Skip to main content
POST
Verification token for the buyer
Provider sandbox on this deployment. Our backend targets the card provider’s sandbox: no card is charged and no real transfer settles. Known limits: a purchase never reaches completed (it stops at processing), the settlement asset is the sandbox’s, not production’s (read cryptoCurrency from GET /v1/config), and the EUR window is unpublished (GET /v1/card/limits says window: unpublished). Every response says which environment answered in its environment field.

Authorizations

Authorization
string
header
required

Your API key, issued by us and shown once at creation.

Body

application/json
email
string
required

Buyer email from the card form; keys the provider user.

Pattern: ^[^\s@]+@[^\s@]+\.[^\s@]+$
Example:

"buyer@example.com"

Response

The WebSDK token.

environment
enum<string>
required

Which environment answered. sandbox: at least one money upstream is the provider's sandbox - no real money moves there, and the card corridor is the sandbox's asset (read GET /v1/config), not the documented production one. production: every configured upstream is real. Derived from the configured upstream hosts at boot, never a flag.

Available options:
sandbox,
production
Example:

"sandbox"

accessToken
string
required

Sumsub WebSDK access token (the provider's own Sumsub tenant).

applicantId
string

Provider-side applicant id, when returned. The WebSDK works from the token alone.