Create a private, read-only report embed session
curl --request POST \
--url https://api.trycactus.com/v1/underwritings/{underwriting_id}/embed-sessions \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"end_user_ref": "<string>",
"parent_origin": "https://app.partner.example"
}
'import requests
url = "https://api.trycactus.com/v1/underwritings/{underwriting_id}/embed-sessions"
payload = {
"end_user_ref": "<string>",
"parent_origin": "https://app.partner.example"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({end_user_ref: '<string>', parent_origin: 'https://app.partner.example'})
};
fetch('https://api.trycactus.com/v1/underwritings/{underwriting_id}/embed-sessions', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.trycactus.com/v1/underwritings/{underwriting_id}/embed-sessions",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'end_user_ref' => '<string>',
'parent_origin' => 'https://app.partner.example'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.trycactus.com/v1/underwritings/{underwriting_id}/embed-sessions"
payload := strings.NewReader("{\n \"end_user_ref\": \"<string>\",\n \"parent_origin\": \"https://app.partner.example\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.trycactus.com/v1/underwritings/{underwriting_id}/embed-sessions")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"end_user_ref\": \"<string>\",\n \"parent_origin\": \"https://app.partner.example\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.trycactus.com/v1/underwritings/{underwriting_id}/embed-sessions")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"end_user_ref\": \"<string>\",\n \"parent_origin\": \"https://app.partner.example\"\n}"
response = http.request(request)
puts response.read_body{
"id": "emb_01J9ZK3M",
"object": "underwriting_embed_session",
"underwriting_id": "<string>",
"url": "<string>",
"launch_expires_at": "2023-11-07T05:31:56Z",
"session_ttl_seconds": 900
}Underwritings
Create a private, read-only report embed session
Call from your authenticated backend. Checks partner, customer, and underwriting ownership. Only completed runs with results can be embedded. The parent origin must be registered on your partner account. The returned URL contains a one-time launch ticket in its fragment, valid for 60 seconds. Loading it exchanges the ticket for a renewable 15-minute report-only lease. The authenticated host can renew it without reloading the iframe. No public share link is created. Do not cache or log the returned URL.
POST
/
v1
/
underwritings
/
{underwriting_id}
/
embed-sessions
Create a private, read-only report embed session
curl --request POST \
--url https://api.trycactus.com/v1/underwritings/{underwriting_id}/embed-sessions \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"end_user_ref": "<string>",
"parent_origin": "https://app.partner.example"
}
'import requests
url = "https://api.trycactus.com/v1/underwritings/{underwriting_id}/embed-sessions"
payload = {
"end_user_ref": "<string>",
"parent_origin": "https://app.partner.example"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({end_user_ref: '<string>', parent_origin: 'https://app.partner.example'})
};
fetch('https://api.trycactus.com/v1/underwritings/{underwriting_id}/embed-sessions', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.trycactus.com/v1/underwritings/{underwriting_id}/embed-sessions",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'end_user_ref' => '<string>',
'parent_origin' => 'https://app.partner.example'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.trycactus.com/v1/underwritings/{underwriting_id}/embed-sessions"
payload := strings.NewReader("{\n \"end_user_ref\": \"<string>\",\n \"parent_origin\": \"https://app.partner.example\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.trycactus.com/v1/underwritings/{underwriting_id}/embed-sessions")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"end_user_ref\": \"<string>\",\n \"parent_origin\": \"https://app.partner.example\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.trycactus.com/v1/underwritings/{underwriting_id}/embed-sessions")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"end_user_ref\": \"<string>\",\n \"parent_origin\": \"https://app.partner.example\"\n}"
response = http.request(request)
puts response.read_body{
"id": "emb_01J9ZK3M",
"object": "underwriting_embed_session",
"underwriting_id": "<string>",
"url": "<string>",
"launch_expires_at": "2023-11-07T05:31:56Z",
"session_ttl_seconds": 900
}Authorizations
Partner API key issued by Cactus.
Path Parameters
Body
application/json