Skip to main content
POST
Error

Headers

x-agent-api-key
string

Opaque API key returned once at bind or rotate. Mutually exclusive with body signedMessage. Required for API-key-only agents.

Example:

"air_ag_…"

Body

application/json
scope
enum<string>
required

Merchant checkout target. pivota.checkout is currently the only supported value.

Available options:
pivota.checkout
Example:

"pivota.checkout"

signedMessage
object

Mutually exclusive with x-agent-api-key. The bound key must have a stored public key.

Response

Checkout JWT issued

accessToken
string
required

JWT (type=agent) whose scope is the requested checkout target and whose aud is the mapped merchant. Not valid on the AIR or Credential API. The merchant must verify aud.

user
object
required