Skip to main content
Version: 0.0.1

Sessions and Hosted Checkout

The Sessions API is the bridge between your backend and Hosted Checkout. Use it when your backend needs to create a secure session for the JavaScript Plugin, so the browser can launch Hosted Checkout without holding merchant credentials or other trusted secret material. It also removes the need for any other dependencies on your page.

Sessions exist so your backend can authenticate with the Merchant API, create a short-lived checkout session, and return only launch-safe data to the frontend, keeping merchant credentials out of browser code entirely.


High-level flow​

A typical flow looks like this:

  1. customer clicks Pay
  2. frontend calls your backend
  3. backend authenticates to the Merchant API
  4. backend creates a session
  5. backend returns the session output to the frontend
  6. frontend launches Hosted Checkout
  7. payment completes through the hosted flow
  8. backend confirms final state using the normal trusted path

This keeps checkout launch and backend trust properly separated.


What the session gives you​

A successful session response gives your integration what it needs to initialise the browser-side checkout launch safely, without exposing raw backend credentials to the client.

Use the generated API reference at /openapi for the exact request and response details.


What Sessions are not​

Sessions are not a replacement for:

  • callback validation
  • backend payment reconciliation
  • refund or preauth management
  • customer management
  • long-term merchant authentication

A session is a launch mechanism, not a source of final payment truth.


Frontend responsibilities​

Your frontend should:

  • request session data from your backend
  • initialise Hosted Checkout
  • handle customer-facing UI
  • avoid holding raw Merchant API credentials

Redirect and callback still matter​

Using Sessions does not change the core Hosted Checkout trust model.

You should still treat:

  • redirect as customer-facing UX
  • callback / backend validation as authoritative confirmation

Even if the session was created correctly, redirect alone should not be treated as final payment confirmation.


When to use Sessions​

Use Sessions whenever your frontend launches Hosted Checkout. If your integration is purely backend-led and never launches browser checkout, you may not need Sessions at all.


Relationship to other pages​


Summary​

Sessions let your backend create secure, short-lived launch data for Hosted Checkout, keeping credentials and trust on the backend while the frontend handles the launch.