Skip to main content
POST
Create a session

Authorizations

Authorization
string
header
required

One client per partner per environment. Access tokens expire after 15 minutes. Scopes are granted per client. Sandbox clients use https://sandbox.api.meet-oj.com/oauth/token.

Headers

Idempotency-Key
string
required

IETF Idempotency-Key semantics (draft-ietf-httpapi-idempotency-key-header). Send a fresh unique value (a UUID) with every new request. A retry with the same key and the same payload returns the original response with the header Idempotent-Replayed: true. The same key with a different payload is rejected with 422 and code idempotency_key_reused. Keys are kept for 24 hours.

Maximum string length: 255

Body

application/json

What you send to create a partner session. A session unlocks one O.J. screen, either as an Embed component inside your page or as a hosted page. purpose picks the screen.

For a new business, use intake and put whatever you already know in prefill, so the borrower confirms it instead of typing it again. For an existing referral, pass its referral_id. theme sets your logo and colour. The wording and legal disclosures on the screen are O.J.'s and cannot be changed.

purpose
enum<string>
required

Which component (or hosted page) this session unlocks. See x-embed for what each one shows.

Available options:
status,
conversation,
intake,
documents,
bank_connect,
offer_acceptance
return_url
string<uri>
required
referral_id
string

Required for every purpose except intake.

options
object

Per-component options listed in x-embed (for example compact for the status card, skip_known_fields for intake, document_request_ids for documents).

prefill
object

For intake — anything already known; the borrower confirms rather than retypes.

expires_in_seconds
integer
default:86400
Required range: 300 <= x <= 604800
theme
object

Partner colors and logo. O.J.'s copy and disclosures are not editable.

Response

Session created

A minted hosted-page link. Send the borrower to url by redirect, new tab, text message, or QR code. When they finish, they are returned to your return_url with ?referral_id= appended.

id
string
required
Example:

"ps_01K5X3T5E9"

url
string<uri>
required

Redirect, open in a new tab, or render as a QR code.

expires_at
string<date-time>
required
object
string
Allowed value: "partner_session"
client_token
string

Hand this to the browser for O.J. Embed (OJ.create({ token })). Single use, 15 minutes, bound to this session's purpose and referral. Never expose your client credentials to a browser; this token is what goes there instead.

referral_id
string