Client sessions
Exchange a client session token
Exchange a client session token, once, for a short-lived client access token.
POST
Exchange client session
Exchanges an opaque
clientSessionToken exactly once for a short-lived accessToken. The request is unauthenticated because the token is already signed, scoped and expiring. Send the returned token as Authorization: Bearer <accessToken> to /v2/client/* endpoints.
An expired but correctly signed token returns 401 client_token_expired; a replayed, malformed or invalid token returns 401 unauthorized.Body
application/json
Required string length:
32 - 4096Example:
"client_session_token_opaque_value_1234567890"
Response
Client bearer token
Example:
"ca_eyJ2ZXJzaW9uIjoxfQ.signature"
Example:
"acct_123"
Immutable date-based contract recorded on the resource. Historical values may appear on existing records; only versions advertised in x-stableyard-supported-api-versions are accepted for new requests.
Available options:
2026-08-28, 2026-09-09 Example:
"2026-09-09"
Account-bound browser/mobile authority granted by the partner backend. This is narrower than the issuing app credential and cannot enable a disabled app product.
Available options:
account:read, payments:read, payments:write, deposits:read, deposits:write, vault_payments:write