Skip to main content
Create every payment session from a trusted backend. The request selects one allowed action and one server-authorized purchase source.

Authentication

Your service-client policy must allow the action, billing resource type, return URL, and embedding origin in the request.

Session fields

string
required
purchase, manage_methods, change_subscription, or buy_credits.
object
required
The boxpressd_user, guest, or service actor and its stable ID.
string
required
The authorized billing account UUID.
string
A short-lived signed assertion when the client policy requires account-specific authorization.
string
required
An exact registered URL or a URL under a registered prefix.
string
A registered destination for cancellation.
string
The registered parent origin when checkout runs in an iframe.
string
default:"page"
page, modal, or sheet.

Marketplace purchase

The trusted shop backend supplies the merchant, order reference, and final minor-unit amount:
The browser cannot change the amount or merchant after session creation.

Server-configured offer

For a Boxpressd-owned purchase, send an offer code. Payments loads the price and effects from the active immutable offer version.

Manage saved methods

Create a session with action: "manage_methods" and no offer, credit purchase, subscription, or marketplace order. The hosted screen lets the user add, make default, and remove saved methods.

Session response

The first successful request returns 201 with a raw one-time URL:
An identical idempotency replay returns 200, replayed: true, and url: null.