> ## Documentation Index
> Fetch the complete documentation index at: https://docs.stableyard.fi/llms.txt
> Use this file to discover all available pages before exploring further.

# Exchange a client session token

> Exchange a client session token, once, for a short-lived client access token.

Exchanges an opaque `clientSessionToken` exactly once for a short-lived `accessToken`. The request is unauthenticated because the token is already signed, scoped and expiring. Send the returned token as `Authorization: Bearer <accessToken>` to `/v2/client/*` endpoints.

An expired but correctly signed token returns `401 client_token_expired`; a replayed, malformed or invalid token returns `401 unauthorized`.


## OpenAPI

````yaml frontend-openapi.json POST /v2/client/auth/exchange
openapi: 3.1.0
info:
  title: Stableyard Interfaces & SDK API
  version: 2.0.0-staging
  x-stableyard-api-version: '2026-09-09'
  x-stableyard-supported-api-versions:
    - '2026-09-09'
  summary: >-
    Advanced browser API used by Stableyard Checkout, Add Money, and
    account-bound interfaces.
  description: >

    These endpoints power Stableyard's official interface SDKs, hosted checkout,
    Add Money, and advanced custom browser integrations.


    Most partners should use `@stableyard/react` or `@stableyard/sdk` instead of
    calling these routes directly. A browser must never receive an app secret.
    Public checkout uses a Payment-scoped client secret, while account-bound
    experiences use a short-lived client bearer token created by the partner
    backend.
  x-stableyard-documentation-surface: frontend
servers:
  - url: https://prod-api.stableyard.fi
    description: Production
  - url: https://staging-api-v2.stableyard.fi
    description: Staging
  - url: http://localhost:3001
    description: Local
security: []
tags:
  - name: Authentication
    x-displayName: API authentication
    description: Verify your app ID and app secret before calling UPA APIs.
  - name: Client API
    description: >-
      Account-bound browser and mobile routes authenticated with a short-lived
      client bearer token. App secrets never enter client code.
  - name: Identity & KYC
    description: >-
      Verify the UPA email and run provider-neutral identity verification.
      Managed vaults and fiat payment rails use this same verified UPA identity.
  - name: Payments
    description: >-
      Create escrow-first payments, issue partner-authenticated send
      instructions or executions, power public checkout, and reconcile
      collection through final account settlement.
paths:
  /v2/client/auth/exchange:
    post:
      tags:
        - Client API
      summary: Exchange client session
      description: >-
        Exchanges an opaque clientSessionToken exactly once for a short-lived
        client access token. The request is unauthenticated because the token is
        already signed, scoped, and expiring. An expired, correctly signed token
        returns 401 client_token_expired; a replayed, malformed, or invalid
        token returns 401 unauthorized. Send the returned accessToken as
        `Authorization: Bearer <accessToken>` to `/v2/client/*` endpoints.
      operationId: exchangeClientSession
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/ExchangeClientSessionRequest'
            examples:
              example:
                summary: Exchange client session request
                value:
                  clientSessionToken: client_session_token_opaque_value_1234567890
      responses:
        '200':
          description: Client bearer token
          headers:
            Stableyard-Version:
              description: >-
                Effective date-based Stableyard API contract version for this
                response.
              schema:
                type: string
                enum:
                  - '2026-09-09'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ClientAccessTokenResponse'
              examples:
                example:
                  summary: Exchange client session 200 response
                  value:
                    accessToken: ca_eyJ2ZXJzaW9uIjoxfQ.signature
                    accountId: acct_123
                    apiVersion: '2026-09-09'
                    permissions:
                      - account:read
                    expiresAt: '2026-08-28T10:00:00.000Z'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
      security: []
components:
  schemas:
    ExchangeClientSessionRequest:
      type: object
      additionalProperties: false
      required:
        - clientSessionToken
      properties:
        clientSessionToken:
          type: string
          minLength: 32
          maxLength: 4096
          example: client_session_token_opaque_value_1234567890
    ClientAccessTokenResponse:
      type: object
      additionalProperties: false
      required:
        - accessToken
        - accountId
        - apiVersion
        - permissions
        - expiresAt
      properties:
        accessToken:
          type: string
          example: ca_eyJ2ZXJzaW9uIjoxfQ.signature
        accountId:
          type: string
          example: acct_123
        apiVersion:
          $ref: '#/components/schemas/StableyardApiVersion'
        permissions:
          type: array
          items:
            $ref: '#/components/schemas/ClientPermission'
        expiresAt:
          type: string
          format: date-time
    StableyardApiVersion:
      type: string
      enum:
        - '2026-08-28'
        - '2026-09-09'
      example: '2026-09-09'
      description: >-
        Immutable date-based contract recorded on the resource. Historical
        values may appear on existing records; only versions advertised in
        x-stableyard-supported-api-versions are accepted for new requests.
    ClientPermission:
      type: string
      enum:
        - account:read
        - payments:read
        - payments:write
        - deposits:read
        - deposits:write
        - vault_payments:write
      description: >-
        Account-bound browser/mobile authority granted by the partner backend.
        This is narrower than the issuing app credential and cannot enable a
        disabled app product.
    ErrorResponse:
      type: object
      additionalProperties: false
      required:
        - error
      properties:
        error:
          type: object
          additionalProperties: false
          required:
            - code
            - message
          properties:
            code:
              type: string
              minLength: 1
              maxLength: 128
              example: bad_request
            message:
              type: string
              minLength: 1
              maxLength: 1000
              example: The request is invalid
            details: {}
  responses:
    BadRequest:
      description: Bad request
      headers:
        Stableyard-Version:
          description: >-
            Effective date-based Stableyard API contract version for this
            response.
          schema:
            type: string
            enum:
              - '2026-09-09'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            example:
              summary: BadRequest response
              value:
                error:
                  code: bad_request
                  message: The request is invalid
                  details: example
    Unauthorized:
      description: Unauthorized
      headers:
        Stableyard-Version:
          description: >-
            Effective date-based Stableyard API contract version for this
            response.
          schema:
            type: string
            enum:
              - '2026-09-09'
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            example:
              summary: Unauthorized response
              value:
                error:
                  code: bad_request
                  message: The request is invalid
                  details: example

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.