Create Redirect Session
Returns a fresh 10-minute handoff for a redirect payout.
POST
/api/payout/{payout_id}/sessionAuthentication
Scope: payouts:write
Authorization: Bearer <YOUR_PAYOUT_KEY>
Idempotency-Key: <unique key per attempt>
Request Parameters
| Field | Type | Description | Required |
|---|---|---|---|
payout_id | string | Path parameter. Must be a redirect payout | ✅ |
customer_id | string | Must match the payout's binding | ✅ |
customer_id asserts who you have just authenticated — you are not choosing a
recipient. It must equal the customer_id the payout was created with.
Response Fields
{
"payout_id": "po_9f3c1d7b2a8e4c15d0b6a291",
"payout_url": "https://luxfin.org/payouts/po_9f3c…/start#handoff=…",
"access_link_expires_at": "2026-09-28T09:24:22Z"
}
| Error | HTTP | Meaning |
|---|---|---|
wrong_delivery | 409 | This is a link payout |
customer_mismatch | 403 | customer_id differs from the payout's binding |
not_resumable | 409 | The payout is no longer open (paid, cancelled, expired or failed) |
Behavior
The handoff is valid for 10 minutes, single use, and never past the payout's
own payout_expires_at. Redirect the customer's browser to it right away. A new
session invalidates the earlier ones and does not extend any deadline. Only redirect payouts support sessions; link
payouts use claim links.
Request Samples
curl -s -X POST https://luxfin.org/api/payout/po_9f3c1d7b2a8e4c15d0b6a291/session \
-H "Authorization: Bearer $PAYOUT_KEY" \
-H "Idempotency-Key: $(uuidgen)" \
-H "Content-Type: application/json" \
-d '{"customer_id": "cust_48213"}'