Create iframe URL

Mints a single-use signed URL that loads the embedded review UI in an iframe, so the token itself never reaches the parent frame. Requires a plan that includes the embedded review UI; other plans get a 403.

Authentication

AuthorizationBearer
Bearer token. Use `ss_live_…` for live data or `ss_test_…` for the sandbox (test mode). See [Authentication](https://docs.spreadspace.app/api/authentication).

Headers

SpreadSpace-VersionstringOptionalformat: "^\d{4}-\d{2}-\d{2}$"
Pin the API version, e.g. `2026-07-19`. Omit to get the latest. See [Versioning](https://docs.spreadspace.app/api/versioning).

Request

This endpoint expects an object.
loan_idstringRequired
surfacestringRequired
scopeslist of strings or nullOptional
handle_lifetime_secondsinteger or nullOptional
token_lifetime_secondsinteger or nullOptional
external_user_idstring or nullOptional

Optional opaque, stable end-user identifier, with the same contract as external_user_id on POST /api/embed/sessions. It is carried onto the session the exchange returns.

display_namestring or nullOptional

Reserved, with the same contract as display_name on POST /api/embed/sessions, including that it requires external_user_id. It is carried onto the session the exchange returns.

Response headers

X-Request-IDstringOptional
Correlation ID for this request. Quote it in support tickets.
SpreadSpace-VersionstringOptional

The API surface version the server resolved for this request. Always present, regardless of whether the client supplied the request-side SpreadSpace-Version header. Default: 2026-07-19.

RateLimit-Limitinteger
Request budget of the endpoint's rate-limit policy per 60-second sliding window. See [Rate limits](https://docs.spreadspace.app/api/rate-limits).
RateLimit-Remaininginteger

Requests left in the current window. Suppressed on 429 responses produced outside the rate limiter (for example a usage throttle), where a remaining budget would be misleading.

RateLimit-Resetinteger

Seconds until a guaranteed-fresh window.

RateLimit-PolicystringOptional

The active policy in limit;w=window-seconds form.

Response

OK
signed_urlstring
handle_idstring
expires_atdatetime
surfacestring
loan_idstring
borrower_idstring
scopeslist of strings
display_namestring or nullOptional

Echo of the request’s display_name as stored, with control characters stripped and the value trimmed. Omitted when the request carried no label.

Errors

400
Bad Request Error
401
Unauthorized Error
403
Forbidden Error
404
Not Found Error
429
Too Many Requests Error
500
Internal Server Error