Before you start
- An account. See Create an account.
- A webhook endpoint with
event_sourceset toconnectorall. See Connect events. - Two URLs on your site, one to return to and one to refresh from.
Steps
1
Create the link
Use
type: "onboarding" for a new account, or update to collect more from one that is already live. Both refresh_url and return_url are required.id identifies the link object itself; the credential that makes the URL work is the opaque token embedded in url’s last path segment, and it is single-use. Do not construct this URL yourself or persist it past its expires_at.2
Send the account to the URL
Redirect the account holder to
url, or email it to them. The flow asks for whatever is currently due and nothing more.3
Handle the refresh URL
An expired or already-used link sends the account to
refresh_url. Your handler there creates a new link and redirects again:4
Confirm from the webhook
There is no event that says “the hosted flow finished.” The account lands on
return_url when it finishes, abandons halfway, or closes the tab without either, so treat that redirect as a cue to show a status screen, not as confirmation of anything. Confirm from the account’s own events instead.account.updated
What happens next
Anaccount.updated event with an empty outstanding means nothing is left for the account to provide, not that the account can transact. Wait for capability.updated with status: "active" before you unlock anything. See Monitor onboarding.

