Skip to main content
POST
Confirm a payment method session

Authorizations

Authorization
string
header
required

A secret key, sk_test_... or sk_live_...; a publishable key (pk_...) on the browser routes only

Path Parameters

id
string
required
Required string length: 1 - 64

Query Parameters

client_secret
string

Required with a publishable key: the secret returned when the session was created.

Body

application/json

A card, or a US bank account with its ACH authorization, by what the session collects.

cardNumber
string
required

The card number as tokenized by the inbound route.

Required string length: 1 - 128
Example:

"tok_sandbox_x7Kq2mP9vL4n"

cvv
string
required

The security code as tokenized by the inbound route. The vault may alias it as digits of the same length.

Required string length: 1 - 128
Example:

"tok_sandbox_b3Rt8wQ1"

expiry_month
integer
required
Required range: 1 <= x <= 12
Example:

12

expiry_year
integer
required
Example:

2030

last4
string
required
Pattern: ^\d{4}$
Example:

"4242"

brand
string | null
required
Maximum string length: 20
Example:

"visa"

bin
string
required
Pattern: ^\d{6,8}$
Example:

"424242"

cardholder_name
string
required
Required string length: 1 - 255
Example:

"Ada Lovelace"

billing_postal_code
string | null
required
Pattern: ^(?:\d{5}(?:-\d{4})?|[ABCEGHJ-NPRSTVXYabceghj-nprstvxy]\d[ABCEGHJ-NPRSTV-Zabceghj-nprstv-z] ?\d[ABCEGHJ-NPRSTV-Zabceghj-nprstv-z]\d)$
Example:

"94110"

Response

The session, now succeeded, with the card the merchant may see

object
enum<string>
required
Available options:
payment_method_session
id
string
required
Example:

"pms_test_7Hs2kQ9mL1pXv4cR8tWzAbCd"

status
enum<string>
required
Available options:
requires_payment_method,
succeeded,
canceled,
expired
Example:

"requires_payment_method"

customer
string<uuid> | null
required
Example:

null

payment_method_types
enum<string>[]
required
Available options:
card,
us_bank_account
Example:
amount
integer | null
required

What a one-time bank debit will authorize, in the smallest unit of currency. Null on a card session and when a bank account is being saved.

Example:

null

currency
enum<string> | null
required
Available options:
USD
Example:

null

livemode
boolean
required
Example:

false

expires_at
string<date-time>
required
Example:

"2026-09-17T18:30:00.000Z"

canceled_at
string<date-time> | null
required
Example:

null

succeeded_at
string<date-time> | null
required
Example:

null

card
object | null
required

Set once the browser confirmed a card.

Example:

null

us_bank_account
object | null
required

Set once the browser confirmed a bank account.

Example:

null

ach_authorization
object | null
required

On a us_bank_account session: the authorization shown to the account holder, and when they accepted it.

Example:

null

payment_method
string | null
required

The payment method your server created from this session, once it did.

Example:

null

created_at
string<date-time>
required
Example:

"2026-09-17T18:00:00.000Z"