Create card embed session

card_token

uuid
required

Card embed session parameters.

Parameters for creating a short-lived card embed session.

type

string
enum
required

The type of card embed session to create.

CARD_EMBED sessions can load PAN, CVV, EXP_MONTH, and EXP_YEAR iframes.

PIN_SETTING_EMBED sessions can load only the PIN_SETTING iframe.

Allowed:
CARD_EMBED, PIN_SETTING_EMBED

expiration

int64

Unix timestamp at which the session expires. The value must be in the future and no more than 10 minutes after the request. If omitted, the session expires 10 minutes after the request.

target_origin

uri
required

Canonical HTTPS origin of the page that will embed the iframe. Lithic embeds will verify the target_origin against the parent application's origin.

The origin must not contain a path, query parameters, fragment, or credentials.

Responses

200

A short-lived card embed session.

object

A short-lived session used to load Lithic-hosted card embed iframes.

session
string
required

Opaque, short-lived credential used to load card embed iframes. Treat this value as sensitive.

Do not log, persist, include in analytics, or share it.

400

A parameter in the query given in the request does not match the valid queries for the endpoint.

401

Error Description
User has not been authenticated Invalid or missing API key
API key is not active The API key used is no longer active
Could not find API key The API key provided is not associated with any user
Please provide API key in Authorization header The Authorization header is not in the request
Please provide API key in the form Authorization: [api-key] The Authorization header is not formatted properly
Insufficient privileges. Issuing API key required Write access requires an Issuing API key. Reach out at lithic.com/contact
Insufficient privileges to create virtual cards. Creating virtual cards requires an additional privilege

404

The specified resource was not found.

422

Unprocessable entity.

429

Client has exceeded the number of allowed requests in a given time period.

Error Description
Rate limited, too many requests per second User has exceeded their per second rate limit
Rate limited, reached daily limit User has exceeded their daily rate limit
Rate limited, too many keys tried One IP has queried too many different API keys

Example Request

curl --request POST \
     --url https://sandbox.lithic.com/v1/cards/card_token/embed \
     --header 'accept: application/json' \
     --header 'content-type: application/json' \
     --data '\
{\
  "target_origin": "https://example.com",\
  "type": "CARD_EMBED"\
}\
'  

Example Response

{  
  "session": "eyJhb..."
}