Mint a customer session token for a browser or app
POST /customers/{customer_id}/session-tokens| Scope | customers:read |
| Customer session token | Not accepted: call from your server with an API key |
| Rate limit class | read (limits) |
| Idempotency key | Not needed: this call has no side effect |
| MCP tool | charm_create_session_token (not exposed: minting is a storefront backend’s job) |
Called by your server for the signed-in shopper; hand the returned token to their browser or app, which then calls the endpoints marked as accepting a session token directly, with CORS. The token speaks for this one customer only, carries read and/or write (independent: write does not include read), expires after ttl_seconds (default 3600, max 604800) and can never do more than the key that minted it. Revoking or pausing that key revokes its tokens. The customer does not have to be a member yet. No Idempotency-Key needed: minting has no side effect.
Parameters
Section titled “Parameters”| Name | In | Type | Description |
|---|---|---|---|
customer_id | path | string | Shopify customer GID (percent-encoded, e.g. gid%3A%2F%2Fshopify%2FCustomer%2F123) or the numeric customer id. |
Request body
Section titled “Request body”| Field | Type | Description |
|---|---|---|
scopes | array of string: read, write | Defaults to ["read"]. (optional) |
ttl_seconds | integer | (optional) |
Response 201
Section titled “Response 201”Returns SessionToken.
| Field | Type | Description |
|---|---|---|
token | string | chrm_st_…; send as Authorization: Bearer <token>. |
token_type | "Bearer" | |
customer_id | string | Shopify customer GID, e.g. gid://shopify/Customer/123. Accepted by every endpoint that takes a customer id, as is the numeric legacy_id. |
scopes | array of string: read, write | |
api_scopes | array of string | |
expires_in | integer | |
expires_at | string |
{ "token": "chrm_st_eyJ2IjoxLCJzaG9wIjoi…", "token_type": "Bearer", "customer_id": "gid://shopify/Customer/7712345", "scopes": [ "read" ], "api_scopes": [ "api scopes" ], "expires_in": 1, "expires_at": "2026-10-01T09:30:00.000Z"}Example
Section titled “Example”curl -X POST "https://charm.appfleece.app/api/v1/customers/7712345/session-tokens" \ -H "Authorization: Bearer chrm_live_..." \ -H "Content-Type: application/json" \ -d '{"scopes":["read"],"ttl_seconds":1}'Errors
Section titled “Errors”unauthorized · invalid_token · insufficient_scope · access_required · not_found · validation_error · rate_limited
Every error body carries code, message, request_id and a doc_url pointing at the matching entry in the error catalog.