## card_token

**uuid**  
*required*

Card embed session parameters.

### Parameters for creating a short-lived card embed session.

#### type  
*string*  
*enum*  
*required*

The type of card embed session to create.

`CARD_EMBED` sessions can load `PAN`, `CVV`, `EXP_MONTH`, and `EXP_YEAR` iframes.

`PIN_SETTING_EMBED` sessions can load only the `PIN_SETTING` iframe.

Allowed:  
`CARD_EMBED`, `PIN_SETTING_EMBED`

#### expiration  
*int64*

Unix timestamp at which the session expires. The value must be in the future and no more than 10 minutes after the request. If omitted, the session expires 10 minutes after the request.

#### target_origin  
*uri*  
*required*

Canonical HTTPS origin of the page that will embed the iframe. Lithic embeds will verify the `target_origin` against the parent application's origin.

The origin must not contain a path, query parameters, fragment, or credentials.

### Responses

#### `200`  
A short-lived card embed session.

*object*

A short-lived session used to load Lithic-hosted card embed iframes.

**session**  
*string*  
*required*

Opaque, short-lived credential used to load card embed iframes. Treat this value as sensitive.

Do not log, persist, include in analytics, or share it.

#### `400`  
A parameter in the query given in the request does not match the valid queries for the endpoint.

#### `401`  
| Error | Description |
| --- | --- |
| User has not been authenticated | Invalid or missing API key |
| API key is not active | The API key used is no longer active |
| Could not find API key | The API key provided is not associated with any user |
| Please provide API key in Authorization header | The Authorization header is not in the request |
| Please provide API key in the form Authorization: [api-key] | The Authorization header is not formatted properly |
| Insufficient privileges. Issuing API key required | Write access requires an Issuing API key. Reach out at [lithic.com/contact](/content/contact/index.html) |
| Insufficient privileges to create virtual cards. | Creating virtual cards requires an additional privilege |

#### `404`  
The specified resource was not found.

#### `422`  
Unprocessable entity.

#### `429`  
Client has exceeded the number of allowed requests in a given time period.  
| Error | Description |
| --- | --- |
| Rate limited, too many requests per second | User has exceeded their per second rate limit |
| Rate limited, reached daily limit | User has exceeded their daily rate limit |
| Rate limited, too many keys tried | One IP has queried too many different API keys |

### Example Request

```shell
curl --request POST \
     --url https://sandbox.lithic.com/v1/cards/card_token/embed \
     --header 'accept: application/json' \
     --header 'content-type: application/json' \
     --data '\
{\
  "target_origin": "https://example.com",\
  "type": "CARD_EMBED"\
}\
'  
```

### Example Response

```json
{  
  "session": "eyJhb..."
}
```
