Skip to main content
POST
cURL
Slash Payment Processing is in beta and not enabled for all accounts. Contact support@joinslash.com to get access.

Authorizations

X-API-Key
string
header
required

API key authentication for public API requests.

Keys come in two flavors:

  • Legal-entity-scoped keys are pinned to a single legal entity. Minted via the dashboard under a specific entity; every request acts on that entity.
  • User-scoped keys are pinned to a user and span every legal entity that user has access to. Every request made with a user-scoped key (except GET /legal-entity, which lists the legal entities the user can access) must include an x-legal-entity header naming the legal entity the request is operating on. Requests without the header are rejected with 400. The authenticated user must have an active permission role on the supplied legal entity, otherwise the request is rejected with 403.

Headers

X-Idempotency-Key
string
required

A unique key for this checkout session. Retrying a request with the same key returns the previously created session instead of creating a new one.

Body

application/json
amount
integer
required

Payment amount in cents. Must be strictly positive.

Required range: x >= 1
currency
enum<string>
required

ISO currency code for the payment. Only usd is currently supported.

Available options:
usd
customMetadata
object

Custom metadata to associate with the checkout session. Echoed on webhook events for this session.

config
object

Configuration for the hosted checkout page. Echoed on reads and editable while the session is open.

expiresAt
string<date-time>

ISO-8601 timestamp after which the session can no longer be paid. Defaults to 24 hours after creation. Must be at least 30 minutes and at most 7 days in the future.

Response

OK

checkoutSession
CheckoutSession · object
required

A checkout session represents a single hosted payment attempt. Embed the session's url in your page (via the Slash checkout SDK or an iframe) to collect a card payment.