> ## Documentation Index
> Fetch the complete documentation index at: https://docs.stablemint.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Checkout hosted create



## OpenAPI

````yaml /api-reference/openapi.json post /v1/checkout/hosted
openapi: 3.0.4
info:
  description: >-
    Public API for the StableMint platform. Every request is authenticated with
    a service-account RSA signature over a canonical string; bearer tokens are
    not accepted.
  title: StableMint API
  version: v1
servers:
  - description: Production
    url: https://api.stablemint.io
  - description: Sandbox
    url: https://api.stablemint.net
security: []
tags:
  - name: accounts
  - name: beneficiaries
  - name: checkout
  - name: customers
  - name: fx
  - name: payouts
  - name: reports
  - name: simulations
  - name: transactions
  - name: users
  - name: wallets
  - name: webhooks
paths:
  /v1/checkout/hosted:
    post:
      tags:
        - checkout
      summary: Checkout hosted create
      operationId: checkout-hosted-create
      parameters:
        - in: header
          name: apiKey
          schema:
            type: string
        - in: header
          name: signature
          schema:
            type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateHostedPartnerCustomerSessionRequest'
        required: true
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/CreateHostedPartnerCustomerSessionResponse
          description: OK
        '400':
          description: Malformed request
        '401':
          description: >-
            No service-account credentials (code: signature_required), a Clerk
            bearer token was sent (code: jwt_not_accepted) — both rejected by
            the gateway — or the RSA signature, timestamp window or nonce failed
            verification downstream.
        '403':
          description: >-
            Authenticated but lacking the required permission, or an
            impersonated session attempting a write (code:
            impersonation_write_blocked).
        '404':
          description: >-
            No such resource. Also returned by the gateway itself when a path
            parameter fails its route constraint.
        '500':
          description: Unhandled downstream error
        '502':
          description: >-
            Gateway could not reach the downstream service or received an
            invalid response from it.
        '504':
          description: Downstream service did not respond in time.
      security:
        - ApiKey: []
          Nonce: []
          Signature: []
          Timestamp: []
components:
  schemas:
    CreateHostedPartnerCustomerSessionRequest:
      properties:
        amount:
          format: double
          type: number
        currency:
          type: string
        customFields:
          $ref: '#/components/schemas/JsonDocument'
        errorUrl:
          type: string
        exitUrl:
          type: string
        idempotencyKey:
          nullable: true
          type: string
        successUrl:
          type: string
        supportUrl:
          type: string
        userCountryCode:
          type: string
        userEmail:
          type: string
        userId:
          type: string
        userKyc:
          $ref: '#/components/schemas/CustomerKyc'
        websiteReference:
          nullable: true
          type: string
        widgetConfigurationSlug:
          nullable: true
          type: string
      required:
        - currency
        - userId
        - userEmail
        - userCountryCode
        - amount
        - successUrl
        - supportUrl
        - exitUrl
        - errorUrl
      type: object
    CreateHostedPartnerCustomerSessionResponse:
      properties:
        expiresAt:
          format: int64
          type: integer
        reference:
          type: string
        url:
          type: string
      required:
        - url
        - expiresAt
        - reference
      type: object
    JsonDocument:
      nullable: true
    CustomerKyc:
      nullable: true
      properties:
        citizenshipCountryCode:
          nullable: true
          type: string
        dateOfBirth:
          nullable: true
          type: string
        fullName:
          nullable: true
          type: string
        gender:
          nullable: true
          type: string
        mobilePhone:
          nullable: true
          type: string
        personalIdentificationNumber:
          nullable: true
          type: string
        placeOfBirth:
          nullable: true
          type: string
        residenceAddress:
          nullable: true
          type: string
      type: object
  securitySchemes:
    ApiKey:
      description: The service account's API key.
      in: header
      name: ApiKey
      type: apiKey
    Nonce:
      description: A GUID, single-use. A replayed nonce is rejected.
      in: header
      name: Nonce
      type: apiKey
    Signature:
      description: >-
        Base64 RSA/SHA-256 (PKCS#1 v1.5) signature over the canonical string:
        METHOD, path, canonical query, Timestamp, Nonce, API secret and the
        lowercase hex SHA-256 of the raw body, joined with LF. Sign the PUBLIC
        path exactly as called (e.g. /v1/webhooks), not any internal path.
      in: header
      name: Signature
      type: apiKey
    Timestamp:
      description: Unix seconds. Rejected outside the server's tolerance window.
      in: header
      name: Timestamp
      type: apiKey

````