> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.coinflow.cash/guides/getting-started/quickstart/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.coinflow.cash/_mcp/server. # Quickstart This guide walks through two end-to-end flows against the **sandbox** environment — a card checkout and a payout to a bank account. > **Info** > > **Before you start:** Make sure you've completed [Account Setup](/guides/getting-started/account-setup) and have your sandbox API key and merchant ID ready. > **Tip** > > **Prefer Postman?** Import the [Card Checkout + Merchant Payouts collection](https://go.postman.co/collection/33642151-837860d2-b624-4dc1-9fb7-1881e9041278?source=collection_link) to run every request in this guide with pre-wired variables. Set `apiKey`, `merchantId`, and `userId` in the collection variables and you're ready to go. --- ## Part 1 — Card Checkout Three steps to take your first card payment: 1. **Get a session key** — authorize the payer to your server (server-side) 2. **Get a checkout JWT** — sign the cart details (server-side) 3. **Render the `CoinflowPurchase` component** — display the card form (client-side) Coinflow's pre-built UI handles card capture, PCI-compliant tokenization, 3DS challenges, and fraud signals automatically. You don't tokenize cards yourself unless you have your own PCI DSS AOC. --- ### Step 1 — Get a session key A session key is a short-lived JWT that ties the checkout to a specific payer. Generate it on your server using your internal user ID, then pass it to the front-end. ### Request GET [https://api-sandbox.coinflow.cash/api/auth/session-key](https://api-sandbox.coinflow.cash/api/auth/session-key) ```curl curl https://api-sandbox.coinflow.cash/api/auth/session-key \ -H "x-coinflow-auth-user-id: " ``` ```python import requests url = "https://api-sandbox.coinflow.cash/api/auth/session-key" headers = {"x-coinflow-auth-user-id": ""} response = requests.get(url, headers=headers) print(response.json()) ``` ```javascript const url = 'https://api-sandbox.coinflow.cash/api/auth/session-key'; const options = {method: 'GET', headers: {'x-coinflow-auth-user-id': ''}}; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go package main import ( "fmt" "net/http" "io" ) func main() { url := "https://api-sandbox.coinflow.cash/api/auth/session-key" req, _ := http.NewRequest("GET", url, nil) req.Header.Add("x-coinflow-auth-user-id", "") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby require 'uri' require 'net/http' url = URI("https://api-sandbox.coinflow.cash/api/auth/session-key") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Get.new(url) request["x-coinflow-auth-user-id"] = '' response = http.request(request) puts response.read_body ``` ```java import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.get("https://api-sandbox.coinflow.cash/api/auth/session-key") .header("x-coinflow-auth-user-id", "") .asString(); ``` ```php request('GET', 'https://api-sandbox.coinflow.cash/api/auth/session-key', [ 'headers' => [ 'x-coinflow-auth-user-id' => '', ], ]); echo $response->getBody(); ``` ```csharp using RestSharp; var client = new RestClient("https://api-sandbox.coinflow.cash/api/auth/session-key"); var request = new RestRequest(Method.GET); request.AddHeader("x-coinflow-auth-user-id", ""); IRestResponse response = client.Execute(request); ``` ```swift import Foundation let headers = ["x-coinflow-auth-user-id": ""] let request = NSMutableURLRequest(url: NSURL(string: "https://api-sandbox.coinflow.cash/api/auth/session-key")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "GET" request.allHTTPHeaderFields = headers let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ``` ### Response (200) ```json { "key": "string" } ``` Session keys are valid for **24 hours**. Refresh when expired. --- ### Step 2 — Get a checkout JWT The checkout JWT signs the cart payload (amount, customer email, chargeback-protection data) so the front-end can't tamper with it. Generate it on your server right before rendering the checkout component. ### Request POST [https://api-sandbox.coinflow.cash/api/checkout/jwt-token](https://api-sandbox.coinflow.cash/api/checkout/jwt-token) ```curl curl -X POST https://api-sandbox.coinflow.cash/api/checkout/jwt-token \ -H "Authorization: " \ -H "Content-Type: application/json" \ -d '{}' ``` ```python import requests url = "https://api-sandbox.coinflow.cash/api/checkout/jwt-token" payload = {} headers = { "Authorization": "", "Content-Type": "application/json" } response = requests.post(url, json=payload, headers=headers) print(response.json()) ``` ```javascript const url = 'https://api-sandbox.coinflow.cash/api/checkout/jwt-token'; const options = { method: 'POST', headers: {Authorization: '', 'Content-Type': 'application/json'}, body: '{}' }; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go package main import ( "fmt" "strings" "net/http" "io" ) func main() { url := "https://api-sandbox.coinflow.cash/api/checkout/jwt-token" payload := strings.NewReader("{}") req, _ := http.NewRequest("POST", url, payload) req.Header.Add("Authorization", "") req.Header.Add("Content-Type", "application/json") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby require 'uri' require 'net/http' url = URI("https://api-sandbox.coinflow.cash/api/checkout/jwt-token") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Post.new(url) request["Authorization"] = '' request["Content-Type"] = 'application/json' request.body = "{}" response = http.request(request) puts response.read_body ``` ```java import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.post("https://api-sandbox.coinflow.cash/api/checkout/jwt-token") .header("Authorization", "") .header("Content-Type", "application/json") .body("{}") .asString(); ``` ```php request('POST', 'https://api-sandbox.coinflow.cash/api/checkout/jwt-token', [ 'body' => '{}', 'headers' => [ 'Authorization' => '', 'Content-Type' => 'application/json', ], ]); echo $response->getBody(); ``` ```csharp using RestSharp; var client = new RestClient("https://api-sandbox.coinflow.cash/api/checkout/jwt-token"); var request = new RestRequest(Method.POST); request.AddHeader("Authorization", ""); request.AddHeader("Content-Type", "application/json"); request.AddParameter("application/json", "{}", ParameterType.RequestBody); IRestResponse response = client.Execute(request); ``` ```swift import Foundation let headers = [ "Authorization": "", "Content-Type": "application/json" ] let parameters = [] as [String : Any] let postData = JSONSerialization.data(withJSONObject: parameters, options: []) let request = NSMutableURLRequest(url: NSURL(string: "https://api-sandbox.coinflow.cash/api/checkout/jwt-token")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "POST" request.allHTTPHeaderFields = headers request.httpBody = postData as Data let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ``` **`Response`** ```json Response { "checkoutJwtToken": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..." } ``` Send `key` (from Step 1) and `checkoutJwtToken` (from Step 2) to your front-end. --- ### Step 3 — Render the checkout component Install the React SDK and render `CoinflowPurchase` with the two tokens. Coinflow handles the rest — card entry UI, validation, PCI-compliant tokenization, 3DS, fraud scoring, and settlement to your Coinflow Wallet. ```bash npm install @coinflowlabs/react ``` **`Checkout.tsx`** ```tsx Checkout.tsx import { CoinflowPurchase, Currency } from '@coinflowlabs/react'; export function Checkout({ sessionKey, jwtToken }: { sessionKey: string; jwtToken: string }) { return ( { console.log('Payment successful:', paymentId); // Redirect to your success page }} /> ); } ``` > **Success** > > **That's a payment.** When `onSuccess` fires, funds have settled to your Coinflow Wallet. Coinflow's chargeback protection and 3DS are layered in by default — see [Adding Chargeback Protection](/guides/checkout/payment-security-risk-management/fraud-protection/implement-chargeback-protection) and [About 3D Secure](/guides/checkout/payment-security-risk-management/fraud-protection/3-ds/about-3-ds) to tune them. **Sandbox test cards:** `5204247750001471` (Mastercard) or any card from the [testing guide](/guides/checkout/testing/testing-credit-cards). #### Alternative: Direct API integration (PCI-compliant merchants only) If you hold your own PCI DSS AOC and want a fully custom UI, you can tokenize and charge cards via the API directly without rendering the `CoinflowPurchase` component. Contact [support@coinflowlabs.app](mailto:support@coinflowlabs.app) to provision the tokenization credentials your requests need. **Tokenize the card:** ### Request POST [https://api-sandbox.coinflow.cash/api/tokenize](https://api-sandbox.coinflow.cash/api/tokenize) ```curl curl -X POST https://api-sandbox.coinflow.cash/api/tokenize \ -H "Authorization: " \ -H "Content-Type: application/json" \ -d '{}' ``` ```python import requests url = "https://api-sandbox.coinflow.cash/api/tokenize" payload = {} headers = { "Authorization": "", "Content-Type": "application/json" } response = requests.post(url, json=payload, headers=headers) print(response.json()) ``` ```javascript const url = 'https://api-sandbox.coinflow.cash/api/tokenize'; const options = { method: 'POST', headers: {Authorization: '', 'Content-Type': 'application/json'}, body: '{}' }; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go package main import ( "fmt" "strings" "net/http" "io" ) func main() { url := "https://api-sandbox.coinflow.cash/api/tokenize" payload := strings.NewReader("{}") req, _ := http.NewRequest("POST", url, payload) req.Header.Add("Authorization", "") req.Header.Add("Content-Type", "application/json") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby require 'uri' require 'net/http' url = URI("https://api-sandbox.coinflow.cash/api/tokenize") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Post.new(url) request["Authorization"] = '' request["Content-Type"] = 'application/json' request.body = "{}" response = http.request(request) puts response.read_body ``` ```java import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.post("https://api-sandbox.coinflow.cash/api/tokenize") .header("Authorization", "") .header("Content-Type", "application/json") .body("{}") .asString(); ``` ```php request('POST', 'https://api-sandbox.coinflow.cash/api/tokenize', [ 'body' => '{}', 'headers' => [ 'Authorization' => '', 'Content-Type' => 'application/json', ], ]); echo $response->getBody(); ``` ```csharp using RestSharp; var client = new RestClient("https://api-sandbox.coinflow.cash/api/tokenize"); var request = new RestRequest(Method.POST); request.AddHeader("Authorization", ""); request.AddHeader("Content-Type", "application/json"); request.AddParameter("application/json", "{}", ParameterType.RequestBody); IRestResponse response = client.Execute(request); ``` ```swift import Foundation let headers = [ "Authorization": "", "Content-Type": "application/json" ] let parameters = [] as [String : Any] let postData = JSONSerialization.data(withJSONObject: parameters, options: []) let request = NSMutableURLRequest(url: NSURL(string: "https://api-sandbox.coinflow.cash/api/tokenize")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "POST" request.allHTTPHeaderFields = headers request.httpBody = postData as Data let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ``` ### Response (200) ```json { "token": "tok_1A2b3C4d5E6f7G8h9I0j", "firstSix": "411111", "lastFour": "1111", "referenceNumber": "REF123456789", "success": true, "error": "", "message": "Tokenization successful" } ``` **Submit the payment** with the returned `token` as `card.cardToken`: ### Request POST [https://api-sandbox.coinflow.cash/api/checkout/card/\{merchantId}](https://api-sandbox.coinflow.cash/api/checkout/card/\{merchantId}) ```curl curl -X POST https://api-sandbox.coinflow.cash/api/checkout/card/merchantId \ -H "x-coinflow-auth-session-key: " \ -H "Content-Type: application/json" \ -d '{ "subtotal": { "cents": 1, "currency": "USD" }, "card": { "cardToken": "string", "expYear": "string", "expMonth": "string", "email": "string", "firstName": "string", "lastName": "string", "address1": "string", "city": "string", "country": "string" } }' ``` ```python import requests url = "https://api-sandbox.coinflow.cash/api/checkout/card/merchantId" payload = { "subtotal": { "cents": 1, "currency": "USD" }, "card": { "cardToken": "string", "expYear": "string", "expMonth": "string", "email": "string", "firstName": "string", "lastName": "string", "address1": "string", "city": "string", "country": "string" } } headers = { "x-coinflow-auth-session-key": "", "Content-Type": "application/json" } response = requests.post(url, json=payload, headers=headers) print(response.json()) ``` ```javascript const url = 'https://api-sandbox.coinflow.cash/api/checkout/card/merchantId'; const options = { method: 'POST', headers: {'x-coinflow-auth-session-key': '', 'Content-Type': 'application/json'}, body: '{"subtotal":{"cents":1,"currency":"USD"},"card":{"cardToken":"string","expYear":"string","expMonth":"string","email":"string","firstName":"string","lastName":"string","address1":"string","city":"string","country":"string"}}' }; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go package main import ( "fmt" "strings" "net/http" "io" ) func main() { url := "https://api-sandbox.coinflow.cash/api/checkout/card/merchantId" payload := strings.NewReader("{\n \"subtotal\": {\n \"cents\": 1,\n \"currency\": \"USD\"\n },\n \"card\": {\n \"cardToken\": \"string\",\n \"expYear\": \"string\",\n \"expMonth\": \"string\",\n \"email\": \"string\",\n \"firstName\": \"string\",\n \"lastName\": \"string\",\n \"address1\": \"string\",\n \"city\": \"string\",\n \"country\": \"string\"\n }\n}") req, _ := http.NewRequest("POST", url, payload) req.Header.Add("x-coinflow-auth-session-key", "") req.Header.Add("Content-Type", "application/json") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby require 'uri' require 'net/http' url = URI("https://api-sandbox.coinflow.cash/api/checkout/card/merchantId") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Post.new(url) request["x-coinflow-auth-session-key"] = '' request["Content-Type"] = 'application/json' request.body = "{\n \"subtotal\": {\n \"cents\": 1,\n \"currency\": \"USD\"\n },\n \"card\": {\n \"cardToken\": \"string\",\n \"expYear\": \"string\",\n \"expMonth\": \"string\",\n \"email\": \"string\",\n \"firstName\": \"string\",\n \"lastName\": \"string\",\n \"address1\": \"string\",\n \"city\": \"string\",\n \"country\": \"string\"\n }\n}" response = http.request(request) puts response.read_body ``` ```java import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.post("https://api-sandbox.coinflow.cash/api/checkout/card/merchantId") .header("x-coinflow-auth-session-key", "") .header("Content-Type", "application/json") .body("{\n \"subtotal\": {\n \"cents\": 1,\n \"currency\": \"USD\"\n },\n \"card\": {\n \"cardToken\": \"string\",\n \"expYear\": \"string\",\n \"expMonth\": \"string\",\n \"email\": \"string\",\n \"firstName\": \"string\",\n \"lastName\": \"string\",\n \"address1\": \"string\",\n \"city\": \"string\",\n \"country\": \"string\"\n }\n}") .asString(); ``` ```php request('POST', 'https://api-sandbox.coinflow.cash/api/checkout/card/merchantId', [ 'body' => '{ "subtotal": { "cents": 1, "currency": "USD" }, "card": { "cardToken": "string", "expYear": "string", "expMonth": "string", "email": "string", "firstName": "string", "lastName": "string", "address1": "string", "city": "string", "country": "string" } }', 'headers' => [ 'Content-Type' => 'application/json', 'x-coinflow-auth-session-key' => '', ], ]); echo $response->getBody(); ``` ```csharp using RestSharp; var client = new RestClient("https://api-sandbox.coinflow.cash/api/checkout/card/merchantId"); var request = new RestRequest(Method.POST); request.AddHeader("x-coinflow-auth-session-key", ""); request.AddHeader("Content-Type", "application/json"); request.AddParameter("application/json", "{\n \"subtotal\": {\n \"cents\": 1,\n \"currency\": \"USD\"\n },\n \"card\": {\n \"cardToken\": \"string\",\n \"expYear\": \"string\",\n \"expMonth\": \"string\",\n \"email\": \"string\",\n \"firstName\": \"string\",\n \"lastName\": \"string\",\n \"address1\": \"string\",\n \"city\": \"string\",\n \"country\": \"string\"\n }\n}", ParameterType.RequestBody); IRestResponse response = client.Execute(request); ``` ```swift import Foundation let headers = [ "x-coinflow-auth-session-key": "", "Content-Type": "application/json" ] let parameters = [ "subtotal": [ "cents": 1, "currency": "USD" ], "card": [ "cardToken": "string", "expYear": "string", "expMonth": "string", "email": "string", "firstName": "string", "lastName": "string", "address1": "string", "city": "string", "country": "string" ] ] as [String : Any] let postData = JSONSerialization.data(withJSONObject: parameters, options: []) let request = NSMutableURLRequest(url: NSURL(string: "https://api-sandbox.coinflow.cash/api/checkout/card/merchantId")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "POST" request.allHTTPHeaderFields = headers request.httpBody = postData as Data let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ``` ### Response (200) ```json { "paymentId": "string", "authorizationExpiration": "string" } ``` Fetch full payment details any time: ### Request GET [https://api-sandbox.coinflow.cash/api/merchant/payments/enhanced/\{paymentId}](https://api-sandbox.coinflow.cash/api/merchant/payments/enhanced/\{paymentId}) ```curl curl https://api-sandbox.coinflow.cash/api/merchant/payments/enhanced/paymentId \ -H "Authorization: " ``` ```python import requests url = "https://api-sandbox.coinflow.cash/api/merchant/payments/enhanced/paymentId" headers = {"Authorization": ""} response = requests.get(url, headers=headers) print(response.json()) ``` ```javascript const url = 'https://api-sandbox.coinflow.cash/api/merchant/payments/enhanced/paymentId'; const options = {method: 'GET', headers: {Authorization: ''}}; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go package main import ( "fmt" "net/http" "io" ) func main() { url := "https://api-sandbox.coinflow.cash/api/merchant/payments/enhanced/paymentId" req, _ := http.NewRequest("GET", url, nil) req.Header.Add("Authorization", "") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby require 'uri' require 'net/http' url = URI("https://api-sandbox.coinflow.cash/api/merchant/payments/enhanced/paymentId") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Get.new(url) request["Authorization"] = '' response = http.request(request) puts response.read_body ``` ```java import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.get("https://api-sandbox.coinflow.cash/api/merchant/payments/enhanced/paymentId") .header("Authorization", "") .asString(); ``` ```php request('GET', 'https://api-sandbox.coinflow.cash/api/merchant/payments/enhanced/paymentId', [ 'headers' => [ 'Authorization' => '', ], ]); echo $response->getBody(); ``` ```csharp using RestSharp; var client = new RestClient("https://api-sandbox.coinflow.cash/api/merchant/payments/enhanced/paymentId"); var request = new RestRequest(Method.GET); request.AddHeader("Authorization", ""); IRestResponse response = client.Execute(request); ``` ```swift import Foundation let headers = ["Authorization": ""] let request = NSMutableURLRequest(url: NSURL(string: "https://api-sandbox.coinflow.cash/api/merchant/payments/enhanced/paymentId")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "GET" request.allHTTPHeaderFields = headers let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ``` --- ## Part 2 — Payout to a Bank Account Four steps to pay a user out from your Coinflow Wallet: 1. **Get a session key** for the withdrawer (server-side) 2. **Embed the Bank Authentication UI** — Coinflow's hosted UI handles KYC and bank linking in one flow (client-side) 3. **Get the withdrawer** to retrieve the linked bank account token (server-side) 4. **Initiate the payout** (server-side) --- ### Step 1 — Get a session key Generate a session key tied to your internal user ID. You'll pass it into the bank-link URL in the next step. ### Request GET [https://api-sandbox.coinflow.cash/api/auth/session-key](https://api-sandbox.coinflow.cash/api/auth/session-key) ```curl curl https://api-sandbox.coinflow.cash/api/auth/session-key \ -H "x-coinflow-auth-user-id: " ``` ```python import requests url = "https://api-sandbox.coinflow.cash/api/auth/session-key" headers = {"x-coinflow-auth-user-id": ""} response = requests.get(url, headers=headers) print(response.json()) ``` ```javascript const url = 'https://api-sandbox.coinflow.cash/api/auth/session-key'; const options = {method: 'GET', headers: {'x-coinflow-auth-user-id': ''}}; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go package main import ( "fmt" "net/http" "io" ) func main() { url := "https://api-sandbox.coinflow.cash/api/auth/session-key" req, _ := http.NewRequest("GET", url, nil) req.Header.Add("x-coinflow-auth-user-id", "") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby require 'uri' require 'net/http' url = URI("https://api-sandbox.coinflow.cash/api/auth/session-key") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Get.new(url) request["x-coinflow-auth-user-id"] = '' response = http.request(request) puts response.read_body ``` ```java import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.get("https://api-sandbox.coinflow.cash/api/auth/session-key") .header("x-coinflow-auth-user-id", "") .asString(); ``` ```php request('GET', 'https://api-sandbox.coinflow.cash/api/auth/session-key', [ 'headers' => [ 'x-coinflow-auth-user-id' => '', ], ]); echo $response->getBody(); ``` ```csharp using RestSharp; var client = new RestClient("https://api-sandbox.coinflow.cash/api/auth/session-key"); var request = new RestRequest(Method.GET); request.AddHeader("x-coinflow-auth-user-id", ""); IRestResponse response = client.Execute(request); ``` ```swift import Foundation let headers = ["x-coinflow-auth-user-id": ""] let request = NSMutableURLRequest(url: NSURL(string: "https://api-sandbox.coinflow.cash/api/auth/session-key")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "GET" request.allHTTPHeaderFields = headers let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ``` ### Response (200) ```json { "key": "string" } ``` --- ### Step 2 — Embed the Bank Authentication UI Coinflow's hosted UI handles KYC verification and bank/card linking end-to-end — you don't have to build any of it. Drop the URL below into an iframe, replacing `YOUR_MERCHANT_ID` and `SESSION_KEY_FROM_STEP_1` with your own values. **`iframe`** ```html iframe