Skip to main content
POST
Open a hosted payment-compliance action
Used by the Stableyard-hosted payment-verification page. The configured hosted origin exchanges the signed code from the action link once. The response sets an HttpOnly browser cookie and returns the current action and a csrfToken; it does not return a bearer token or accept partner credentials. Treat the code, cookie and CSRF token as credentials. Do not log them or copy them into application storage. Responses use Cache-Control: no-store, private. An invalid, expired or already consumed code returns 410; an unauthorized origin returns 403. Continue with Get the hosted action and Submit requested fields. This browser flow collects missing payment-compliance information; it does not move money.

Path Parameters

code
string
required
Pattern: ^ki_info_req_[A-Za-z0-9]+\.[1-9][0-9]{0,8}\.[A-Za-z0-9_-]{43}$

Response

Hosted action and CSRF proof

action
object
required
csrfToken
string
required
Pattern: ^[A-Za-z0-9_-]{43}$
Example:

"ccccccccccccccccccccccccccccccccccccccccccc"