Skip to main content
POST
Create a hosted pick-and-connect link for a client

Authorizations

Authorization
string
header
required

Pass your secret key in the Authorization header as a Bearer token: Authorization: Bearer sk_test_... (sandbox) or Bearer sk_live_... (production).

Keys are created in the developer portal and the plaintext secret is shown exactly once at creation. Treat them like passwords — never embed them in mobile apps or front-end code.

Headers

Idempotency-Key
string

Safe-retry key for POSTs. Send any unique string per logical request (a UUIDv4 is great). If the network drops and you retry with the same Idempotency-Key within 24 hours, you get the exact same response back instead of creating a duplicate. A replayed response carries Idempotent-Replayed: true.

Cached responses include failures (4xx and 5xx) too. If a call failed because of a bad input and you want to try again with the corrected input, use a fresh key — otherwise you'll keep getting the cached failure.

If the original request is still running you get 409 with a Retry-After header. Retry with the same key after that interval. Do not generate a new key to get past a 409 — a new key is a new request, which is exactly the duplicate this header prevents.

Reusing a key for a genuinely different request (different body, or a different path) returns 409 idempotency_conflict. The key is scoped to the API key that first used it, so a sandbox key and a live key never share an entry.

A replay still counts against your request rate limit, but it does not consume the daily refresh budget on POST /connections/{connection_id}/refresh, and it does not take a connection-concurrency slot.

Maximum string length: 255
Example:

"6f1a8c50-3e9c-4d4a-b1f5-2c5b9a2f7d11"

Path Parameters

client_id
string
required

Body

application/json
redirect_url
string<uri>

Where to send the member after a successful connect. Must exactly match one of your allowlisted redirect URLs for this environment. Omit to end on the connect widget's own success screen.

Response

A hosted connect link.

sid
string
required

This session's opaque id. Pass it to DELETE /v3/clients/{client_id}/connect-session/{sid} to kill the link before it expires. It is also the link's credential, since the url carries it, so keep it server-side and never hand it to anyone you would not hand the link itself.

Example:

"9f2c4b7e1a8d6350f4e2c9b7a1d83e56"

url
string<uri>
required

The LedgerSync-hosted page to send the member to.

expires_at
string<date-time>
required

When the link stops working. To kill it sooner, call DELETE /v3/clients/{client_id}/connect-session/{sid} with the sid above.