API/Hosted sessions
v1.0.0-beta.mdGet API keys
Hosted sessions

Hosted sessions

A single-use token minted by your server and exchanged exactly once by the hosted screen. No redirect URL, and the browser never carries the amount.

CallPageWhat it does
POST hosted-session-createsessions/createYour server mints the single-use token
POST hosted-session-consumesessions/consumeThe hosted screen exchanges it, once, atomically

Branding comes from merchant-theme-get, not from the session. Hosted sessions emit no webhooks.

Sidaxis is the human authorisation layer. It never moves money, holds funds or settles. The machine-readable contract is openapi.yaml.
Sidaxis API documentationQuickstartAuthenticationHosted or headlessSandbox and productionIdempotencyRate limitsErrors and refusalsField namesWebhooksAssuranceThe document ruleAlias availabilityMerchant themeMCP serverCompatibilityStatusRoadmapChangelogIdentityEnroll an identityRecognise a personDisclose an attributeMandatesThe eight scopesIssue a mandateCheck an actionConsume a mandateRead a mandateRevoke a mandateReceiptsRead a merchant's receiptsVerify a receiptHosted sessionsCreate a hosted sessionConsume a hosted sessionOne Face for agents