Create embed session
Mints a short-lived embed session token bound to one loan. Requires a plan that includes the embedded review UI; other plans get a 403.
Authentication
Headers
Request
Optional opaque, stable identifier for the end user you are embedding for. Supply it and that user’s saved work persists across their sessions; omit it and the session keeps nothing. Max 256 characters after trimming, and a blank value is rejected rather than ignored.
Reserved. Stored with the end user’s id, not shown anywhere yet.
Requires external_user_id (a label on its own is a 400). Control
characters are stripped and the value trimmed; max 120 characters, and
a blank value is rejected rather than ignored.
Response headers
The API surface version the server resolved for this request. Always present, regardless of whether the client supplied the request-side SpreadSpace-Version header. Default: 2026-07-19.
Requests left in the current window. Suppressed on 429 responses produced outside the rate limiter (for example a usage throttle), where a remaining budget would be misleading.
Seconds until a guaranteed-fresh window.
The active policy in limit;w=window-seconds form.
Response
How far the end user’s work survives this session. user means the
mint carried an external_user_id, so saved spreads, preferences
and memo templates come back on that user’s next session. session
means it did not, so everything the end user arranges is discarded when
the frame unloads. Always present.
Echo of the request’s external_user_id, trimmed. Omitted when the
mint carried no end-user id.
Echo of the request’s display_name as stored, with control
characters stripped and the value trimmed. Omitted when the mint carried
no label.