Create Link Session

Create Link Session

This endpoint is to be called by your back end, to establish a new link session for creating a link to your end user's institution.

URL

POST
/link-session
Request
curl --request POST \
--url 'https://api.moneykit.com/link-session' \
--header 'Authorization: Bearer REPLACE_BEARER_TOKEN' \
--header 'X-Client-Id: SOME_STRING_VALUE' \
--header 'X-Client-Secret: SOME_STRING_VALUE' \
--header 'X-MoneyKit-User-Token: SOME_STRING_VALUE' \
--header 'Content-Type: application/json' \
--data ' {
"settings": "SOME_STRING_VALUE",
"customer_user": "SOME_STRING_VALUE",
"existing_link_id": "SOME_STRING_VALUE",
"institution_id": "SOME_STRING_VALUE",
"allowed_institutions": "SOME_STRING_VALUE",
"blocked_institutions": "SOME_STRING_VALUE",
"redirect_uri": "SOME_STRING_VALUE",
"webhook": "SOME_STRING_VALUE",
"link_tags": "SOME_STRING_VALUE",
"connect_features": "SOME_STRING_VALUE",
"custom_sandbox_data": "SOME_STRING_VALUE"
}'
fetch("https://api.moneykit.com/link-session", {
"method": "POST",
"headers": {
"Authorization": "Bearer REPLACE_BEARER_TOKEN",
"Content-Type": "application/json",
"X-Client-Id": "SOME_STRING_VALUE",
"X-Client-Secret": "SOME_STRING_VALUE",
"X-MoneyKit-User-Token": "SOME_STRING_VALUE"
},
"body": "{\n \"settings\": \"SOME_STRING_VALUE\",\n \"customer_user\": \"SOME_STRING_VALUE\",\n \"existing_link_id\": \"SOME_STRING_VALUE\",\n \"institution_id\": \"SOME_STRING_VALUE\",\n \"allowed_institutions\": \"SOME_STRING_VALUE\",\n \"blocked_institutions\": \"SOME_STRING_VALUE\",\n \"redirect_uri\": \"SOME_STRING_VALUE\",\n \"webhook\": \"SOME_STRING_VALUE\",\n \"link_tags\": \"SOME_STRING_VALUE\",\n \"connect_features\": \"SOME_STRING_VALUE\",\n \"custom_sandbox_data\": \"SOME_STRING_VALUE\"\n}"
})
.then(response => response.json())
.then(data => console.log(data));
import requests

url = "https://api.moneykit.com/link-session"
headers = {
'Authorization': 'Bearer REPLACE_BEARER_TOKEN',
'Content-Type': 'application/json',
'X-Client-Id': 'SOME_STRING_VALUE',
'X-Client-Secret': 'SOME_STRING_VALUE',
'X-MoneyKit-User-Token': 'SOME_STRING_VALUE'
}
data = {
'settings': 'SOME_STRING_VALUE',
'customer_user': 'SOME_STRING_VALUE',
'existing_link_id': 'SOME_STRING_VALUE',
'institution_id': 'SOME_STRING_VALUE',
'allowed_institutions': 'SOME_STRING_VALUE',
'blocked_institutions': 'SOME_STRING_VALUE',
'redirect_uri': 'SOME_STRING_VALUE',
'webhook': 'SOME_STRING_VALUE',
'link_tags': 'SOME_STRING_VALUE',
'connect_features': 'SOME_STRING_VALUE',
'custom_sandbox_data': 'SOME_STRING_VALUE'
}

response = requests.post(url, headers=headers, json=data)
print(response.json())
package main

import (
"fmt"
"net/http"
"strings"
)

func main() {
payload := strings.NewReader(`{
"settings": "SOME_STRING_VALUE",
"customer_user": "SOME_STRING_VALUE",
"existing_link_id": "SOME_STRING_VALUE",
"institution_id": "SOME_STRING_VALUE",
"allowed_institutions": "SOME_STRING_VALUE",
"blocked_institutions": "SOME_STRING_VALUE",
"redirect_uri": "SOME_STRING_VALUE",
"webhook": "SOME_STRING_VALUE",
"link_tags": "SOME_STRING_VALUE",
"connect_features": "SOME_STRING_VALUE",
"custom_sandbox_data": "SOME_STRING_VALUE"
}`)

req, _ := http.NewRequest("POST", "https://api.moneykit.com/link-session", payload)
req.Header.Add("Authorization", "Bearer REPLACE_BEARER_TOKEN")
req.Header.Add("Content-Type", "application/json")
req.Header.Add("X-Client-Id", "SOME_STRING_VALUE")
req.Header.Add("X-Client-Secret", "SOME_STRING_VALUE")
req.Header.Add("X-MoneyKit-User-Token", "SOME_STRING_VALUE")

res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()

fmt.Println(res)
}
require 'net/http'
require 'json'

uri = URI('https://api.moneykit.com/link-session')
http = Net::HTTP.new(uri.host, uri.port)
http.use_ssl = true

request = Net::HTTP::Post.new(uri)
request['Authorization'] = 'Bearer REPLACE_BEARER_TOKEN'
request['Content-Type'] = 'application/json'
request['X-Client-Id'] = 'SOME_STRING_VALUE'
request['X-Client-Secret'] = 'SOME_STRING_VALUE'
request['X-MoneyKit-User-Token'] = 'SOME_STRING_VALUE'
request.body = '{
"settings": "SOME_STRING_VALUE",
"customer_user": "SOME_STRING_VALUE",
"existing_link_id": "SOME_STRING_VALUE",
"institution_id": "SOME_STRING_VALUE",
"allowed_institutions": "SOME_STRING_VALUE",
"blocked_institutions": "SOME_STRING_VALUE",
"redirect_uri": "SOME_STRING_VALUE",
"webhook": "SOME_STRING_VALUE",
"link_tags": "SOME_STRING_VALUE",
"connect_features": "SOME_STRING_VALUE",
"custom_sandbox_data": "SOME_STRING_VALUE"
}'

response = http.request(request)
puts response.body
import Foundation

let url = URL(string: "https://api.moneykit.com/link-session")!
var request = URLRequest(url: url)
request.httpMethod = "POST"
request.setValue("Bearer REPLACE_BEARER_TOKEN", forHTTPHeaderField: "Authorization")
request.setValue("application/json", forHTTPHeaderField: "Content-Type")
request.setValue("SOME_STRING_VALUE", forHTTPHeaderField: "X-Client-Id")
request.setValue("SOME_STRING_VALUE", forHTTPHeaderField: "X-Client-Secret")
request.setValue("SOME_STRING_VALUE", forHTTPHeaderField: "X-MoneyKit-User-Token")

let jsonData = "{
"settings": "SOME_STRING_VALUE",
"customer_user": "SOME_STRING_VALUE",
"existing_link_id": "SOME_STRING_VALUE",
"institution_id": "SOME_STRING_VALUE",
"allowed_institutions": "SOME_STRING_VALUE",
"blocked_institutions": "SOME_STRING_VALUE",
"redirect_uri": "SOME_STRING_VALUE",
"webhook": "SOME_STRING_VALUE",
"link_tags": "SOME_STRING_VALUE",
"connect_features": "SOME_STRING_VALUE",
"custom_sandbox_data": "SOME_STRING_VALUE"
}".data(using: .utf8)!
request.httpBody = jsonData

let task = URLSession.shared.dataTask(with: request) { data, response, error in
guard let data = data else { return }
print(String(data: data, encoding: .utf8)!)
}
task.resume()
Response
{
"link_session_token": "c7318ff7-257c-490e-8242-03a815b223b7"
}
{
"error_code": "api_error.auth.expired_access_token",
"error_message": "Access token expired",
"documentation_url": string
}
{
"error_code": "link_session_error.forbidden_config",
"error_message": "Forbidden use of a Connect feature",
"documentation_url": string
}

allowed_institutions

: array

A list of IDs for institutions you want to enable linking to. Providing this will hide all other institutions during institution selection. Note that if it is not possible to show any institutions (due to other restrictions such as provider, product, or country) then creating the link session will fail.

example: ["chase", "bofa"]

blocked_institutions

: array

A list of IDs for institutions you want to disable linking to. Providing this will hide these institutions during institution selection. Note that if it is not possible to show any institutions (due to other restrictions such as provider, product, or country) then creating the link session will fail.

example: ["chase", "bofa"]

connect_features

: object

Enables optional testing and UI features.

default: {"issue_reporter":false,"enable_money_id":false,"duplicate_institution_warning":false,"duplicate_institution_rejected":false,"connect_manually":false,"permit_only_one_account":false,"permit_only_depository_accounts":false,"bug_reporter":false,"enable_device_verification":false,"provider_sandbox_institutions":false,"simulate_provider_error":false}

custom_sandbox_data

: object

If provided, will allow custom static data to be returned on Credentials Bank in Sandbox mode, using the user user_custom.

customer_user

: object

required

Details about your end user. These details are used to improve conversion, streamline the linking flow, and provide enhanced debugging and improved privacy controls for your end user.

institution_id

: string

The ID of the institution you want to link to. Providing this will skip the institution selection step. This field is ignored if existing_link_id is provided.

example: chase

redirect_uri

: string (uri)

required

For Oauth linking, a URI indicating the destination, in your application, where the user should be sent after authenticating with the institution. The redirect_uri should not contain any query parameters, and its protocol://host[:port]/ must be listed in your dashboard settings.

format:

uri

min length:

1

example: https://yourdomain.com/oauth.html

settings

: object

If provided, these settings will override your default settings for this session.

webhook

: string (uri)

The destination URL to which any webhooks should be sent.

example: https://yourdomain.com/moneykit_webhook

X-Client-Id

: string

Your client ID.

example: live_dcc75c42eb6122127356

X-Client-Secret

: string

Your client secret

example: vzPznCv3kT7fHsAr6y3jk38d

X-MoneyKit-User-Token

: string

Clerk JWT required when creating a link session for a Playground app.

Responses

201

Successful Response

403

Forbidden session configuration.

error_code

: string

default: "link_session_error.forbidden_config"

error_message

: string

Error message

example: Forbidden use of a Connect feature

documentation_url

: string