A valid request URL is required to generate request examples{
"accessToken": "<jwt>",
"user": {
"id": "018f9a2b-7c3d-7e10-9a4b-2c1d5e6f7a8b",
"abstractAccountAddress": "0x…"
}
}{
"code": "INVALID_PARAMETER",
"message": "scope is required"
}{
"code": "INVALID_TOKEN",
"message": "Unknown agent API key"
}{
"code": "AGENT_KEYS_DISABLED",
"message": "Agent keys are not enabled for this partner"
}Create a checkout session
Issues a short-lived access token (type=agent) for a merchant checkout.
No refresh token. The bound key must include commerce.checkout.
Identify the agent with exactly one of the x-agent-api-key header or
the body signedMessage.
The request scope names the merchant checkout target, not an agent
scope. pivota.checkout is currently the only supported value. The JWT’s
scope equals the requested value, and its aud is the merchant mapped to
that target. The JWT includes the holder’s abstract account address.
AIR and Credential APIs reject this token because of the audience. The
merchant must verify aud.
A valid request URL is required to generate request examples{
"accessToken": "<jwt>",
"user": {
"id": "018f9a2b-7c3d-7e10-9a4b-2c1d5e6f7a8b",
"abstractAccountAddress": "0x…"
}
}{
"code": "INVALID_PARAMETER",
"message": "scope is required"
}{
"code": "INVALID_TOKEN",
"message": "Unknown agent API key"
}{
"code": "AGENT_KEYS_DISABLED",
"message": "Agent keys are not enabled for this partner"
}Headers
Opaque API key returned once at bind or rotate. Mutually exclusive with body
signedMessage. Required for API-key-only agents.
"air_ag_…"
Body
Was this page helpful?