Skip to content

Mint a customer session token for a browser or app

POST /customers/{customer_id}/session-tokens
Scopecustomers:read
Customer session tokenNot accepted: call from your server with an API key
Rate limit classread (limits)
Idempotency keyNot needed: this call has no side effect
MCP toolcharm_create_session_token (not exposed: minting is a storefront backend’s job)

Called by your server for the signed-in shopper; hand the returned token to their browser or app, which then calls the endpoints marked as accepting a session token directly, with CORS. The token speaks for this one customer only, carries read and/or write (independent: write does not include read), expires after ttl_seconds (default 3600, max 604800) and can never do more than the key that minted it. Revoking or pausing that key revokes its tokens. The customer does not have to be a member yet. No Idempotency-Key needed: minting has no side effect.

NameInTypeDescription
customer_idpathstringShopify customer GID (percent-encoded, e.g. gid%3A%2F%2Fshopify%2FCustomer%2F123) or the numeric customer id.
FieldTypeDescription
scopesarray of string: read, writeDefaults to ["read"]. (optional)
ttl_secondsinteger(optional)

Returns SessionToken.

FieldTypeDescription
tokenstringchrm_st_…; send as Authorization: Bearer <token>.
token_type"Bearer"
customer_idstringShopify customer GID, e.g. gid://shopify/Customer/123. Accepted by every endpoint that takes a customer id, as is the numeric legacy_id.
scopesarray of string: read, write
api_scopesarray of string
expires_ininteger
expires_atstring
{
"token": "chrm_st_eyJ2IjoxLCJzaG9wIjoi…",
"token_type": "Bearer",
"customer_id": "gid://shopify/Customer/7712345",
"scopes": [
"read"
],
"api_scopes": [
"api scopes"
],
"expires_in": 1,
"expires_at": "2026-10-01T09:30:00.000Z"
}
Terminal window
curl -X POST "https://charm.appfleece.app/api/v1/customers/7712345/session-tokens" \
-H "Authorization: Bearer chrm_live_..." \
-H "Content-Type: application/json" \
-d '{"scopes":["read"],"ttl_seconds":1}'

unauthorized · invalid_token · insufficient_scope · access_required · not_found · validation_error · rate_limited

Every error body carries code, message, request_id and a doc_url pointing at the matching entry in the error catalog.