Skip to content

Resolve Deep Link

POST
/api/Checkout/sessions/resolve
curl --request POST \
--url https://example.com/api/Checkout/sessions/resolve \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "d": "example", "s": "example" }'

Verifies the HMAC signature on a checkout deep link, creates a CheckoutSession, and returns a short-lived JWT the browser uses for subsequent endpoints. Anonymous.

An enrolment link names exactly one of plan (a single-plan checkout) or items (a multi-plan “family” checkout of 1 to 10 lines, each { "plan": uuid, "ref": string?, "label": string? }).

object
d
required
string
>= 1 characters
s
required
string
>= 1 characters
Example generated
{
"d": "example",
"s": "example"
}

Session created; use the returned token for the rest of the flow.

Media type application/json
object
outcome
string
Allowed values: Ok InvalidSignature ApiKeyNotFound MerchantMismatch PlanNotFound LinkExpired NonceAlreadyUsed InvalidPayload
sessionId
string format: uuid
nullable
sessionToken
string
nullable
expiresAt
string format: date-time
nullable
Example
{
"outcome": "Ok"
}

The enrolment lines are malformed: both or neither of plan and items, an empty or over-long items (max 10), a ref over 200 or label over 60 characters, or two lines with the same plan and the same ref.

Media type application/json
object
type
string
nullable
title
string
nullable
status
integer format: int32
nullable
detail
string
nullable
instance
string
nullable
key
additional properties
Example generated
{
"type": "example",
"title": "example",
"status": 1,
"detail": "example",
"instance": "example"
}

The signature does not verify, or the payload merchant does not match the key.

Media type application/json
object
type
string
nullable
title
string
nullable
status
integer format: int32
nullable
detail
string
nullable
instance
string
nullable
key
additional properties
Example generated
{
"type": "example",
"title": "example",
"status": 1,
"detail": "example",
"instance": "example"
}

The API key is unknown or revoked, or a line’s plan is not an active plan of the merchant.

Media type application/json
object
type
string
nullable
title
string
nullable
status
integer format: int32
nullable
detail
string
nullable
instance
string
nullable
key
additional properties
Example generated
{
"type": "example",
"title": "example",
"status": 1,
"detail": "example",
"instance": "example"
}

The link’s nonce has already been used.

Media type application/json
object
type
string
nullable
title
string
nullable
status
integer format: int32
nullable
detail
string
nullable
instance
string
nullable
key
additional properties
Example generated
{
"type": "example",
"title": "example",
"status": 1,
"detail": "example",
"instance": "example"
}

The link has expired.

Media type application/json
object
type
string
nullable
title
string
nullable
status
integer format: int32
nullable
detail
string
nullable
instance
string
nullable
key
additional properties
Example generated
{
"type": "example",
"title": "example",
"status": 1,
"detail": "example",
"instance": "example"
}