Hosted payment verification
Open a hosted payment-verification action
Exchange a one-time hosted action code for a scoped browser session.
POST
Open a hosted payment-compliance action
Used by the Stableyard-hosted payment-verification page. The configured hosted origin exchanges the signed code from the action link once. The response sets an HttpOnly browser cookie and returns the current
action and a csrfToken; it does not return a bearer token or accept partner credentials.
Treat the code, cookie and CSRF token as credentials. Do not log them or copy them into application storage. Responses use Cache-Control: no-store, private. An invalid, expired or already consumed code returns 410; an unauthorized origin returns 403.
Continue with Get the hosted action and Submit requested fields. This browser flow collects missing payment-compliance information; it does not move money.