Skip to main content
POST
Create a card reveal session
Sandbox only. This endpoint is available in sandbox only while we finish development. It is not available in production yet, and its request and response shapes may change before release.

Authorizations

x-api-key
string
header
required

Path Parameters

card_id
string
required

KSUID is a 27-character globally unique ID that combines a timestamp with a random component. Used for all entity identifiers in the Dakota platform.

Required string length: 27
Pattern: ^[0-9A-Za-z]{27}$
Example:

"1NFHrqBHb3cTfLVkFSGmHZqdDPi"

Body

application/json

Reveal session parameters

Parameters for minting a single-use card reveal session.

session_type
enum<string>
required

What the session authorizes. card_details displays the card's sensitive data; further session types are reserved for future card capabilities.

Available options:
card_details
Example:

"card_details"

origin
string
required

Canonical HTTPS origin of the page that will display the card — scheme and host only, with no path, query, or fragment.

Example:

"https://app.example.com"

Response

Reveal session created successfully.

A single-use credential the embedding page exchanges with the card provider to render the reveal surface. Never contains card data.

session
string
required

Opaque, single-use credential authorizing one reveal attempt.

expires_at
string<date-time>
required

Instant after which the session can no longer be redeemed.

Example:

"2026-07-22T15:04:05Z"

provider
string

Reserved routing discriminator. Optional and may be absent; consumers must ignore unknown fields and must not depend on this value.