Create a client session
Create a short-lived client session for one existing UPA, from your backend.
accountId or externalUserId. Both are strict lookups: this endpoint never creates or updates a UPA, so create the account through the Partner API first.
Grant only the permissions this browser or mobile flow needs; omitted permissions default to account:read. Each permission also requires the matching app module and issuing credential scope. The app secret stays on your backend. Pass the returned clientSessionToken to the client, which exchanges it once for a client bearer token.
See Authentication.Authorizations
HTTP Basic auth. Username is the Stableyard app ID. Password is the app secret. The optional Stableyard-Version request header must match the environment pin.
Headers
Optional contract-version assertion. Omit it to use the app environment's pinned version. A different supported version is accepted only after that environment is explicitly migrated.
2026-09-09 Body
- Create client session request
- Create client session request
Bind the client session to exactly one UPA using either identifier.
Stableyard account id for the authenticated app user.
"acct_123"
Partner-owned external user id.
128"user_123"
60 <= x <= 3600Least-privilege operations embedded in this account-bound client token. Each permission also requires the matching app module and issuing credential scope.
1 - 6 elementsAccount-bound browser/mobile authority granted by the partner backend. This is narrower than the issuing app credential and cannot enable a disabled app product.
account:read, payments:read, payments:write, deposits:read, deposits:write, vault_payments:write Response
Client session token
"session_123"
32 - 4096"client_session_token_opaque_value_1234567890"
Immutable date-based contract recorded on the resource. Historical values may appear on existing records; only versions advertised in x-stableyard-supported-api-versions are accepted for new requests.
2026-08-28, 2026-09-09 "2026-09-09"
Account-bound browser/mobile authority granted by the partner backend. This is narrower than the issuing app credential and cannot enable a disabled app product.
account:read, payments:read, payments:write, deposits:read, deposits:write, vault_payments:write