Create a customer-portal session
Mint a short-lived bearer token that authenticates a specific customer against /v2/customer-portal/*. Returns an opaque `rkcps_...` token that expires in 60 minutes by default. Call this server-side from the merchant's backend, then hand the token to the customer's browser or embedded client. Treat the token like a password — never log it and never expose it to untrusted code. --- **Related endpoints** - `GET /customer-portal/customer` — Retrieve the authenticated customer - `GET /customer-portal/subscriptions` — List the authenticated customer's subscriptions - `GET /customer-portal/subscriptions/{id}` — Retrieve a subscription - `POST /customer-portal/subscriptions/{id}/cancel` — Cancel a subscription - `GET /customer-portal/invoices` — List the authenticated customer's invoices - `GET /customer-portal/invoices/{id}` — Retrieve an invoice - `GET /customer-portal/mandates` — List the authenticated customer's Direct Debit mandates - `POST /customer-portal/mandates/{id}/re-authorize` — Re-authorise a Direct Debit mandate with new bank details **Common errors** - `401 authentication_error` — missing, invalid, expired, or revoked credential. Codes: `authentication_failed`, `invalid_api_key`, `expired_api_key`, `api_key_revoked`, `session_invalid`, `merchant_required`. Carries a `WWW-Authenticate: Bearer` challenge. - `404 resource_missing` — the referenced resource does not exist or is not visible to your key. **Idempotency** Pass an `Idempotency-Key` header (UUID v4 recommended) to make retries safe. Keys are valid for 24 hours; see [the idempotency guide](/docs/fundamentals/idempotency).
Mint a short-lived bearer token that authenticates a specific customer against /v2/customer-portal/*. Returns an opaque rkcps_... token that expires in 60 minutes by default. Call this server-side from the merchant's backend, then hand the token to the customer's browser or embedded client. Treat the token like a password — never log it and never expose it to untrusted code.
Related endpoints
GET /customer-portal/customer— Retrieve the authenticated customerGET /customer-portal/subscriptions— List the authenticated customer's subscriptionsGET /customer-portal/subscriptions/{id}— Retrieve a subscriptionPOST /customer-portal/subscriptions/{id}/cancel— Cancel a subscriptionGET /customer-portal/invoices— List the authenticated customer's invoicesGET /customer-portal/invoices/{id}— Retrieve an invoiceGET /customer-portal/mandates— List the authenticated customer's Direct Debit mandatesPOST /customer-portal/mandates/{id}/re-authorize— Re-authorise a Direct Debit mandate with new bank details
Common errors
401 authentication_error— missing, invalid, expired, or revoked credential. Codes:authentication_failed,invalid_api_key,expired_api_key,api_key_revoked,session_invalid,merchant_required. Carries aWWW-Authenticate: Bearerchallenge.404 resource_missing— the referenced resource does not exist or is not visible to your key.
Idempotency
Pass an Idempotency-Key header (UUID v4 recommended) to make retries safe. Keys are valid for 24 hours; see the idempotency guide.
Your RevKeen merchant API key. Create and manage keys in Dashboard → Settings → Developer. Use rk_sandbox_* for staging/test and rk_live_* for production. The same key may be sent as Authorization: Bearer <key> if that suits your HTTP client better. A missing, invalid, expired, or revoked key returns 401 with a WWW-Authenticate: Bearer challenge; a valid key without the required scope returns 403.
In: header
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Parameters for creating a customer-portal session. The authenticated merchant must already own the referenced customer.
Response Body
application/json
application/json
application/json
application/json
curl -X POST "https://api.revkeen.com/v2/customer-portal/sessions" \
-H "x-api-key: $REVKEEN_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"customer_id": "cus_a1b2c3d4e5f6",
"ttl_minutes": 60
}'{ "data": { "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08", "customer_id": "160c0c4b-9966-4dc1-a916-8407eb10d74e", "merchant_id": "500924a8-3f5e-4c00-beb8-2efcde988aea", "url": "http://example.com", "expires_at": "2019-08-24T14:15:22Z", "created_at": "2019-08-24T14:15:22Z" }}Re-authorise a Direct Debit mandate with new bank details POST
Updates the existing provider customer with new bank details and returns the mandate to pending while the fresh Bacs instruction is lodged. Requires portal DD self-service. --- **Related endpoints** - `POST /customer-portal/sessions` — Create a customer-portal session - `GET /customer-portal/customer` — Retrieve the authenticated customer - `GET /customer-portal/subscriptions` — List the authenticated customer's subscriptions - `GET /customer-portal/subscriptions/{id}` — Retrieve a subscription - `POST /customer-portal/subscriptions/{id}/cancel` — Cancel a subscription - `GET /customer-portal/invoices` — List the authenticated customer's invoices - `GET /customer-portal/invoices/{id}` — Retrieve an invoice - `GET /customer-portal/mandates` — List the authenticated customer's Direct Debit mandates **Common errors** - `400 invalid_request` — malformed payload or failed validation. - `401 authentication_error` — missing, invalid, expired, or revoked credential. Codes: `authentication_failed`, `invalid_api_key`, `expired_api_key`, `api_key_revoked`, `session_invalid`, `merchant_required`. Carries a `WWW-Authenticate: Bearer` challenge. - `403 authorization_error` — the caller is identified but the action is denied. Codes include `insufficient_permissions`, `ip_not_allowed`, `merchant_mismatch`, and `origin_not_allowed`. - `404 resource_missing` — the referenced resource does not exist or is not visible to your key. - `409 conflict` — Idempotency-Key collision with a different body, or a concurrent state-transition conflict. - `422 unprocessable_entity` — business-rule failure (for example, refunding more than the original charge). **Idempotency** Pass an `Idempotency-Key` header (UUID v4 recommended) to make retries safe. Keys are valid for 24 hours; see [the idempotency guide](/docs/fundamentals/idempotency).
Cancel a subscription POST
Cancel a subscription owned by the authenticated customer. By default the subscription is scheduled to cancel at the end of the current billing period — set `cancel_at_period_end=false` to cancel immediately. Idempotent — cancelling an already-canceled subscription is a no-op that returns the current state. --- **Related endpoints** - `POST /customer-portal/sessions` — Create a customer-portal session - `GET /customer-portal/customer` — Retrieve the authenticated customer - `GET /customer-portal/subscriptions` — List the authenticated customer's subscriptions - `GET /customer-portal/subscriptions/{id}` — Retrieve a subscription - `GET /customer-portal/invoices` — List the authenticated customer's invoices - `GET /customer-portal/invoices/{id}` — Retrieve an invoice - `GET /customer-portal/mandates` — List the authenticated customer's Direct Debit mandates - `POST /customer-portal/mandates/{id}/re-authorize` — Re-authorise a Direct Debit mandate with new bank details **Common errors** - `401 authentication_error` — missing, invalid, expired, or revoked credential. Codes: `authentication_failed`, `invalid_api_key`, `expired_api_key`, `api_key_revoked`, `session_invalid`, `merchant_required`. Carries a `WWW-Authenticate: Bearer` challenge. - `404 resource_missing` — the referenced resource does not exist or is not visible to your key. **Idempotency** Pass an `Idempotency-Key` header (UUID v4 recommended) to make retries safe. Keys are valid for 24 hours; see [the idempotency guide](/docs/fundamentals/idempotency).