Create an embedded-components account session
Mints a Stripe Account Session client secret for the embedded Connect components (account_onboarding, payouts, payments). Omit accountId to use the caller's most recent connected account.
Ownership: an explicit accountId must be a connected account the caller owns: their own account, or an organization's account where the caller holds org.manage_payouts in that organization. Any other id, including one that does not exist, returns 404 and no session is created.
Requires a bearer session; rate limited to 100 requests per minute per account.
Authorizations
In the browser, authentication rides on the httpOnly session cookies set by /cognito/signin or the Google / Apple sign-in at /cognito/oauth/{provider}. For scripts and for Swagger UI testing, paste an API key (fh_live_…, created with POST /api-keys); a Cognito JWT is accepted too. Sign-in does not return a token in its body.
Request Body
Responses
Account session