/v1/session

Create customer session via merchant's authentication

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…

Creates a single sign-on (SSO) link into the Frisbii Customer Portal for one of your
customers. Use it when the customer is already authenticated in your own system (web shop,
app, self-service area) and you want a "My subscriptions" / "My invoices" button that takes
them straight into the portal — without the one-time password email of the
OTP flow.

POST https://customer-portal-api.reepay.com/v1/session

Authentication

Authenticate with your private API key using HTTP Basic auth (key as username, empty
password). The account is derived from the key, which is why — unlike the OTP endpoints —
there is no accountId in the path.

Requires the Customer Portal feature on your plan. Without it the request is rejected with
Feature: customer_portal is not enabled for your account.

Request

FieldTypeRequiredDescription
emailstringyesEmail of the customer to sign in. Validated against RFC 822.

The customer is looked up by email on your account:

  • Deleted customers are ignored.
  • If several non-deleted customers share the email, the most recently created one is used.
  • If no customer matches, the request fails with 404 Not Found (customer not found).
    Create the customer first, or use the customer's email exactly as stored on the customer
    object — the lookup is an exact match, not a search.
curl -X POST https://customer-portal-api.reepay.com/v1/session \
  -u "priv_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx:" \
  -H "Content-Type: application/json" \
  -d '{"email": "[email protected]"}'

Response

{
  "redirect_url": "https://customer-portal.frisbii.com/#/auth/login?session=customer_os8du201987e23418sdf969faw56973c"
}

Send the customer to redirect_url — typically an HTTP 302 from your own backend, or
window.location = redirect_url. The session token is embedded in the URL, so the portal logs
the customer in with no further steps. Treat the URL as opaque: do not parse, rewrite or
append to it.

Lifetime and session reuse

This is the part worth reading before you integrate:

  • A customer session is valid for 1 hour from the moment the session was created.
  • This endpoint does not always create a new session. If an active session already exists
    for that email on your account, the newest one is reused and its link is returned.
  • Reuse spans both flows: a session created by the OTP endpoint counts, and so does a session
    the customer has already logged in with.

The practical consequence: the returned link is not guaranteed to be valid for a full hour.
If the reused session was created 55 minutes ago, the link works for 5 more minutes. So:

  • Generate the link at click time, in the request that redirects the customer. Do not
    generate links ahead of time, cache them, or store them in a database.
  • Do not email or message the link. It can already be expired by the time it is read, and
    it is a credential (see below).
  • If the customer logs out of the portal, the session is deleted immediately and any link
    pointing at it stops working. Calling this endpoint again returns a fresh session.
  • Sessions are hard-deleted a few hours after creation; expired links land on the portal login
    page rather than an error.

Security

redirect_url is a bearer credential: anyone holding it can see and change that customer's
subscriptions, invoices and payment methods until the session expires.

  • Call this endpoint server-side only. Your private API key must never reach the browser.
  • Only call it for a customer that the current visitor is already authenticated as in your own
    system — the endpoint performs no verification beyond "this email exists on your account".
  • Redirect over HTTPS and avoid writing the URL to logs, analytics or referrer-leaking pages.

Rate limits

The 30-second cooldown and 10-active-session cap of the OTP flow do not apply here — you
can call this endpoint repeatedly for the same customer (subsequent calls return the same
session while it is active). Standard API rate limiting still applies and is reported as
429 with error codes 122/123.

Errors

StatusWhen
400Invalid request body, e.g. missing or malformed email.
401 / 403Missing, invalid or non-private API key; Customer Portal not enabled on the plan.
404No non-deleted customer with that email exists on the account.
429Rate or concurrency limit exceeded (error codes 122 and 123).

See the full list at error codes.

Body Params
string
required

Customer email. Validated against RFC 822.

Responses

Language
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json