> ## Documentation Index
> Fetch the complete documentation index at: https://docs.useroutr.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Mint a short-lived token for a wallet app round trip

> The session token never travels through a deep link or a URL bar. This
one does, is single use, and expires in about a minute.




## OpenAPI

````yaml /api-reference/openapi.yaml post /checkout_sessions/{id}/handoff
openapi: 3.1.0
info:
  title: Useroutr API
  version: 1.0.0
  description: |
    Universal application funding. Users fund an application with whatever they
    hold, on whatever rail, and the application receives exactly what it needs,
    credited exactly once.

    This document is the single source of truth for every wire type. Server
    handlers, the SDK, the checkout, and the dashboard all consume types
    generated from it. A handler change without a regenerated type fails CI.
servers:
  - url: https://api.useroutr.com/v1
    description: Production
  - url: https://api.sandbox.useroutr.com/v1
    description: Sandbox
security:
  - secretKey: []
tags:
  - name: Funding intents
  - name: Funding addresses
  - name: Customers
  - name: Registry
  - name: Webhooks
paths:
  /checkout_sessions/{id}/handoff:
    post:
      tags:
        - Checkout
      summary: Mint a short-lived token for a wallet app round trip
      description: |
        The session token never travels through a deep link or a URL bar. This
        one does, is single use, and expires in about a minute.
      operationId: createHandoff
      parameters:
        - name: id
          in: path
          required: true
          schema:
            type: string
        - $ref: '#/components/parameters/IdempotencyKey'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - code_challenge
              properties:
                code_challenge:
                  type: string
                  minLength: 43
                  description: >
                    Base64url SHA-256 of a verifier your browser keeps.
                    Required,

                    not optional: a handoff token travels through a URL and must

                    be assumed to leak, and an optional binding is one an

                    attacker can strip.
      responses:
        '201':
          description: The handoff token.
          content:
            application/json:
              schema:
                type: object
                required:
                  - handoff_token
                  - expires_at
                properties:
                  handoff_token:
                    type: string
                  expires_at:
                    type: string
                    format: date-time
        default:
          $ref: '#/components/responses/Error'
components:
  parameters:
    IdempotencyKey:
      name: Idempotency-Key
      in: header
      required: true
      description: Required on every mutating request. Absent is a 400.
      schema:
        type: string
        minLength: 8
        maxLength: 200
  responses:
    Error:
      description: Error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
  schemas:
    ErrorResponse:
      type: object
      required:
        - error
      properties:
        error:
          type: object
          required:
            - code
            - message
            - type
            - request_id
          properties:
            code:
              type: string
            message:
              type: string
            type:
              type: string
              enum:
                - validation_error
                - authentication_error
                - permission_error
                - not_found
                - conflict
                - rate_limit
                - provider_error
                - compliance_error
                - internal_error
            param:
              type:
                - string
                - 'null'
            retryable:
              type: boolean
            retry_after_seconds:
              type: integer
            docs_url:
              type: string
              format: uri
            request_id:
              type: string
  securitySchemes:
    secretKey:
      type: http
      scheme: bearer
      description: Server-side only. Never ships to a browser.

````