> ## Documentation Index
> Fetch the complete documentation index at: https://docs.payra.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Confirm a payment method session

> Called by Payra Elements, through the secure route, once the customer submitted the fields: it closes the session with the collected card, or with the collected bank account and the ACH authorization the account holder accepted. With a publishable key it needs the session `client_secret`; a secret key may call it too. The secure details must arrive tokenized; anything else is refused and never stored. A bank account without the acceptance is refused too.



## OpenAPI

````yaml /api-reference/openapi-v1.json post /payment-method-sessions/{id}/confirm
openapi: 3.1.0
info:
  title: Payra API
  version: v1
  description: >-
    The Payra API. Authenticate with a secret key: `Authorization: Bearer
    sk_test_...`. The two payment method session endpoints Payra Elements calls
    also take a publishable key with the session's `client_secret`.
servers:
  - url: https://api-dashboard.payra.com/v1
    description: 'Sandbox and live: the key decides which'
security: []
paths:
  /payment-method-sessions/{id}/confirm:
    post:
      tags:
        - Payment method sessions
      summary: Confirm a payment method session
      description: >-
        Called by Payra Elements, through the secure route, once the customer
        submitted the fields: it closes the session with the collected card, or
        with the collected bank account and the ACH authorization the account
        holder accepted. With a publishable key it needs the session
        `client_secret`; a secret key may call it too. The secure details must
        arrive tokenized; anything else is refused and never stored. A bank
        account without the acceptance is refused too.
      parameters:
        - schema:
            type: string
            minLength: 1
            maxLength: 64
          required: true
          name: id
          in: path
        - schema:
            type: string
            description: >-
              Required with a publishable key: the secret returned when the
              session was created.
          required: false
          description: >-
            Required with a publishable key: the secret returned when the
            session was created.
          name: client_secret
          in: query
      requestBody:
        required: true
        content:
          application/json:
            schema:
              anyOf:
                - type: object
                  properties:
                    cardNumber:
                      type: string
                      minLength: 1
                      maxLength: 128
                      description: The card number as tokenized by the inbound route.
                      example: tok_sandbox_x7Kq2mP9vL4n
                    cvv:
                      type: string
                      minLength: 1
                      maxLength: 128
                      description: >-
                        The security code as tokenized by the inbound route. The
                        vault may alias it as digits of the same length.
                      example: tok_sandbox_b3Rt8wQ1
                    expiry_month:
                      type: integer
                      minimum: 1
                      maximum: 12
                      example: 12
                    expiry_year:
                      type: integer
                      example: 2030
                    last4:
                      type: string
                      pattern: ^\d{4}$
                      example: '4242'
                    brand:
                      type:
                        - string
                        - 'null'
                      maxLength: 20
                      example: visa
                    bin:
                      type: string
                      pattern: ^\d{6,8}$
                      example: '424242'
                    cardholder_name:
                      type: string
                      minLength: 1
                      maxLength: 255
                      example: Ada Lovelace
                    billing_postal_code:
                      type:
                        - string
                        - 'null'
                      pattern: >-
                        ^(?:\d{5}(?:-\d{4})?|[ABCEGHJ-NPRSTVXYabceghj-nprstvxy]\d[ABCEGHJ-NPRSTV-Zabceghj-nprstv-z]
                        ?\d[ABCEGHJ-NPRSTV-Zabceghj-nprstv-z]\d)$
                      example: '94110'
                  required:
                    - cardNumber
                    - cvv
                    - expiry_month
                    - expiry_year
                    - last4
                    - brand
                    - bin
                    - cardholder_name
                    - billing_postal_code
                - type: object
                  properties:
                    routingNumber:
                      type: string
                      minLength: 1
                      maxLength: 128
                      description: The routing number as tokenized by the inbound route.
                      example: tok_sandbox_r7Kq2mP9vL4n
                    accountNumber:
                      type: string
                      minLength: 1
                      maxLength: 128
                      description: >-
                        The account number as tokenized by the inbound route, in
                        the format that keeps the last four digits.
                      example: '991822436789'
                    account_holder_name:
                      type: string
                      minLength: 1
                      maxLength: 255
                      example: Ada Lovelace
                    account_type:
                      type: string
                      enum:
                        - checking
                        - savings
                      example: checking
                    account_holder_type:
                      type: string
                      enum:
                        - individual
                        - company
                      example: individual
                    billing_postal_code:
                      type:
                        - string
                        - 'null'
                      pattern: >-
                        ^(?:\d{5}(?:-\d{4})?|[ABCEGHJ-NPRSTVXYabceghj-nprstvxy]\d[ABCEGHJ-NPRSTV-Zabceghj-nprstv-z]
                        ?\d[ABCEGHJ-NPRSTV-Zabceghj-nprstv-z]\d)$
                      example: '94110'
                    ach_authorization:
                      type: object
                      properties:
                        accepted:
                          type: boolean
                          enum:
                            - true
                          description: >-
                            The account holder ticked the box. Anything else is
                            not sent.
                        terms_version:
                          type: string
                          minLength: 1
                          maxLength: 64
                          example: 2026-08-21.v1
                          description: The version the element showed.
                      required:
                        - accepted
                        - terms_version
                      description: >-
                        The acceptance; the server stamps its own clock and the
                        request address on it.
                  required:
                    - routingNumber
                    - accountNumber
                    - account_holder_name
                    - account_type
                    - account_holder_type
                    - billing_postal_code
                    - ach_authorization
              description: >-
                A card, or a US bank account with its ACH authorization, by what
                the session collects.
      responses:
        '200':
          description: The session, now succeeded, with the card the merchant may see
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PaymentMethodSession'
        '400':
          description: >-
            Invalid parameters, untokenized details, a missing ACH
            authorization, or a session no longer collecting
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '401':
          description: Missing, invalid or revoked API key
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '403':
          description: The API is not enabled for the workspace, or the key lacks the scope
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '404':
          description: No such session in this workspace (secret key)
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '429':
          description: Rate limit exceeded; see Retry-After
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
        '500':
          description: Internal error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
      security:
        - bearerAuth: []
components:
  schemas:
    PaymentMethodSession:
      type: object
      properties:
        object:
          type: string
          enum:
            - payment_method_session
        id:
          type: string
          example: pms_test_7Hs2kQ9mL1pXv4cR8tWzAbCd
        status:
          type: string
          enum:
            - requires_payment_method
            - succeeded
            - canceled
            - expired
          example: requires_payment_method
        customer:
          type:
            - string
            - 'null'
          format: uuid
          example: null
        payment_method_types:
          type: array
          items:
            type: string
            enum:
              - card
              - us_bank_account
          example:
            - card
        amount:
          type:
            - integer
            - 'null'
          example: null
          description: >-
            What a one-time bank debit will authorize, in the smallest unit of
            `currency`. Null on a card session and when a bank account is being
            saved.
        currency:
          type:
            - string
            - 'null'
          enum:
            - USD
          example: null
        livemode:
          type: boolean
          example: false
        expires_at:
          type: string
          format: date-time
          example: '2026-09-17T18:30:00.000Z'
        canceled_at:
          type:
            - string
            - 'null'
          format: date-time
          example: null
        succeeded_at:
          type:
            - string
            - 'null'
          format: date-time
          example: null
        card:
          $ref: '#/components/schemas/PaymentMethodSessionCard'
        us_bank_account:
          $ref: '#/components/schemas/PaymentMethodSessionBankAccount'
        ach_authorization:
          $ref: '#/components/schemas/PaymentMethodSessionAchAuthorization'
        payment_method:
          type:
            - string
            - 'null'
          example: null
          description: >-
            The payment method your server created from this session, once it
            did.
        created_at:
          type: string
          format: date-time
          example: '2026-09-17T18:00:00.000Z'
      required:
        - object
        - id
        - status
        - customer
        - payment_method_types
        - amount
        - currency
        - livemode
        - expires_at
        - canceled_at
        - succeeded_at
        - card
        - us_bank_account
        - ach_authorization
        - payment_method
        - created_at
    Error:
      type: object
      properties:
        error:
          type: object
          properties:
            type:
              type: string
              enum:
                - invalid_request_error
                - authentication_error
                - permission_error
                - rate_limit_error
                - idempotency_error
                - card_error
                - api_error
            code:
              type: string
            message:
              type: string
            param:
              type: string
            request_id:
              type: string
          required:
            - type
            - code
            - message
            - request_id
          additionalProperties:
            type: string
      required:
        - error
    PaymentMethodSessionCard:
      type:
        - object
        - 'null'
      properties:
        brand:
          type:
            - string
            - 'null'
          example: visa
        last4:
          type: string
          example: '4242'
        exp_month:
          type: integer
          example: 12
        exp_year:
          type: integer
          example: 2030
      required:
        - brand
        - last4
        - exp_month
        - exp_year
      description: Set once the browser confirmed a card.
      example: null
    PaymentMethodSessionBankAccount:
      type:
        - object
        - 'null'
      properties:
        last4:
          type: string
          example: '6789'
        account_type:
          type: string
          enum:
            - checking
            - savings
          example: checking
        account_holder_type:
          type: string
          enum:
            - individual
            - company
          example: individual
      required:
        - last4
        - account_type
        - account_holder_type
      description: Set once the browser confirmed a bank account.
      example: null
    PaymentMethodSessionAchAuthorization:
      type:
        - object
        - 'null'
      properties:
        scope:
          type: string
          enum:
            - single
            - standing
          example: single
          description: >-
            `single` authorizes one debit of `amount`; `standing` (a session
            with a customer) authorizes debits for amounts owed until revoked.
        terms_version:
          type: string
          example: 2026-08-21.v1
        short_text:
          type: string
          example: >-
            I authorize Northwind Traders to electronically debit the bank
            account provided for this one-time payment of $213.75, in accordance
            with the ACH Authorization.
          description: The sentence Payra Elements shows next to the checkbox.
        full_text:
          type: string
          description: The complete authorization, paragraphs separated by blank lines.
        accepted_at:
          type:
            - string
            - 'null'
          format: date-time
          example: null
          description: >-
            When the account holder accepted it, by the server clock; null until
            the session succeeds.
      required:
        - scope
        - terms_version
        - short_text
        - full_text
        - accepted_at
      description: >-
        On a `us_bank_account` session: the authorization shown to the account
        holder, and when they accepted it.
      example: null
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        A secret key, `sk_test_...` or `sk_live_...`; a publishable key
        (`pk_...`) on the browser routes only

````