Skip to main content
POST
Returns a widget_url you load in an iframe or WebView. The flows you list are the only ones the session can open, and they’re carried in the signed session token, so they can’t be changed from the browser. The user has to exist first. Create them with Create a User.

Configuration

Header Parameters

string
required
Your ZBD API key.
string
Content Type

Body Parameters

string
required
The ZBD user ID returned by Create a User.
string[]
required
The flows this session can open: kyc (identity verification), payment_methods (payment method selection), disclosures, and cashout. cashout is only available where ZBD holds the user’s balance.
string
The project the session belongs to.

Response

The session is in data.
string
The signed token for this session. It’s already in widget_url, so you only need it on its own when the widget asks your page for a new session.
string
The URL to load in an iframe or WebView. Load it as it comes back, and add embed parameters if you need them.
string[]
The flows this session can open, as you requested them.
string
When the session expires, as an ISO 8601 timestamp. Sessions last 4 hours.
When the session is close to expiring, the widget asks your page for a new one. See Refreshing a session.

Errors