Stripe Ephemeral Keys API

Stripe.js uses ephemeral keys to securely retrieve Card information from the Stripe API without publicly exposing your secret keys. You need to do some of the ephemeral key exchange on the server-side to set this up.

Operations 2

Each operation below carries the questions people ask an LLM about it and the instructions they give an agent to run it. Generated by API Evangelist overlay

POST /v1/ephemeral_keys Create a short-lived client key · Post ephemeral keys #
Ask an LLM
“How do I give a mobile app temporary access to a customer's saved payment details?”
“Can I issue a short-lived key scoped to one issuing card or verification session?”
Tell an agent
Create an ephemeral key for customer {customer}.
Create an ephemeral key for issuing card {issuing_card} with nonce {nonce}.
DELETE /v1/ephemeral_keys/{key} Revoke a short-lived client key · Delete ephemeral keys key #
Ask an LLM
“How do I invalidate an ephemeral key before it expires?”
“Can I revoke a client's temporary key when a user logs out?”
Tell an agent destructive · confirm first
Revoke ephemeral key {key}.
Invalidate short-lived key {key} now.

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/stripe-ephemeral-keys-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

stripe-ephemeral-keys-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: Stripe Ephemeral Keys API
  description: Needs description.
  contact:
    email: dev-platform@stripe.com
    name: Stripe Dev Platform Team
    url: https://stripe.com
  termsOfService: https://stripe.com/us/terms/
  version: '2023-10-16'
  x-stripeSpecFilename: spec3
servers:
- url: https://api.stripe.com/
security:
- basicAuth: []
- bearerAuth: []
tags:
- name: Ephemeral Keys
paths:
  /v1/ephemeral_keys:
    post:
      description: Creates a short-lived API key for a given resource.
      operationId: PostEphemeralKeys
      requestBody:
        content:
          application/x-www-form-urlencoded:
            encoding:
              expand:
                explode: true
                style: deepObject
            schema:
              additionalProperties: false
              $ref: '#/components/schemas/PostEphemeralKeysRequest'
        required: false
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ephemeral_key'
          description: Successful response.
        default:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error'
          description: Error response.
      tags:
      - Ephemeral Keys
      summary: Post ephemeral keys
      x-summary-source: derived
  /v1/ephemeral_keys/{key}:
    delete:
      description: Invalidates a short-lived API key for a given resource.
      operationId: DeleteEphemeralKeysKey
      parameters:
      - in: path
        name: key
        required: true
        schema:
          maxLength: 5000
          type: string
        style: simple
      requestBody:
        content:
          application/x-www-form-urlencoded:
            encoding:
              expand:
                explode: true
                style: deepObject
            schema:
              additionalProperties: false
              $ref: '#/components/schemas/DeleteEphemeralKeysKeyRequest'
        required: false
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ephemeral_key'
          description: Successful response.
        default:
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/error'
          description: Error response.
      tags:
      - Ephemeral Keys
      summary: Delete ephemeral keys key
      x-summary-source: derived
components:
  schemas:
    PostEphemeralKeysRequest:
      type: object
      properties:
        customer:
          description: The ID of the Customer you'd like to modify using the resulting ephemeral key.
          maxLength: 5000
          type: string
        expand:
          description: Specifies which fields in the response should be expanded.
          items:
            maxLength: 5000
            type: string
          type: array
        issuing_card:
          description: The ID of the Issuing Card you'd like to access using the resulting ephemeral key.
          maxLength: 5000
          type: string
        nonce:
          description: A single-use token, created by Stripe.js, used for creating ephemeral keys for Issuing Cards without exchanging sensitive information.
          maxLength: 5000
          type: string
        verification_session:
          description: The ID of the Identity VerificationSession you'd like to access using the resulting ephemeral key
          maxLength: 5000
          type: string
    DeleteEphemeralKeysKeyRequest:
      type: object
      properties:
        expand:
          description: Specifies which fields in the response should be expanded.
          items:
            maxLength: 5000
            type: string
          type: array
    error:
      description: An error response from the Stripe API
      properties:
        error:
          $ref: '#/components/schemas/api_errors'
      required:
      - error
      type: object
    ephemeral_key:
      description: ''
      properties:
        created:
          description: Time at which the object was created. Measured in seconds since the Unix epoch.
          format: unix-time
          type: integer
        expires:
          description: Time at which the key will expire. Measured in seconds since the Unix epoch.
          format: unix-time
          type: integer
        id:
          description: Unique identifier for the object.
          maxLength: 5000
          type: string
        livemode:
          description: Has the value `true` if the object exists in live mode or the value `false` if the object exists in test mode.
          type: boolean
        object:
          description: String representing the object's type. Objects of the same type share the same value.
          enum:
          - ephemeral_key
          type: string
        secret:
          description: The key's secret. You can use this value to make authorized requests to the Stripe API.
          maxLength: 5000
          type: string
      required:
      - created
      - expires
      - id
      - livemode
      - object
      title: EphemeralKey
      type: object
      x-expandableFields: []
      x-resourceId: ephemeral_key
  securitySchemes:
    basicAuth:
      description: 'Basic HTTP authentication. Allowed headers-- Authorization: Basic <api_key> | Authorization: Basic <base64 hash of `api_key:`>'
      scheme: basic
      type: http
    bearerAuth:
      bearerFormat: auth-scheme
      description: 'Bearer HTTP authentication. Allowed headers-- Authorization: Bearer <api_key>'
      scheme: bearer
      type: http