Look up an Easy Connect customer by email
Returns whether the email corresponds to an enrolled customer AND is in a country eligible for Easy Connect SMS verification. Response shape is identical for unrecognized vs. recognized-but-ineligible so the endpoint can't be used to enumerate enrolled emails.
Authorization
apiKey Merchant API key. Publishable keys (pk_test_* / pk_live_) are safe for browser/frontend use and carry a limited scope set (sessions, payment_instruments, customers, orders writes; products, product_prices, payment_links reads). Secret keys (sk_test_ / sk_live_*) grant full admin access and must only be used server-side.
In: header
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://loading/v1/api/easy-connect/lookup" \ -H "Content-Type: application/json" \ -d '{ "email": "user@example.com" }'{
"success": true,
"timestamp": "2019-08-24T14:15:22Z",
"data": null,
"message": "string",
"pagination": {
"total": 0,
"limit": 1,
"offset": 0,
"has_more": true,
"truncated": true,
"cursors": {
"first": "string",
"last": "string"
}
}
}{
"success": false,
"timestamp": "2019-08-24T14:15:22Z",
"error": {
"code": "string",
"message": "string",
"details": null
}
}{
"success": false,
"timestamp": "2019-08-24T14:15:22Z",
"error": {
"code": "string",
"message": "string",
"details": null
}
}{
"success": false,
"timestamp": "2019-08-24T14:15:22Z",
"error": {
"code": "string",
"message": "string",
"details": null
}
}{
"success": false,
"timestamp": "2019-08-24T14:15:22Z",
"error": {
"code": "string",
"message": "string",
"details": null
}
}List cross-merchant saved methods for the authenticated customer
Returns canonical payment methods for the customer encoded in the customer-session JWT (Authorization: Bearer). Display metadata only — the per-merchant Finix PI id is intentionally omitted here; the iframe materializes it on demand at transfer time. Pass ?include_archived=true to include soft-deleted methods.
Refresh the customer-session token
Slides the customer-session JWT window. Requires Authorization: Bearer <token>. Enforces a 30-minute hard cap on the refresh chain — beyond that the customer must re-OTP.