Skip to main content
POST

Authorizations

Authorization
string
header
required

JWT bearer token obtained via the OAuth2 client-credentials grant from the platform Authentication API. The token's scopes gate the endpoints it may call, and its audience names the Guardian instance. This is the standard way to authenticate to Guardian.

Body

application/json
source
From Session · object
required

Where the network token is provisioned from. type selects the variant.

metadata
object

Metadata consisting of key-value entries.

  • Maximum 20 key-value pairs.
  • Maximum 20 characters per key.
  • Maximum 80 characters per value.
Example:

Response

Success response

Which variant you get follows the request's source.type, and the three carry no shared tag field — tell them apart by shape.

  • A session source returns the Session object (session_id only).
  • A pan or pci_token source returns the Network Token.
  • A wallet_token source returns Wallet Token Promotion, which nests the created network_token alongside the originating source.
session_id
string<uuid>
required
Example:

"0f2c8f7e-4d2a-4d1b-9a6e-1c9b2d3e4f50"