How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

JPMorgan Chase Session API

Create session for clients or parties.

JPMorgan Chase Session API is one of 65 APIs that JPMorgan Chase publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Session. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, and an API reference.

This API exposes 2 operations across 1 path, and defines 11 schemas. It is described by OpenAPI 3.2.0, at version 1.0.18.

Requests are made against 3 base URLs: https://api.payments.jpmorgan.com/onboarding/v1, https://api-sandbox.payments.jpmorgan.com/onboarding/v1, https://api-mock.payments.jpmorgan.com/onboarding/v1.

2 operations 1 paths 11 schemas 1 GET1 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.0.18
Base URL
https://api.payments.jpmorgan.com/onboarding/v1
Authentication
HTTP Bearer
Contact
JPMC Technical Services Support
Resource Areas
1

Authentication & Security 1

JPMorgan Chase Session API declares 1 security scheme for authenticating requests. It accepts HTTP bearer tokens (BearerAuth). By default, every request must be authenticated.

Paths & Operations 2

Across 1 path, the API surfaces 2 operations — 1 GET, 1 POST. Each is listed below with its method, path, parameters, and response codes.

Session 2

Create session for clients or parties.

GET
/sessions
List sessions
smbdo-listSessions 4 params → 200400401403404500503
POST
/sessions
Create session.
smbdo-postSessions 2 params body → 201400401403404409422500

Schemas 11

The contract defines 11 schemas that model the data the API accepts and returns. The most detailed are schemas-ApiError (5 properties), SessionResponse (5 properties), ApiErrorContext (4 properties), PageMetaData (3 properties). Each schema is shown below with its type and property counts.

ListSessionResponse
object
2 properties
SessionTargetType
string
Client or party type.
SessionTargetId
string
The ID of the client or party.
ApiErrorContext
object
Context of the API error.
4 properties 1 required
SessionResponse
object
List of sessions.
5 properties
SessionTarget
object
2 properties 2 required
schemas-ApiError
object
An API error.
5 properties 2 required
SessionsType
string
PageMetaData
object
Page metadata.
3 properties
SessionId
string
ID to uniquely identify the session
CreateSessionRequest
object
2 properties 2 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

jp-morgan-chase-session-api-openapi.yml Raw ↑

Other APIs JPMorgan Chase publishes across the network.

Notifications API
Accounts API
Recipients API
Webhooks API
Transactions API
Documents API
JPMorgan Chase Account Information API
JPMorgan Chase Account Restrictions API
JPMorgan Chase Account Services API
JPMorgan Chase Account Statements API
JPMorgan Chase Account Transactions API
JPMorgan Chase Account Updates API
Where this information came from

This is an independent, third-party profile of JPMorgan Chase Session API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.