> ## Documentation Index
> Fetch the complete documentation index at: https://docs.useroutr.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Exchange a handoff token for a session token



## OpenAPI

````yaml /api-reference/openapi.yaml post /checkout_sessions/resume
openapi: 3.1.0
info:
  title: Useroutr API
  version: 1.0.0
  description: |
    Universal application funding. Users fund an application with whatever they
    hold, on whatever rail, and the application receives exactly what it needs,
    credited exactly once.

    This document is the single source of truth for every wire type. Server
    handlers, the SDK, the checkout, and the dashboard all consume types
    generated from it. A handler change without a regenerated type fails CI.
servers:
  - url: https://api.useroutr.com/v1
    description: Production
  - url: https://api.sandbox.useroutr.com/v1
    description: Sandbox
security:
  - secretKey: []
tags:
  - name: Funding intents
  - name: Funding addresses
  - name: Customers
  - name: Registry
  - name: Webhooks
paths:
  /checkout_sessions/resume:
    post:
      tags:
        - Checkout
      summary: Exchange a handoff token for a session token
      operationId: resumeCheckoutSession
      parameters:
        - $ref: '#/components/parameters/IdempotencyKey'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - handoff_token
                - code_verifier
              properties:
                handoff_token:
                  type: string
                code_verifier:
                  type: string
                  minLength: 43
                  description: >-
                    The verifier whose hash was sent when the handoff was
                    minted.
      responses:
        '201':
          description: A fresh session token.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CheckoutSession'
        default:
          $ref: '#/components/responses/Error'
components:
  parameters:
    IdempotencyKey:
      name: Idempotency-Key
      in: header
      required: true
      description: Required on every mutating request. Absent is a 400.
      schema:
        type: string
        minLength: 8
        maxLength: 200
  schemas:
    CheckoutSession:
      type: object
      description: |
        A browser credential for one funding intent. The token is shown once and
        only its hash is stored.
      required:
        - id
        - session_token
        - funding_intent_id
        - expires_at
      properties:
        id:
          type: string
          examples:
            - cst_...
        session_token:
          type: string
        funding_intent_id:
          type: string
        expires_at:
          type: string
          format: date-time
    ErrorResponse:
      type: object
      required:
        - error
      properties:
        error:
          type: object
          required:
            - code
            - message
            - type
            - request_id
          properties:
            code:
              type: string
            message:
              type: string
            type:
              type: string
              enum:
                - validation_error
                - authentication_error
                - permission_error
                - not_found
                - conflict
                - rate_limit
                - provider_error
                - compliance_error
                - internal_error
            param:
              type:
                - string
                - 'null'
            retryable:
              type: boolean
            retry_after_seconds:
              type: integer
            docs_url:
              type: string
              format: uri
            request_id:
              type: string
  responses:
    Error:
      description: Error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
  securitySchemes:
    secretKey:
      type: http
      scheme: bearer
      description: Server-side only. Never ships to a browser.

````