Knox Docs Sign in

API reference

Test mode. Use your secret key on your server; live processing is currently disabled.

https://api.knoxapi.com

Send form-encoded requests with Authorization: Bearer sk_test_....

Complete OpenAPI specification · Integration guide

Operations and schemas are based on the pinned Stripe OpenAPI specification (MIT). Nested object definitions and enums are available in the complete specification.

POST /v1/customer_sessions

Create a Customer Session

Creates a Customer Session object that includes a single-use client secret that you can use on your front-end to grant client-side API access for certain customer resources.

Request parameters

FieldTypeDescription
components requiredobjectConfiguration for each component. At least 1 component must be enabled.
customerstringThe ID of an existing customer for which to create the Customer Session.
customer_accountstringThe ID of an existing Account for which to create the Customer Session.
expandarray of stringSpecifies which fields in the response should be expanded.

Responses

HTTP 200: Successful response.
FieldTypeDescription
client_secret requiredstringThe client secret of this Customer Session. Used on the client to set up secure access to the given `customer`. The client secret can be used to provide access to `customer` from your frontend. It should not be stored, logged, or exposed to anyone other than the relevant customer. Make sure that you have TLS enabled on any page that includes the client secret.
componentscustomer_session_resource_components
created requiredintegerTime at which the object was created. Measured in seconds since the Unix epoch.
customer requiredone of multiple schemasThe Customer the Customer Session was created for.
customer_accountstringThe Account that the Customer Session was created for.
expires_at requiredintegerThe timestamp at which this Customer Session will expire.
livemode requiredbooleanIf the object exists in live mode, the value is `true`. If the object exists in test mode, the value is `false`.
object requiredstringString representing the object's type. Objects of the same type share the same value.
HTTP default: Error response.
FieldTypeDescription
error requiredapi_errors