> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.crisscross.money/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.crisscross.money/_mcp/server.

# Get Checkout Session

GET https://api.crisscross.money/v1/checkout/session

Retrieves the details of a specific checkout session using the provided session ID.
The response includes the session object and may include an active transaction if one exists.
Note that the hosted checkout `paymentLink` is returned only by session creation and is
not included here — see the [Payment Status & Recovery guide](/collect/payment-recovery).


Reference: https://docs.crisscross.money/api-reference/collect/payments/payment-initiation/get-checkout-session

## Request

### Query parameters

- `sessionId` (string, required) — Unique identifier for the checkout session.

## Response

### 200

Checkout session details retrieved successfully.

- `session` (CheckoutSession, required)
- `payerId` (string, optional) — Persistent identifier for the payer (customer) associated with this session. The same payer keeps the same `payerId` across all of their sessions and transactions. Store it against your customer record and pass it back in `payerDetails.payerId` on future sessions to recognise a returning customer. See the [Payer ID guide](/payer-id).
- `payerDetails` (GetCheckoutSessionPayerDetails, optional)
- `activeTransaction` (ActiveTransaction, optional) — The current active transaction for this session (if any). Fields may vary depending on payment method and auth state.

## Errors

### 401 Unauthorized Error

Unauthorized.

- `message` (string, required) — Human-readable description of what went wrong.
- `error` (string, required) — Error category. Most endpoints return the HTTP reason phrase (e.g. "Bad Request", "Unauthorized", "Conflict", "Unprocessable Entity", "Internal Server Error"). Some return a machine-readable snake_case code instead — notably the FX and rate-lock rejections on checkout session creation and payment initiation, where several distinct codes share a single HTTP status. Where a code is present it is the finer discriminator and is safe to branch on.
- `statusCode` (integer, required) — HTTP status code, mirroring the response header. The response header is the source of truth.

### 404 Not Found Error

Checkout session not found.

- `message` (string, required) — Human-readable description of what went wrong.
- `error` (string, required) — Error category. Most endpoints return the HTTP reason phrase (e.g. "Bad Request", "Unauthorized", "Conflict", "Unprocessable Entity", "Internal Server Error"). Some return a machine-readable snake_case code instead — notably the FX and rate-lock rejections on checkout session creation and payment initiation, where several distinct codes share a single HTTP status. Where a code is present it is the finer discriminator and is safe to branch on.
- `statusCode` (integer, required) — HTTP status code, mirroring the response header. The response header is the source of truth.

### 422 Unprocessable Entity Error

Unprocessable Entity.

- `message` (string, required) — Human-readable description of what went wrong.
- `error` (string, required) — Error category. Most endpoints return the HTTP reason phrase (e.g. "Bad Request", "Unauthorized", "Conflict", "Unprocessable Entity", "Internal Server Error"). Some return a machine-readable snake_case code instead — notably the FX and rate-lock rejections on checkout session creation and payment initiation, where several distinct codes share a single HTTP status. Where a code is present it is the finer discriminator and is safe to branch on.
- `statusCode` (integer, required) — HTTP status code, mirroring the response header. The response header is the source of truth.

## Types

### CheckoutSession

- `id` (string, required) — Unique identifier for the checkout session.
- `merchantId` (string, required) — Merchant identifier.
- `merchantReference` (string, required) — Your reference for the checkout session.
- `amount` (integer, required) — Amount in minor units, denominated in `currencyId` (the initiation currency).
- `currencyId` (string, required) — Currency of the session (ISO 4217) — the initiation currency supplied as `currency` at session creation. For a session priced by a [rate lock](/rate-locks) this is the lock's base currency; the amount the payer is actually charged is carried on `fxCommit`.
- `expiresAt` (datetime, required) — Timestamp when the session expires.
- `customerId` (string, required) — Persistent identifier for the payer behind this session — the same value as the top-level `payerId`. See the [Payer ID guide](/payer-id).
- `payerLocation` (string, required) — Country code of the payer (ISO 3166 alpha-3).
- `redirectUrl` (string, optional) — Optional URL to redirect after payment.
- `paymentAttributes` (map from string to string, optional) — Optional session attributes passed through the payment lifecycle.
- `fxCommit` (FxCommit, optional) — The FX commit currently applied to the session. Present when [Adaptive Currency Conversion](/adaptive-currency-conversion) has priced the session — by its default per-session quote (`pricingModel: SPOT_QUOTE`) or by an attached [rate lock](/rate-locks) (`pricingModel: RATE_LOCK`, with `fxCommit.quoteId` the `rlk_` rate lock id). Reflects the *latest* committed conversion; the rate a transaction actually settled at is preserved per-attempt on the transaction itself.

### GetCheckoutSessionPayerDetails

- `emailAddress` (string, optional)
- `location` (enum, optional)
  - Allowed values: `ZAF`, `NGA`, `UGA`, `ZMB`, `GHA`, `KEN`, `TZA`, `ETH`, `CMR`, `SEN`, `BEN`, `BFA`, `CIV`, `MLI`, `TGO`, `SLE`
- `fullName` (string, optional)
- `phoneNumber` (string, optional)
- `payerId` (string, optional) — Persistent identifier for the payer. See the [Payer ID guide](/payer-id).

### ActiveTransaction

The current active transaction for this session (if any). Fields may vary depending on payment method and auth state.

- `transactionId` (string, optional) — Unique identifier for the transaction.
- `status` (string, optional) — Current transaction status.
- `message` (string, optional) — Human-readable status message.

### FxCommit

Immutable FX conversion snapshot recorded when a session or transaction is priced in a currency other than the merchant's initiation currency. Written whenever [Adaptive Currency Conversion](/adaptive-currency-conversion) applies — priced per session by default, or by a [rate lock](/rate-locks).

- `quoteId` (string, required) — Identifier of the FX commitment that priced this conversion. For a session priced by a [rate lock](/rate-locks) this is the `rlk_` rate lock id — use it to read back which lock a session was priced against. For an ACC conversion it is the upstream quote identifier, preserved for audit.
- `collectionCurrency` (string, required) — ISO 4217 currency code the customer pays in.
- `collectionAmount` (string, required) — All-in amount the customer is asked to pay, in `collectionCurrency` major units (decimal string).
- `midRate` (string, required) — Spot mid-market rate before markup. `1 initiation-currency = midRate collection-currency` (decimal string, 8 decimal places).
- `markupBps` (integer, required) — Markup applied over the mid rate, in basis points (100 bps = 1%).
- `allInRate` (string, required) — The rate actually transacted at — `midRate * (1 + markupBps / 10000)` (decimal string, 8 decimal places).
- `fee` (string, required) — Markup component denominated in `collectionCurrency`, expressed as a major-unit decimal string.
- `expiresAt` (datetime, required) — RFC3339 timestamp. The commit is valid until this time; past-expiry payment submissions are rejected `422` (stale quote) and the hosted page refreshes the rate.
- `pricingModel` (enum, optional) — Which [Adaptive Currency Conversion](/adaptive-currency-conversion) flow priced the session — `SPOT_QUOTE` for the default [per-session rate](/api-reference/collect/per-session), `RATE_LOCK` for an attached [rate lock](/rate-locks). May be absent on sessions created before this field was introduced.
  - Allowed values: `SPOT_QUOTE`, `RATE_LOCK`

## Examples

### ACC — per-session rate (default)

**Response**

```json
{
  "session": {
    "id": "01951c8a-7c3d-7e1f-9d4a-2b3c4d5e6f70",
    "merchantId": "7c9e6679-7425-40de-944b-e07fc1f90ae7",
    "merchantReference": "ORDER-20260624-001",
    "amount": 10000,
    "currencyId": "USD",
    "expiresAt": "2026-06-24T11:00:00Z",
    "customerId": "9b2d7f3a-8c4e-4f1a-9d3e-1a2b3c4d5e6f",
    "payerLocation": "KEN",
    "redirectUrl": "https://merchant.example.com/order/confirmation",
    "paymentAttributes": {
      "paymentMethod": "card",
      "platform": "web"
    },
    "fxCommit": {
      "quoteId": "qut_01951c8a-9d5e-7f3b-bc4f-6e7d8c9b0a21",
      "collectionCurrency": "KES",
      "collectionAmount": "13260.00",
      "midRate": "130.00",
      "markupBps": 200,
      "allInRate": "132.60",
      "fee": "260.00",
      "expiresAt": "2026-06-24T10:35:00Z",
      "pricingModel": "SPOT_QUOTE"
    }
  }
}
```

**SDK Code**

```python ACC — per-session rate (default)
import requests

url = "https://api.crisscross.money/v1/checkout/session"

querystring = {"sessionId":"sessionId"}

response = requests.get(url, params=querystring)

print(response.json())
```

```javascript ACC — per-session rate (default)
const url = 'https://api.crisscross.money/v1/checkout/session?sessionId=sessionId';
const options = {method: 'GET'};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go ACC — per-session rate (default)
package main

import (
	"fmt"
	"net/http"
	"io"
)

func main() {

	url := "https://api.crisscross.money/v1/checkout/session?sessionId=sessionId"

	req, _ := http.NewRequest("GET", url, nil)

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby ACC — per-session rate (default)
require 'uri'
require 'net/http'

url = URI("https://api.crisscross.money/v1/checkout/session?sessionId=sessionId")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Get.new(url)

response = http.request(request)
puts response.read_body
```

```java ACC — per-session rate (default)
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.get("https://api.crisscross.money/v1/checkout/session?sessionId=sessionId")
  .asString();
```

```php ACC — per-session rate (default)
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.crisscross.money/v1/checkout/session?sessionId=sessionId');

echo $response->getBody();
```

```csharp ACC — per-session rate (default)
using RestSharp;

var client = new RestClient("https://api.crisscross.money/v1/checkout/session?sessionId=sessionId");
var request = new RestRequest(Method.GET);
IRestResponse response = client.Execute(request);
```

```swift ACC — per-session rate (default)
import Foundation

let request = NSMutableURLRequest(url: NSURL(string: "https://api.crisscross.money/v1/checkout/session?sessionId=sessionId")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "GET"

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```

### ACC — rate lock

**Response**

```json
{
  "session": {
    "id": "01951c8a-7c3d-7e1f-9d4a-2b3c4d5e6f70",
    "merchantId": "7c9e6679-7425-40de-944b-e07fc1f90ae7",
    "merchantReference": "ORDER-20260624-001",
    "amount": 10000,
    "currencyId": "USD",
    "expiresAt": "2026-06-24T11:00:00Z",
    "customerId": "9b2d7f3a-8c4e-4f1a-9d3e-1a2b3c4d5e6f",
    "payerLocation": "KEN",
    "redirectUrl": "https://merchant.example.com/order/confirmation",
    "paymentAttributes": {
      "paymentMethod": "card",
      "platform": "web"
    },
    "fxCommit": {
      "quoteId": "qut_01951c8a-9d5e-7f3b-bc4f-6e7d8c9b0a21",
      "collectionCurrency": "KES",
      "collectionAmount": "13260.00",
      "midRate": "130.00",
      "markupBps": 200,
      "allInRate": "132.60",
      "fee": "260.00",
      "expiresAt": "2026-06-24T10:35:00Z",
      "pricingModel": "SPOT_QUOTE"
    }
  }
}
```

**SDK Code**

```python ACC — rate lock
import requests

url = "https://api.crisscross.money/v1/checkout/session"

querystring = {"sessionId":"sessionId"}

response = requests.get(url, params=querystring)

print(response.json())
```

```javascript ACC — rate lock
const url = 'https://api.crisscross.money/v1/checkout/session?sessionId=sessionId';
const options = {method: 'GET'};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go ACC — rate lock
package main

import (
	"fmt"
	"net/http"
	"io"
)

func main() {

	url := "https://api.crisscross.money/v1/checkout/session?sessionId=sessionId"

	req, _ := http.NewRequest("GET", url, nil)

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby ACC — rate lock
require 'uri'
require 'net/http'

url = URI("https://api.crisscross.money/v1/checkout/session?sessionId=sessionId")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Get.new(url)

response = http.request(request)
puts response.read_body
```

```java ACC — rate lock
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.get("https://api.crisscross.money/v1/checkout/session?sessionId=sessionId")
  .asString();
```

```php ACC — rate lock
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('GET', 'https://api.crisscross.money/v1/checkout/session?sessionId=sessionId');

echo $response->getBody();
```

```csharp ACC — rate lock
using RestSharp;

var client = new RestClient("https://api.crisscross.money/v1/checkout/session?sessionId=sessionId");
var request = new RestRequest(Method.GET);
IRestResponse response = client.Execute(request);
```

```swift ACC — rate lock
import Foundation

let request = NSMutableURLRequest(url: NSURL(string: "https://api.crisscross.money/v1/checkout/session?sessionId=sessionId")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "GET"

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```