checkout redirects to return_url on completion. Embedded only; never is refused if a redirect-based payment method (e.g. Binance Pay) is available.

Available options:
always,
if_required,
never
Example:

"if_required"

return_url
string

Where an embedded checkout returns the payer. Embedded only; must be on allowed_origin. Required unless redirect_on_completion is never.

Maximum string length: 2048
Example:

"https://shop.example/deposit/result"

success_url
string

Where a hosted or lite checkout sends the payer once it completes. Required for those modes, rejected for Embedded, and must be on one of your registered origins.

Maximum string length: 2048
Example:

"https://shop.example/deposit/done"

ui_mode
enum<string>

How the checkout is presented.

Available options:
Hosted,
Embedded,
Lite
Example:

"Embedded"

Response

Idempotency key replayed; client_secret is absent

data
object

Response payload when the request succeeded.

error
boolean

True when the request failed.

message
string

Human-readable status or error message.