> For a complete page index, fetch https://docs.transak.com/llms.txt # Create Widget URL POST https://api-gateway-stg.transak.com/api/v2/auth/session Content-Type: application/json This API creates a `widgetUrl` to securely store widget query parameters and authentication context. This facilitates secure widget interactions by encapsulating info in a sessionId, reducing exposure in client-side requests. Use the returned `widgetUrl` to load the Transak Widget. This URL expires 5 minutes after creation. **Important:** * Each `sessionId` is single-use. * The widget cannot be reopened using the same `widgetUrl`. * A new `sessionId` is required for every new user flow. | Environment | Base URL | | :---------- | :------------------------------------------------------------------------- | | Staging | [https://api-gateway-stg.transak.com](https://api-gateway-stg.transak.com) | | Production | [https://api-gateway.transak.com](https://api-gateway.transak.com) | Call this API only from the partner backend, with partner IPs whitelisted. Direct frontend calls are not supported. `apiKey` and `referrerDomain` are mandatory query parameters inside the `widgetParams` object. Reference: https://docs.transak.com/api/public/create-widget-url ## Request ### Headers - `x-user-ip` (string, required) — End user's originating IP. More details [here](/guides/mandatory-security-changes#user-ip-header-in-apis) - `x-api-key` (string, required) — Partner API Key present in Transak Dashboard. - `access-token` (string, required) — Your Partner Access Token. Please refer [here](/guides/how-to-create-partner-access-token) for a tutorial on generating your access token. - `authorization` (string, optional) — User Authorization Token. Only required in Integrations via User Authentication APIs. ### Body (application/json) This endpoint expects an object. - `widgetParams` (ApiV2AuthSessionPostRequestBodyContentApplicationJsonSchemaWidgetParams, required) — Transak Widget accepts query parameters as a JSON object. Below are some example query parameters. You can refer to the [complete list of Transak Query Parameters](/customization/query-parameters) for more configuration options. ## Response ### 200 Success - `data` (ApiV2AuthSessionPostResponsesContentApplicationJsonSchemaData, optional) ## Errors ### 400 Bad Request Error Bad Request - `error` (ApiV2AuthSessionPostResponsesContentApplicationJsonSchemaError, required) ### 401 Unauthorized Error Unauthorized - `error` (ApiV2AuthSessionPostResponsesContentApplicationJsonSchemaError, optional) ## Types ### ApiV2AuthSessionPostRequestBodyContentApplicationJsonSchemaWidgetParams Transak Widget accepts query parameters as a JSON object. Below are some example query parameters. You can refer to the [complete list of Transak Query Parameters](/customization/query-parameters) for more configuration options. - `apiKey` (string, required) — Your Api Key which you can get it from Transak Partner Dashboard for respective environment - `referrerDomain` (string, required) — For web integrations use the domain URL, and for mobile integrations use the application package name. - `cryptoCurrencyCode` (string, optional) — Specifies the code of the cryptocurrency for the transaction - `fiatCurrency` (string, optional) — Specifies the fiat currency code for the buy/sell. ### ApiV2AuthSessionPostResponsesContentApplicationJsonSchemaData - `widgetUrl` (string, optional) — Widget URL with embedded session token to launch the Transak widget ### ApiV2AuthSessionPostResponsesContentApplicationJsonSchemaError - `statusCode` (integer, optional, default: 0) - `message` (string, optional) - `errorCode` (integer, optional, default: 0) ## Examples **Request** ```json { "widgetParams": { "apiKey": "", "referrerDomain": "" } } ``` **Response** ```json { "data": { "widgetUrl": "https://global-stg.transak.com?apiKey=YOUR_API_KEY&sessionId=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJvdHQiOiI2YzgxMDFiMjlhMzg0YWE2YmRjM2JjMmFkODA1M2YzMyIsImlhdCI6MTc1NzMyNTkwNywiZXhwIjoxNzU3MzI2MjA3fQ.zooQ07sGOnI_2dwtIzYL5sOD-Z0wQZoahPxZqZcCVCI" } } ``` **SDK Code** ```python Success import requests url = "https://api-gateway-stg.transak.com/api/v2/auth/session" payload = { "widgetParams": { "apiKey": "", "referrerDomain": "" } } headers = { "access-token": "", "x-api-key": "", "x-user-ip": "", "Content-Type": "application/json" } response = requests.post(url, json=payload, headers=headers) print(response.json()) ``` ```javascript Success const url = 'https://api-gateway-stg.transak.com/api/v2/auth/session'; const options = { method: 'POST', headers: { 'access-token': '', 'x-api-key': '', 'x-user-ip': '', 'Content-Type': 'application/json' }, body: '{"widgetParams":{"apiKey":"","referrerDomain":""}}' }; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go Success package main import ( "fmt" "strings" "net/http" "io" ) func main() { url := "https://api-gateway-stg.transak.com/api/v2/auth/session" payload := strings.NewReader("{\n \"widgetParams\": {\n \"apiKey\": \"\",\n \"referrerDomain\": \"\"\n }\n}") req, _ := http.NewRequest("POST", url, payload) req.Header.Add("access-token", "") req.Header.Add("x-api-key", "") req.Header.Add("x-user-ip", "") req.Header.Add("Content-Type", "application/json") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby Success require 'uri' require 'net/http' url = URI("https://api-gateway-stg.transak.com/api/v2/auth/session") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Post.new(url) request["access-token"] = '' request["x-api-key"] = '' request["x-user-ip"] = '' request["Content-Type"] = 'application/json' request.body = "{\n \"widgetParams\": {\n \"apiKey\": \"\",\n \"referrerDomain\": \"\"\n }\n}" response = http.request(request) puts response.read_body ``` ```java Success import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.post("https://api-gateway-stg.transak.com/api/v2/auth/session") .header("access-token", "") .header("x-api-key", "") .header("x-user-ip", "") .header("Content-Type", "application/json") .body("{\n \"widgetParams\": {\n \"apiKey\": \"\",\n \"referrerDomain\": \"\"\n }\n}") .asString(); ``` ```php Success request('POST', 'https://api-gateway-stg.transak.com/api/v2/auth/session', [ 'body' => '{ "widgetParams": { "apiKey": "", "referrerDomain": "" } }', 'headers' => [ 'Content-Type' => 'application/json', 'access-token' => '', 'x-api-key' => '', 'x-user-ip' => '', ], ]); echo $response->getBody(); ``` ```csharp Success using RestSharp; var client = new RestClient("https://api-gateway-stg.transak.com/api/v2/auth/session"); var request = new RestRequest(Method.POST); request.AddHeader("access-token", ""); request.AddHeader("x-api-key", ""); request.AddHeader("x-user-ip", ""); request.AddHeader("Content-Type", "application/json"); request.AddParameter("application/json", "{\n \"widgetParams\": {\n \"apiKey\": \"\",\n \"referrerDomain\": \"\"\n }\n}", ParameterType.RequestBody); IRestResponse response = client.Execute(request); ``` ```swift Success import Foundation let headers = [ "access-token": "", "x-api-key": "", "x-user-ip": "", "Content-Type": "application/json" ] let parameters = ["widgetParams": [ "apiKey": "", "referrerDomain": "" ]] as [String : Any] let postData = JSONSerialization.data(withJSONObject: parameters, options: []) let request = NSMutableURLRequest(url: NSURL(string: "https://api-gateway-stg.transak.com/api/v2/auth/session")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "POST" request.allHTTPHeaderFields = headers request.httpBody = postData as Data let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```