> ## Documentation Index
> Fetch the complete documentation index at: https://docs.whop.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create Confirmation Token

> Mints a single-use, short-lived confirmation token from what the buyer entered on your collection surface: the payment method payload, billing details, and attested save consent. Public and rate-limited — the account_id in the body scopes the token but does not authenticate. Confirm it with POST /payments from your server.



## OpenAPI

````yaml /openapi/api-v1-native.json post /confirmation_tokens
openapi: 3.1.0
info:
  description: >-
    The Whop REST API. Please see
    https://docs.whop.com/developer/api/getting-started for more details.
  termsOfService: https://whop.com/tos-developer-api/
  title: Whop API
  version: 1.0.0
  x-api-version-date: 2026-08-25-2
servers:
  - description: Production Whop API
    url: https://api.whop.com/api/v1
  - description: Sandbox Whop API
    url: https://sandbox-api.whop.com/api/v1
security: []
tags:
  - description: >
      An Account represents a person or business on Whop that can have its own
      profile, wallet, and account-scoped settings. Use accounts for customers,
      creators, merchants, sellers, or connected businesses your integration
      supports.


      Use the Accounts API to create accounts, list accounts visible to your
      credentials, retrieve or update an account, suspend a connected account
      managed by your platform, and retrieve the account associated with the
      current API key.
    name: Accounts
    x-whop-summary: 'A business on Whop: profile, wallet, capabilities, settings.'
  - description: >
      A User represents a person on Whop. Users have a public profile and can
      buy products, join accounts, and access experiences.


      Use the Users API to search for users, retrieve or update profiles, and
      check whether a user has access to an account, product, or experience.
    name: Users
    x-whop-summary: 'A person on Whop: profile and connected identities.'
  - description: >
      A Team Member is a member of an account's team: the link between a user
      and an account, carrying the role that controls what they can do. Roles
      are either system roles (like `admin` or `moderator`) or `custom` roles
      managed from the dashboard.


      Use the Team Members API to list an account's team, add a user to the team
      with a system role, change a member's role, and remove members. Adding a
      user who has not yet accepted sends an invitation instead.
    name: Team Members
    x-whop-summary: An account's team members and the roles that scope their access.
  - description: >
      A Member is one buyer's relationship with an account — one record per
      customer regardless of how many memberships they hold. It carries
      relationship-level state: whether they have joined or left, their access
      level (`customer`, `admin`, or `no_access`), when they joined, and when
      they last opened the account's content.


      Use the Members API to list an account's members with filtering by access
      level, status, join date, and name or username search, and to retrieve a
      single member. Member rows are created and maintained by the membership
      lifecycle; to grant or revoke access, work with memberships instead.
    name: Members
    x-whop-summary: One buyer's relationship with an account, across all their purchases.
  - name: Webhooks
    x-whop-summary: Event notifications pushed to your server as things happen.
  - description: >
      Stats represent aggregated activity for an account over time. They help
      you understand revenue, transactions, disputes, members, referrals, and
      advertising performance across reporting periods like days, weeks, or
      months.


      Use the Stats API to list available metrics and their filterable
      properties, then retrieve time-series values for a date range.
    name: Stats
    x-whop-summary: Aggregated financial, audience, and traffic reporting.
  - description: >
      A Verification represents a legal identity for a person or business.
      Accounts and users complete verification when Whop needs to confirm who
      they are before enabling payouts or compliance-sensitive workflows.


      Use the Verifications API to start or resume a hosted verification
      session, check review status, and submit requested details or documents.
      If `requested_information` contains items, submit answers with [Update
      Verification](/api-reference/beta/verifications/update-verification).
    name: Verifications
    x-whop-summary: Legal identity required before payouts and card issuing.
  - description: >
      An Export is an asynchronous CSV of one resource for one account —
      members, payments, disputes, ads, and the other tables the Whop dashboard
      can export. Generating a full table takes longer than a request, so an
      export is created in `pending`, moves through `processing`, and lands on
      `completed` with a download link. Each resource requires that resource's
      own export scope.


      Use the Exports API to start an export, poll it until `download_url` is
      set, and list the exports already requested for an account. Finished CSVs
      are retained for 30 days, after which the file is deleted and the export
      moves to `expired`.
    name: Exports
    x-whop-summary: Asynchronous CSV dumps of an account's dashboard data.
  - description: >
      A Notification is a message delivered to a user — a new post, a payment, a
      mention. Every notification comes from an experience the user belongs to
      or a team they are on, and users control what they receive with
      notification preferences.


      Every notification belongs to a topic: the category it falls under, such
      as new sales or account activity. Topics carry a default, so a user only
      needs a preference row where they diverge from it. `GET
      /notifications/topics` lists the platform's visible topics, and a topic's
      `id` is what the notification preference endpoints take as `topic_id` —
      the catalog is the only place those ids come from, so read it rather than
      hardcoding. Each topic also carries an `identifier` such as
      `new-follower`, which is stable across environments and is the value to
      match on in code.


      Use the Notifications API to list the authenticated user's feed, read
      per-experience unread badges, mark an experience (or everything) as read,
      send notifications from your app to an experience's users or an account's
      team, and list the topic catalog.
    name: Notifications
    x-whop-summary: >-
      The user's notification feed: unread badges, mark-read, app sends, and the
      topic catalog.
  - description: >
      A Payment is one charge against a buyer. Create an on-session payment with
      a `confirmation_token` for the method the buyer selected, or an
      off-session payment with an existing member's stored payment method.


      Collection runs in the background, so the create response is not the
      outcome. Poll [Retrieve
      status](/api-reference/beta/payments/retrieve-status) for how far the
      payment has got and, while it is `requires_action`, what the buyer must do
      next — follow a redirect, complete 3D Secure, display transfer
      instructions, or link a bank account. Use the return_url operation to
      change where they land afterwards, up until they come back.
    name: Payments
    x-whop-summary: A charge against a buyer, and the step they still owe.
  - description: >
      A Confirmation Token is a single-use, short-lived reference to a payment
      method and billing details collected from a buyer. Its response contains
      only a display-safe preview and never returns the underlying payment
      credential.


      Create a confirmation token in a buyer-facing collection flow, then send
      its `ctok_` ID to the Payments API from your server. Retrieve a token to
      display its payment method and billing preview or check whether it is
      still usable.
    name: Confirmation Tokens
    x-whop-summary: A short-lived reference to payment details collected from a buyer.
  - description: >
      A Setup Intent saves a buyer's payment method for later without taking
      money now. It runs the same collection flow a payment does, so the buyer
      may still owe a step — 3D Secure on a card, a hosted enrollment, or
      linking a bank account.


      Poll [Retrieve status](/api-reference/beta/setup-intents/retrieve-status)
      for how far the setup has got and what is outstanding. Once it reaches
      `succeeded` the method is on file and can be charged.
    name: Setup Intents
    x-whop-summary: Saving a buyer's payment method without charging it.
  - description: >
      A Ledger Activity row is a single financial event on an account's ledger —
      a payment, payout, refund, transfer, on-chain deposit, swap, or card
      transaction. Each row is derived from the underlying ledger lines and
      carries a typed `resource` and `source` so you can present and link the
      event without extra lookups.


      Use Ledger Activity to build a statement or transaction feed for an
      account or user. Reconcile against your own records with `amount` (signed,
      in the currency's smallest precision units) and `posted_at`, and use
      `available_at` to know when inflows became withdrawable.
    name: Ledgers
    x-whop-summary: The activity feed behind an account or user's balance.
  - description: >
      Payouts represent money sent from an account or user balance to an
      external destination, such as a bank account, wallet, or other saved
      payout method.


      Use the Payouts API to create and track payouts, manage saved payout
      methods, and show expected arrival details for funds leaving Whop.
    name: Payouts
    x-whop-summary: Send money from a balance to a bank or wallet.
  - description: >
      Cards represent Whop-issued virtual payment cards that spend from an
      account or user balance. Cards can be assigned to cardholders and
      configured with spending limits for controlled spending.


      Use the Cards API to issue cards, list cards for an account or user, and
      retrieve active card details such as the card number and CVC.
    name: Cards
    x-whop-summary: Issue cards that spend from a balance.
  - description: >
      Transfers move value between identities on Whop. They are used for
      account-to-account money movement, user payouts inside Whop, crypto
      transfers, and claim links depending on the destination type.


      Use the Transfers API to create a transfer, list previous transfers, and
      retrieve a transfer by ID when reconciling money movement between accounts
      or users.
    name: Transfers
    x-whop-summary: Move funds between Whop accounts and users.
  - description: >
      A Dispute is a chargeback a customer files against a payment through their
      bank, or an inquiry that may become one. It carries the disputed payment,
      a deadline to respond, your evidence, and the outcome once the processor
      rules.


      Use the Disputes API to list disputes, edit the evidence packet while a
      dispute is still contestable, and submit it for review.
    name: Disputes
    x-whop-summary: Chargebacks filed against an account, with evidence and outcomes.
  - description: >
      A Dispute alert is an early warning from a card issuer that a settled
      payment is being questioned, ahead of any chargeback. `type` separates
      fraud reports (`early_fraud_warning`), pre-dispute notices
      (`dispute_alert`), and Visa RDR cases the network already closed by
      refunding (`rapid_dispute_resolution`).


      Use the Dispute alerts API to list alerts for an account, filter them by
      type or payment, and read `actionable` to see whether refunding can still
      avoid the chargeback.
    name: Dispute alerts
    x-whop-summary: Issuer warnings that arrive before a chargeback does.
  - description: >
      Deposits describe ways to add funds to an account balance, including
      hosted deposit pages, bank deposit instructions, and supported crypto
      wallet addresses.


      Use the Deposits API to create deposit instructions for an account.
    name: Deposits
    x-whop-summary: Add funds to a balance.
  - description: >
      Swaps convert value between supported tokens, chains, or wallet
      destinations for an account. A swap quote describes the expected output,
      fees, and approval requirements before you create the swap.


      Use the Swaps API to quote a conversion, create the swap, list recent
      swaps, and retrieve status until the transaction completes.
    name: Swaps
    x-whop-summary: Convert a balance between currencies.
  - description: >
      A Resolution Center Case is opened by a buyer when something is wrong with
      a purchase — an unwanted renewal, an item that never arrived, or a charge
      they don't recognize. It is the step before a chargeback: the two sides
      work it out directly, and Whop decides the case if they can't. Each case
      carries a reason, a status naming which side it is waiting on, a timeline
      of events, and the actions available to whoever is reading it.


      Use the Resolution Center Cases API from either side: as the buyer, open a
      case, reply, appeal a decision, or withdraw it; as the merchant, accept it
      (refunding the payment), deny it, or ask the buyer for more information.
      Both sides read the same case, page its timeline, and summarize the cases
      they can see.
    name: Resolution Center Cases
    x-whop-summary: File or respond to a case against a payment, as the buyer or the merchant.
  - description: >
      A Product is a digital good or service sold on Whop. Products may contain
      plans for pricing and/or experiences for content delivery.


      Use the Products API to search the public marketplace, list an account's
      products, retrieve a product, and create, update, or delete products.
    name: Products
    x-whop-summary: The things you sell. Each owns plans and a store page.
  - description: >
      A Plan defines how customers buy a product. It controls pricing, billing
      cadence, availability, tax behavior, checkout fields, and purchase
      visibility.


      Use the Plans API to create plans for products, list existing plans,
      retrieve or update plan configuration, calculate tax for checkout, and
      delete plans that should no longer be offered.
    name: Plans
    x-whop-summary: 'Pricing for a product: one-time, recurring, trials, stock.'
  - name: Promo Codes
    x-whop-summary: Discounts that creators configure for checkout.
  - description: >
      A Membership is a customer's purchase of a plan: the subscription or
      one-time grant that gives them access to a product. It tracks billing
      state (`active`, `trialing`, `past_due`, and so on), the current period,
      pending cancellations, custom metadata, and the software license key when
      the product includes licensing.


      Use the Memberships API to list an account's memberships or the caller's
      own, retrieve one by ID or license key, invite a recipient to join through
      a free plan, and manage the lifecycle: cancel immediately or at period
      end, reverse a scheduled period-end cancellation, pause and resume payment
      collection, extend with free days, generate a transfer link, and update
      metadata.
    name: Memberships
    x-whop-summary: A customer's purchase of a plan, from checkout through cancellation.
  - description: >
      A Checkout Configuration is a reusable checkout link owned by an account.
      In `payment` mode it sells a specific plan; in `setup` mode it collects
      and saves payment details without charging. Each configuration can also
      override which payment methods are accepted and how 3D Secure is enforced
      for that checkout.


      Use the Checkout Configurations API to create checkout links for an
      existing or inline plan, list configurations for an account, retrieve the
      configuration behind a checkout URL, and delete links that should no
      longer be used.
    name: Checkout Configurations
    x-whop-summary: Turn a plan into a shareable, prefilled checkout link.
  - description: >
      A Payment Method Domain registers a hostname with a wallet provider so its
      payment methods can appear at a checkout served from that domain. The
      domain proves ownership by hosting the provider's association file — for
      Apple Pay, at `/.well-known/apple-developer-merchantid-domain-association`
      — and `status` reports whether verification has completed.


      Use the Payment Method Domains API to register domains for your account or
      its connected accounts, retry verification once the association file is
      hosted, and remove domains that should no longer serve wallet payments. A
      domain a platform shares with its connected accounts at checkout is listed
      on the platform's account, not on each connected account.
    name: Payment Method Domains
    x-whop-summary: >-
      Domains verified to show wallet payment methods like Apple Pay at
      checkout.
  - description: >
      A Shipment attaches a carrier tracking number to a payment and follows the
      package from label creation to delivery, exposing the current delivery
      status and a customer-facing tracking URL.


      Use the Shipments API to list an account's shipments, retrieve one by its
      id or the payment it fulfills, attach a tracking number to a payment, and
      update the tracking number on an existing shipment.
    name: Shipments
    x-whop-summary: Track the delivery of an order by its carrier tracking number.
  - description: >
      The Partners API covers your Whop partner activity: the users you referred
      onto Whop, the businesses you referred and the earnings generated from
      their processing volume, and the partner leaderboard.


      Use it to enroll as a Whop partner, list the users you referred, list your
      referred businesses and review their earnings, and see the partner
      leaderboard.
    name: Partners
    x-whop-summary: >-
      The users and businesses you referred to Whop, and what you earn from
      them.
  - description: >
      A Bounty is a paid task posted by an account or user. The reward is held
      in escrow when the bounty publishes, workers submit proof of completed
      work, and each accepted submission is paid out until every winner slot
      fills.


      Use the Bounties API to create and publish a bounty, list an account's
      bounties for reporting or dashboards, list the bounties a user can work or
      has participated in, and retrieve a single bounty by ID.
    name: Bounties
    x-whop-summary: Paid tasks with reviewed submissions and escrowed rewards.
  - description: >
      A Bounty Submission is one worker's attempt on a bounty. It starts as an
      in-progress attempt, enters the review queue when proof is submitted, and
      ends approved (paid from the bounty's escrowed pool) or denied.


      Use the Bounty Submissions API to submit proof of completed work to a
      bounty, list the submissions you authored, and review the submissions on
      your bounties — across every bounty or narrowed to one.
    name: Bounty Submissions
    x-whop-summary: Work submitted to a bounty, from attempt to payout.
  - description: >
      A Person is an identity-linked profile of a visitor or customer of an
      account, assembled from every [event](/api-reference/beta/events/event)
      the person generated — pixel page views, ad clicks, leads, identifies, and
      payments. Each profile carries the person's known identities (names,
      emails, phones, user IDs), purchase history and LTV, geo/device profile,
      traffic sources, and the first and last marketing touches that reached
      them.


      Use the People API to list and segment the people of an account — filter
      by activity, purchases, traffic source, location, or marketing touch, and
      sort by value — or retrieve one person by person ID, user ID, email
      address, or phone number.
    name: People
    x-whop-summary: >-
      Visitors and customers of an account, with identity, purchase, and traffic
      profiles.
  - description: >
      An Event records conversion or engagement activity for an account, such as
      page views, purchases, or leads. Each event ties the action to the
      [person](/api-reference/beta/people/person) who took it, so activity can
      be attributed to the ads and links that drove it.


      Use the Events API to send new tracking events, list recent
      identity-linked events for an account, and inspect the events recorded for
      a person. The resource also exposes an anonymized read mode — the pulse
      feed — a platform-wide snapshot of recent purchases that carries nothing
      identifying. The pulse feed is public; other Events endpoints require
      authentication and are scoped to an account.


      Events are only as good as the pixel sending them, so [Validate
      Pixel](/api-reference/beta/events/validate-pixel) answers whether an
      account's pixel is working: it reads the events the pixel has sent, and
      when you pass a `url` whose page hasn't sent any lately, it fetches that
      page and looks for the pixel in its source. Use it before launching an ad
      to confirm its destination is tracked, or in a setup flow to tell a
      merchant whether their install is live.
    name: Events
    x-whop-summary: Conversion and engagement events tracked for attribution.
  - description: >
      A Recommended Action Chain is a short, ordered sequence of dashboard
      actions — create a product, price it, publish it — suggested for an
      account based on what it already has. Seeded chains come from hand-written
      presets; generated chains, produced per account, share the same shape.


      Use the Recommended Actions API to list the chains recommended for an
      account and to record that a chain was run. Running a chain executes
      nothing server-side — the client follows each step's CTA itself; the run
      endpoint records the `recommended_action_chain.executed` analytics event.
    name: Recommended Actions
    x-whop-summary: Suggested next-step action chains for an account.
  - description: >
      An Ad is the individual creative unit delivered by an [ad
      group](/api-reference/beta/ad-groups/ad-group). It holds the copy,
      creative assets, and destination URL for one ad.


      Use the Ads API to list ads for an account, create ads inside ad groups,
      retrieve or update creative details, delete ads that should stop running,
      and pause or resume delivery.
    name: Ads
    x-whop-summary: 'The creative: copy, assets, and destination URL.'
  - description: >
      An Ad Campaign is the top-level container for paid ads on an ad network.
      It sets the platform, objective, and budget strategy shared by its [ad
      groups](/api-reference/beta/ad-groups/ad-group) and ads.


      Use the Ad Campaigns API to create campaigns, list campaigns for an
      account, retrieve or update campaign settings, and pause or resume
      campaign delivery.
    name: Ad Campaigns
    x-whop-summary: Platform, objective, and budget for a set of ads.
  - description: >
      An Ad Group sits inside an [ad
      campaign](/api-reference/beta/ad-campaigns/ad-campaign) and controls
      delivery for [ads](/api-reference/beta/ads/ad). It sets the audience,
      placements, schedule, budget, and optimization goal for its ads.


      Use the Ad Groups API to create ad groups in campaigns, list or retrieve
      targeting and delivery settings, update budgets or targeting, delete
      groups that should stop running, and pause or resume delivery. It can also
      search the ad platform's targeting taxonomy for options to target and
      estimate how many people a draft targeting spec can reach.
    name: Ad Groups
    x-whop-summary: Audience, placements, and schedule within a campaign.
  - description: >
      An Audience represents a customer list uploaded to Whop for ad targeting.
      Audiences belong to an account and sync to supported ad platforms as
      custom audiences.


      Use the Audiences API to create audiences from CSV uploads, monitor
      processing status, and list or delete audiences for an account. Created
      audiences are usable for targeting after processing reaches `ready` or
      `partial`.
    name: Audiences
    x-whop-summary: Reusable targeting lists for ad groups.
  - description: >
      A File is an uploaded document or media object, identified by a `file_`
      ID. Creating a file returns a presigned destination; upload the bytes
      there and the file becomes `ready`.


      Use the Files API to create a file, upload its content directly to storage
      (in one PUT, or in parts for large files), and retrieve it while polling
      for readiness. A ready file's ID can be attached wherever Whop accepts
      files.
    name: Files
    x-whop-summary: Upload files and attach them wherever Whop accepts documents.
  - description: >
      A Media Asset is an AI-generated image or video created from a prompt and
      billed from an account balance. When generation finishes, the asset
      includes a file that can be attached anywhere Whop accepts files.


      Use the Media API to start a generation job and retrieve the asset while
      it processes or after it is ready.
    name: Media
    x-whop-summary: >-
      AI-generated assets, billed from a balance, attachable wherever files are
      accepted.
  - description: >
      A Social Account represents an external profile connected to a Whop
      account or user, such as a Facebook page or Instagram account. Connecting
      a social account lets Whop run [ads](/api-reference/beta/ads/ad) under
      that profile's identity and promote its existing posts.


      Use the Social Accounts API to list connected accounts, create a
      Whop-managed Facebook page, start an OAuth connection, disconnect a social
      account, and list a connected profile's posts or a Facebook page's lead
      forms.
    name: Social Accounts
    x-whop-summary: Connected Facebook and Instagram accounts that run ads.
  - description: >
      An App is software you build on Whop. It can be a hosted web app served at
      `<route>.whop.site` or an API integration installed as an experience, and
      it belongs to the account that owns its credentials, settings, builds, and
      runtime logs.


      Use the Apps API to manage app configuration, deploy an app's working copy
      and follow the run on the app's `deployment` field, and, for hosted apps,
      read server runtime logs for console output, uncaught exceptions, and
      failed requests. Logs are retained for 7 days and can be filtered by
      build, level, time window, and message text.


      Apps are also reusable blueprints. List official blueprints with
      `app_type=website&verified=true&order=template_usage`, or community
      blueprints with
      `app_type=website&verified=false&recommended=true&order=template_usage`.
      Pass the returned App `id` as `blueprint_id` when creating an Account.
    name: Apps
    x-whop-summary: 'Apps you build on Whop: metadata, hosted builds, runtime logs.'
  - description: >
      An App Build is a versioned artifact uploaded for an app — a hosted web
      archive, or an iOS/Android bundle. Builds start as drafts, go through
      review, and one approved build per platform is served to users as the
      production build.


      Use the App Builds API to upload a build for an app, list an app's builds
      with platform and status filters, retrieve a build, and promote a draft or
      approved build to production.
    name: App Builds
    x-whop-summary: Versioned build artifacts deployed to an app's platforms.
  - description: >
      An API Key is a programmatic credential owned by an account or app. Each
      key carries its own permissions policy — explicit permission statements or
      an inherited system role — and can be restricted with an expiration date
      and an IP allowlist.


      Use the API Keys API to list an account or app's keys, create a key (the
      full secret is returned once, on creation), inspect a key's effective
      grants, update its name or restrictions, rotate its secret, and revoke it.
      These endpoints require a user session — they cannot be called with an API
      key.
    name: API Keys
    x-whop-summary: Programmatic credentials for an account or app.
  - description: >
      An Api Log is a record of a single request made to Whop's API using one of
      your account's API keys — the programmatic counterpart to the dashboard
      audit log, which only records actions taken by signed-in team members.
      Reads and failed requests are logged too.


      Use the Api Logs API to see what your integrations are doing on Whop: the
      operation, HTTP method and status, outcome, and timing of each request,
      newest first.
    name: Api Logs
    x-whop-summary: Requests made to Whop's API with your account's API keys.
  - description: >
      A Permission is one action, such as `stats:read`, paired with whether your
      credential is granted it on a given resource. It answers for whatever you
      authenticated with, so you can decide what to show or attempt instead of
      discovering a `403`.


      Use the Permissions API to check an account, product, experience, or app,
      narrowing to the actions you care about. It reports only your own access —
      to manage who else can reach an account, use the Team Members API.
    name: Permissions
    x-whop-summary: What your credential is allowed to do on a resource.
paths:
  /confirmation_tokens:
    parameters:
      - $ref: '#/components/parameters/ApiVersionDate'
    post:
      tags:
        - Confirmation Tokens
      summary: Create Confirmation Token
      description: >-
        Mints a single-use, short-lived confirmation token from what the buyer
        entered on your collection surface: the payment method payload, billing
        details, and attested save consent. Public and rate-limited — the
        account_id in the body scopes the token but does not authenticate.
        Confirm it with POST /payments from your server.
      operationId: createConfirmationToken
      parameters:
        - $ref: '#/components/parameters/IdempotencyKey'
      requestBody:
        content:
          application/json:
            schema:
              example:
                account_id: biz_xxxxxxxxxxxxxx
                billing_details:
                  address:
                    city: Austin
                    country: US
                    line1: 123 Main St
                    postal_code: '78701'
                  email: buyer@example.com
                  name: Buyer Name
                payment_method:
                  card:
                    brand: visa
                    last4: '4242'
                    token_intent: bt_ti_123
                  category: card
                  type: card
                setup_future_usage: off_session
              properties:
                account_id:
                  description: >-
                    The account (biz_) this token is scoped to — the publishable
                    identity.
                  example: biz_xxxxxxxxxxxxxx
                  type: string
                billing_details:
                  description: >-
                    Billing details collected with the method. `email` is always
                    required; cards additionally require `name` and an address
                    with `line1` and `country`.
                  properties:
                    address:
                      example:
                        city: Austin
                        country: US
                        line1: 123 Main St
                        postal_code: '78701'
                      type:
                        - object
                        - 'null'
                    email:
                      example: marcus@shinetime.example
                      type: string
                    name:
                      example: Buyer Name
                      type:
                        - string
                        - 'null'
                  required:
                    - email
                  type: object
                browser_info:
                  description: >-
                    Screen/runtime facts from the buyer's browser (platform,
                    screen dimensions, language, ...) used for authentication
                    ceremonies. Header-derived fields are captured server-side.
                  example:
                    browser_time_difference: 0
                    java_enabled: false
                    javascript_enabled: false
                    language: de-DE
                  type:
                    - object
                    - 'null'
                payment_method:
                  description: >-
                    The collected method: `type` names the payment method,
                    `category` names the payload shape, and the category-keyed
                    object carries the payload. Wallets are the exception: their
                    payload rides the type key (`apple_pay` / `google_pay`).
                    Send exactly the one payload arm the category selects —
                    extra arms are rejected. Redirect-flow methods (category
                    `redirect`, `bank_transfer`, `voucher`, and redirect wallets
                    like `cashapp`) collect nothing and send no payload arm.
                  properties:
                    apple_pay:
                      description: Type `apple_pay` (category `wallet`) only.
                      properties:
                        merchant_identifier:
                          description: >-
                            The merchant identifier the Apple Pay sheet
                            validated with — the same hostname-matched value
                            from the type's `merchants` list the session
                            ceremony used. Apple encrypts the wallet token for
                            the certificate attached to this exact identifier,
                            so the charge needs it to decrypt. Omit it when the
                            ceremony omitted it; must be one the account has
                            registered.
                          example: merchant.whop.com.y.uno
                          type:
                            - string
                            - 'null'
                        token_intent:
                          description: >-
                            The Basis Theory token intent the Apple Pay sheet
                            flow vaulted the raw wallet token into.
                          example: bt_ti_apple_789
                          type: string
                      required:
                        - token_intent
                      type: object
                    balance:
                      description: >-
                        Category `balance` only. Names one of the buyer's
                        spendable platform balances. Requires a buyer credential
                        — whether the caller may spend the wallet is checked
                        against their own grants, so another user's id reads as
                        not found.
                      properties:
                        id:
                          description: >-
                            The balance to spend — a balance id (ldgr_) from GET
                            /balances.
                          example: ldgr_xxxxxxxxxxxxxx
                          type: string
                      required:
                        - id
                      type: object
                    bank_debit:
                      description: >-
                        Category `bank_debit` only. A type that declares a
                        secure field (`sepa_debit`) sends the element's
                        tokenized credential as `token`. `us_bank_account` sends
                        nothing here — the buyer links the account after
                        confirm, through the hosted bank-connection flow the
                        payment parks behind.
                      properties:
                        token:
                          description: >-
                            The Basis Theory token the element vaulted the
                            account details into. Required for types declaring a
                            secure field; rejected for types that collect after
                            confirm.
                          example: bt_tok_sepa
                          type: string
                      type: object
                    card:
                      description: >-
                        Category `card` only. Exactly one of `token` or
                        `token_intent`; display fields ride alongside.
                      properties:
                        brand:
                          description: >-
                            Display-safe card brand from the collection surface,
                            e.g. `visa`.
                          example: visa
                          type:
                            - string
                            - 'null'
                        last4:
                          description: >-
                            Display-safe last four digits from the collection
                            surface.
                          example: '4242'
                          type:
                            - string
                            - 'null'
                        token:
                          description: >-
                            An element-assembled, expiring Basis Theory token.
                            Provide this or token_intent.
                          example: bt_tok_456
                          type: string
                        token_intent:
                          description: A Basis Theory token intent. Provide this or token.
                          example: bt_ti_123
                          type: string
                      type: object
                    category:
                      description: >-
                        The payload shape the surface collected. Must be the
                        category the type resolves to — it is derived
                        server-side and a mismatch is rejected. `saved` and
                        `balance` are the exceptions: they name a method already
                        on file or a spendable balance rather than one collected
                        here.
                      enum:
                        - card
                        - wallet
                        - bank_debit
                        - bank_transfer
                        - voucher
                        - redirect
                        - crypto
                        - balance
                        - in_app_purchase
                        - saved
                      example: card
                      type: string
                    google_pay:
                      description: Type `google_pay` (category `wallet`) only.
                      properties:
                        token_intent:
                          description: >-
                            The Basis Theory token intent the Google Pay sheet
                            flow vaulted the raw wallet token into.
                          type: string
                      required:
                        - token_intent
                      type: object
                    payer_document:
                      description: >-
                        The buyer's identity document when the charge currency
                        has a payer_document_requirements entry for this method,
                        such as ARS card, MODO, or Rapipago. This is independent
                        of the method category.
                      properties:
                        token:
                          description: >-
                            The Basis Theory token containing the
                            identity-document number.
                          example: '20123456'
                          type: string
                        type:
                          description: >-
                            The selected identity-document type from the
                            method's payer_document_requirements entry.
                          enum:
                            - dni
                            - cuil
                            - cuit
                            - passport
                            - cc
                            - ci
                            - rut
                            - curp
                            - rfc
                          example: dni
                          type: string
                      required:
                        - type
                        - token
                      type: object
                    saved:
                      description: >-
                        Category `saved` only. Names one of the buyer's own
                        stored payment methods. Requires a buyer credential —
                        the wallet read is scoped to that account, so another
                        user's id reads as not found.
                      properties:
                        payment_method:
                          description: >-
                            The stored payment method to charge — a payment
                            method id from GET /payment_methods.
                          example: payt_xxxxxxxxxxxxxx
                          type: string
                      required:
                        - payment_method
                      type: object
                    type:
                      description: >-
                        The payment method type, for example `card` or `ideal`.
                        Required for every category except `saved` and
                        `balance`, where it is read from the referenced method.
                      example: card
                      type: string
                  required:
                    - category
                  type: object
                return_url:
                  description: >-
                    Where redirect flows send the buyer, carried onto the
                    confirm that consumes this token.
                  type:
                    - string
                    - 'null'
                setup_future_usage:
                  description: >-
                    The save-consent state your surface displayed when the buyer
                    confirmed. Confirm may vault only if attested here.
                  enum:
                    - off_session
                    - on_session
                    - null
                  example: off_session
                  type:
                    - string
                    - 'null'
              required:
                - account_id
                - payment_method
              type: object
        required: true
      responses:
        '201':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ConfirmationToken'
          description: confirmation token created from a card token intent
        '400':
          $ref: '#/components/responses/InvalidParameters'
          description: a token on a method that collects after confirm
        '401':
          $ref: '#/components/responses/Unauthorized'
          description: saved method requested without a credential
        '403':
          $ref: '#/components/responses/Forbidden'
          description: credential does not carry the payment methods scope
        '404':
          $ref: '#/components/responses/NotFound'
          description: unknown account
        '409':
          $ref: '#/components/responses/Conflict'
      security:
        - {}
        - bearerAuth:
            - member:payment_methods:use
components:
  parameters:
    ApiVersionDate:
      description: Pins the request to a dated API version.
      in: header
      name: Api-Version-Date
      required: false
      schema:
        example: 2026-08-25-2
        type: string
    IdempotencyKey:
      description: >-
        A unique key that makes this request safe to retry. See [Idempotent
        requests](https://docs.whop.com/developer/api/idempotency).
      in: header
      name: Idempotency-Key
      required: false
      schema:
        example: d9105228-4a08-46b1-8b91-42fed586d383
        maxLength: 255
        type: string
  schemas:
    ConfirmationToken:
      properties:
        billing_details:
          description: >-
            Enough of the billing details to raise a customer record and
            recognise the method — email, name, country and postal code. The
            street address is collected for the charge but never returned; this
            endpoint is a display-safe preview.
          oneOf:
            - $ref: '#/components/schemas/PaymentBillingDetailsPreview'
            - type: 'null'
        created_at:
          description: When the token was created, as an ISO 8601 timestamp.
          example: '2026-01-01T12:00:00.000Z'
          type: string
        expires_at:
          description: >-
            When the token expires, as an ISO 8601 timestamp. Tokens are
            single-use and short-lived.
          example: '2026-01-01T12:00:00.000Z'
          type: string
        id:
          example: ctok_xxxxxxxxxxxxxx
          type: string
        object:
          description: Always `confirmation_token`.
          example: confirmation_token
          type: string
        payment_method_preview:
          $ref: '#/components/schemas/PaymentMethodDisplay'
          description: >-
            Display-only preview of the collected method — never the underlying
            token.
        setup_future_usage:
          description: >-
            Save-consent state the element displayed at collection:
            `off_session`, `on_session`, or `null`. Confirm may vault only if
            attested here.
          example: off_session
          type:
            - string
            - 'null'
        status:
          description: >-
            `pending` until it is used, then `consumed`; `expired` once its
            short lifetime elapses. Only a `pending` token can be charged.
          enum:
            - pending
            - consumed
            - expired
          example: pending
          type: string
      required:
        - id
        - object
        - status
        - payment_method_preview
        - setup_future_usage
        - billing_details
        - created_at
        - expires_at
      type: object
    PaymentBillingDetailsPreview:
      properties:
        country:
          description: ISO 3166-1 alpha-2 country code.
          example: AR
          type:
            - string
            - 'null'
        email:
          description: Email supplied when the method was collected.
          example: marcus@shinetime.example
          type:
            - string
            - 'null'
        name:
          description: Name on the payment method.
          example: Buyer Name
          type:
            - string
            - 'null'
        postal_code:
          description: Postal or ZIP code.
          example: C1043
          type:
            - string
            - 'null'
      required:
        - email
        - name
        - country
        - postal_code
      type: object
    PaymentMethodDisplay:
      properties:
        bank_debit:
          $ref: '#/components/schemas/PaymentMethodDisplayPreview'
          description: >-
            Present when the category is `bank_debit`. Carries the account's
            last four when the linking provider surfaced it.
        card:
          $ref: '#/components/schemas/PaymentMethodDisplayPreview'
          description: >-
            Present when the category is `card`. What the collection surface
            displayed — the token has not been charged, so this is the buyer's
            claim, not the vault's record.
        category:
          description: The family the type belongs to.
          enum:
            - card
            - wallet
            - bank_debit
            - bank_transfer
            - voucher
            - redirect
            - crypto
            - balance
            - in_app_purchase
            - saved
          example: saved
          type: string
        display_name:
          description: Human-readable label for the method, e.g. `Visa •••• 4242`.
          example: Visa •••• 4242
          type: string
        id:
          description: >-
            The saved payment method this preview came from, or `null` when the
            buyer supplied a new one.
          example: payt_xxxxxxxxxxxxxx
          type:
            - string
            - 'null'
        saved:
          $ref: '#/components/schemas/PaymentMethodDisplayPreview'
          description: >-
            Present when the category is `saved` and the stored method is a
            card. Unlike the other previews this is the vault's own record, not
            a claim from the collection surface. Absent for a balance, which has
            no instrument.
        type:
          description: The payment method type, e.g. `card`, `apple_pay`, `klarna`.
          example: card
          type: string
        wallet:
          $ref: '#/components/schemas/PaymentMethodDisplayPreview'
          description: >-
            Present when the category is `wallet`. Carries the backing card's
            brand and last four when the wallet surfaced them.
      required:
        - id
        - type
        - category
        - display_name
      type: object
    V1ErrorResponse:
      properties:
        error:
          properties:
            code:
              description: >-
                Machine-readable reason for this specific refusal, such as
                `bank_warning_not_acknowledged`. Only present when the error
                carries one.
              type: string
            message:
              description: Human-readable error message.
              example: account_id is required
              type: string
            type:
              description: Machine-readable error code.
              example: bad_request
              type: string
          required:
            - type
            - message
          type: object
      required:
        - error
      type: object
    PaymentMethodDisplayPreview:
      properties:
        brand:
          description: >-
            Lowercase card brand, e.g. `visa`. Absent when the method carries no
            brand.
          example: visa
          type: string
        last4:
          description: >-
            Last four digits of the instrument. Absent when the method carries
            none.
          example: '4242'
          type: string
      required: []
      type: object
  responses:
    InvalidParameters:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/V1ErrorResponse'
      description: Invalid Parameters
    Unauthorized:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/V1ErrorResponse'
      description: Unauthorized
    Forbidden:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/V1ErrorResponse'
      description: Forbidden
    NotFound:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/V1ErrorResponse'
      description: Resource not found
    Conflict:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/V1ErrorResponse'
      description: Conflict
  securitySchemes:
    bearerAuth:
      bearerFormat: auth-scheme
      description: >-
        An Account API key, account-scoped JWT, App API key, or user OAuth
        token. Prepend the key or token with `Bearer`, for example `Bearer
        ***************************`.
      scheme: bearer
      type: http

````