> ## Documentation Index
> Fetch the complete documentation index at: https://docs.calmtreasury.xyz/llms.txt
> Use this file to discover all available pages before exploring further.

# Exchange an auth intent for tokens

> Complete Link authentication for the session.

Completes Link authentication. The resulting access token is stored server-side
and never reaches the browser. A `link_not_found` means the email has no Link
account yet — register the buyer and retry.

Returns 204 with no body. Read
[Get the session's Stripe login state](/api/stripe/login-state) to confirm the
buyer is authenticated.


## OpenAPI

````yaml api/openapi.json POST /v1/stripe/tokens
openapi: 3.1.0
info:
  description: Fiat-to-USDC onramp API. The URL prefix (`/v1`) is the version contract.
  license:
    identifier: LicenseRef-Proprietary
    name: Proprietary
  title: Calm API
  version: v1
servers:
  - description: Production
    url: https://api.calmtreasury.xyz
  - description: Sandbox
    url: https://api.sandbox.calmtreasury.xyz
security: []
paths:
  /v1/stripe/tokens:
    post:
      summary: Exchange an auth intent for tokens
      description: >-
        Exchanges a consented auth intent for the per-user OAuth tokens and
        stores them server-side. Returns 204; the access token never reaches the
        browser. The bound intent must match this session.
      operationId: createStripeTokens
      requestBody:
        content:
          application/json:
            schema:
              properties:
                auth_intent_id:
                  minLength: 1
                  type: string
                wallet:
                  pattern: ^0x[a-fA-F0-9]{40}$
                  type: string
              required:
                - wallet
                - auth_intent_id
              type: object
        required: true
      responses:
        '204':
          description: Tokens stored.
        '400':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
          description: >-
            Bad Request — `error.code` includes: publishable_key_missing,
            validation_error.
        '401':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
          description: 'Unauthorized — `error.code` includes: invalid_publishable_key.'
        '403':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
          description: >-
            Forbidden — `error.code` includes: binding_invalid, link_forbidden,
            origin_not_allowed.
        '404':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
          description: 'Not Found — `error.code` includes: link_not_found.'
        '409':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
          description: 'Conflict — `error.code` includes: link_revoked.'
        '429':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
          description: 'Too Many Requests — `error.code` includes: rate_limited.'
        '502':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
          description: >-
            Bad Gateway — an upstream dependency failed; the body carries the
            standard error envelope with a cause-specific `error.code`.
      security:
        - publishableKey: []
components:
  schemas:
    Error:
      properties:
        error:
          properties:
            code:
              type: string
            message:
              type: string
          required:
            - code
            - message
          type: object
      required:
        - error
      type: object
  securitySchemes:
    publishableKey:
      description: Publishable key identifying the calling app.
      in: header
      name: x-calm-publishable-key
      type: apiKey

````