Skip to main content
POST
Exchange client session
Exchanges an opaque clientSessionToken exactly once for a short-lived accessToken. The request is unauthenticated because the token is already signed, scoped and expiring. Send the returned token as Authorization: Bearer <accessToken> to /v2/client/* endpoints. An expired but correctly signed token returns 401 client_token_expired; a replayed, malformed or invalid token returns 401 unauthorized.

Body

application/json
clientSessionToken
string
required
Required string length: 32 - 4096
Example:

"client_session_token_opaque_value_1234567890"

Response

Client bearer token

accessToken
string
required
Example:

"ca_eyJ2ZXJzaW9uIjoxfQ.signature"

accountId
string
required
Example:

"acct_123"

apiVersion
enum<string>
required

Immutable date-based contract recorded on the resource. Historical values may appear on existing records; only versions advertised in x-stableyard-supported-api-versions are accepted for new requests.

Available options:
2026-08-28,
2026-09-09
Example:

"2026-09-09"

permissions
enum<string>[]
required

Account-bound browser/mobile authority granted by the partner backend. This is narrower than the issuing app credential and cannot enable a disabled app product.

Available options:
account:read,
payments:read,
payments:write,
deposits:read,
deposits:write,
vault_payments:write
expiresAt
string<date-time>
required