List stored merchant sessions
Buyer sessions
List stored merchant sessions
Metadata only. The cookie blob itself is encrypted at rest and is never returned by any endpoint.
Sessions are created only by checkout runs — a credentials login, or a refresh on a later success — so there is no POST here.
When the session vault is disabled on the deployment, this returns an empty list with vaultEnabled: false rather than an error.
Requires the buyer-sessions.read scope.
GET
List stored merchant sessions
Authorizations
Authorization: Bearer ck_test_… or ck_live_…. There is no other auth scheme — no query-string keys, no request signing, no OAuth.
Query Parameters
Narrow to one buyer.