Skip to main content
POST
Resolve a hosted checkout code
Exchanges the 12-character, case-sensitive Base58 checkoutCode from a Stableyard-hosted paymentUrl for the paymentId and clientSecret. The hosted checkout does this server-side before loading the checkout engine. Treat clientSecret as opaque and send it only as a Bearer token. Invalid, inactive, expired or corrupted codes all return the same generic 404. Exchanges are rate-limited by caller IP and a non-reversible digest of the code.

Body

application/json
checkoutCode
string
required

Case-sensitive Base58 code from the canonical paymentUrl.

Required string length: 12
Pattern: ^[1-9A-HJ-NP-Za-km-z]{12}$
Example:

"7Yf3KMpQ2xWa"

Response

Signed browser credential

paymentId
string
required
Pattern: ^payment_[A-Za-z0-9_-]+$
Example:

"payment_123"

clientSecret
string
required

Opaque browser credential for exactly one Payment. Do not parse it; send it only as a Bearer token.

Required string length: 32 - 512
apiVersion
enum<string>
required

Immutable date-based contract recorded on the resource. Historical values may appear on existing records; only versions advertised in x-stableyard-supported-api-versions are accepted for new requests.

Available options:
2026-08-28,
2026-09-09
Example:

"2026-09-09"

expiresAt
string<date-time>
required