### session  
  
**string**  
**required**  
  
The short-lived credential returned by the session creation endpoint. Treat it as sensitive and use it only in the iframe `src`.  
  
### type  
  
**string**  
**enum**  
**required**  
  
The type of embed to return.  
  
`CARD_EMBED` sessions support `PAN`, `CVV`, `EXP_MONTH`, and `EXP_YEAR`.  
  
`PIN_SETTING_EMBED` sessions support only `PIN_SETTING`.  
  
**Allowed:**  
`PAN``CVV``EXP_MONTH``EXP_YEAR``PIN_SETTING`  
  
### styles  
  
**string**  
**length ≤ 4096**  
**Optional** base64-encoded JSON object containing CSS property and value pairs to apply to the iframe. URL-encode the base64 value when adding it to the query string. Styles that load external resources are not permitted. The encoded value cannot exceed 4096 characters.  
  
### accept  
  
**string**  
**enum**  
  
Defaults to application/json  
  
Generated from available response content types  
  
**Allowed:**  
`application/json``text/html`  
  
### Response Codes  
| Code | Description |  
| --- | --- |  
| `200` | Lithic-hosted card embed HTML. |  
| `400` | A parameter in the query given in the request does not match the valid queries for the endpoint. |  
| `401` | The embed session is missing, invalid, expired, or not authorized for the requested type. |  
| `404` | The specified resource was not found. |  
| `429` | Client has exceeded the number of allowed requests in a given time period. |  
| - | Rate limited, too many requests per second |  
| - | User has exceeded their per second rate limit |  
| - | Rate limited, reached daily limit |  
| - | User has exceeded their daily rate limit |  
| - | Rate limited, too many keys tried |  
| - | One IP has queried too many different API keys |

### Example CURL Request  
```bash
curl --request GET \
     --url 'https://sandbox.lithic.com/v1/embed?type=PAN' \
     --header 'accept: application/json'
```  
  
### HTML Response Structure  
```html
<!doctype html><html><body><div id="app"></div></body></html>
```
