Subscriptions

Create Payment Method Session

Create a short-lived session that lets this Subscription's customer update their payment method through the embeddable update element, without your page ever touching card data. Call it from your backend, then hand only the sessionToken to the embed script on your page — the secret key must never reach the browser. The token works only for this one Subscription and expires 15 minutes after it is minted; it is also retired as soon as an update completes, though a browser that never reports back leaves it usable until it expires — the 15 minutes is the guarantee. Mint a fresh token per attempt rather than storing one. Minting is rate-limited per Subscription; exceeding the limit returns 429. The Subscription must be in a state whose payment method can still be used for a future charge (active, trialing, past_due, unpaid or paused); other states return 400. Returns 403 when the embedded payment-method update feature is not enabled for your workspace.

Authorization

Public key Secret key
x-fngs-public-key<token>

In: header

x-fngs-secret-key<token>

In: header

Path Parameters

subscriptionIdOrNumber*string

Subscription identifier - the initial order number, exactly as returned in subscription.id. Omit the leading # the dashboard shows: a #-prefixed value passes validation but resolves to nothing. Payment-provider subscription ids are not accepted.

Match^#?([0-9A-Za-z]{12,32}|[0-9]+)(-[0-9]+)?$

Request Body

application/json

POST /v0/subscriptions/:subscriptionIdOrNumber/paymentMethodSession Request body

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

POST
/v0/subscriptions/{subscriptionIdOrNumber}/paymentMethodSession
curl -X POST "https://example.com/v0/subscriptions/ABC123DEF456/paymentMethodSession" \  -H "Content-Type: application/json" \  -d '{}'
{  "status": "success",  "data": {    "sessionToken": "string",    "expiresAt": -1.7976931348623157e+308,    "url": "string"  }}