Hosted payment verification
Get the hosted payment-verification action
Read the remaining fields for the action bound to the browser session.
GET
Get the active hosted payment-compliance action
Reads the action bound to the HttpOnly cookie from Exchange action code. The request must come from the configured hosted origin. The browser sends the cookie; an app secret or Payment client secret does not replace it.
The response contains
action and csrfToken. Render the returned fields using their keys, labels, types and options; only still-missing fields are returned. Use the CSRF token when submitting those fields. Do not log or cache identity data or credentials. Responses use Cache-Control: no-store, private.Authorizations
Scoped HttpOnly cookie set by POST /v2/public/partner-kyc-actions/{code}/exchange. The browser sends it automatically from the configured hosted origin; non-secure local development uses stableyard_partner_kyc. It is not an app secret or bearer token.