curl --request POST \
--url https://api.yo-lead.com/v1/embed/sessions \
--header 'Content-Type: application/json' \
--header 'X-YoLead-Key: <api-key>' \
--header 'X-YoLead-Signature: <api-key>' \
--header 'X-YoLead-Timestamp: <api-key>' \
--data '
{
"employeeId": "64f000000000000000000001",
"capabilities": [
"showChatPage",
"startOutboundChat",
"showSendInput"
]
}
'import requests
url = "https://api.yo-lead.com/v1/embed/sessions"
payload = {
"employeeId": "64f000000000000000000001",
"capabilities": ["showChatPage", "startOutboundChat", "showSendInput"]
}
headers = {
"X-YoLead-Key": "<api-key>",
"X-YoLead-Timestamp": "<api-key>",
"X-YoLead-Signature": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'X-YoLead-Key': '<api-key>',
'X-YoLead-Timestamp': '<api-key>',
'X-YoLead-Signature': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
employeeId: '64f000000000000000000001',
capabilities: ['showChatPage', 'startOutboundChat', 'showSendInput']
})
};
fetch('https://api.yo-lead.com/v1/embed/sessions', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.yo-lead.com/v1/embed/sessions",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'employeeId' => '64f000000000000000000001',
'capabilities' => [
'showChatPage',
'startOutboundChat',
'showSendInput'
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-YoLead-Key: <api-key>",
"X-YoLead-Signature: <api-key>",
"X-YoLead-Timestamp: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.yo-lead.com/v1/embed/sessions"
payload := strings.NewReader("{\n \"employeeId\": \"64f000000000000000000001\",\n \"capabilities\": [\n \"showChatPage\",\n \"startOutboundChat\",\n \"showSendInput\"\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-YoLead-Key", "<api-key>")
req.Header.Add("X-YoLead-Timestamp", "<api-key>")
req.Header.Add("X-YoLead-Signature", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.yo-lead.com/v1/embed/sessions")
.header("X-YoLead-Key", "<api-key>")
.header("X-YoLead-Timestamp", "<api-key>")
.header("X-YoLead-Signature", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"employeeId\": \"64f000000000000000000001\",\n \"capabilities\": [\n \"showChatPage\",\n \"startOutboundChat\",\n \"showSendInput\"\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.yo-lead.com/v1/embed/sessions")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-YoLead-Key"] = '<api-key>'
request["X-YoLead-Timestamp"] = '<api-key>'
request["X-YoLead-Signature"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"employeeId\": \"64f000000000000000000001\",\n \"capabilities\": [\n \"showChatPage\",\n \"startOutboundChat\",\n \"showSendInput\"\n ]\n}"
response = http.request(request)
puts response.read_body{
"data": {
"iframeUrl": "https://app.yo-lead.com/embed/chats/outbound#token=eyJ...",
"embedToken": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",
"expiresAt": "2026-05-08T12:00:00.000Z",
"capabilities": [
"showChatPage",
"startOutboundChat",
"showSendInput"
]
}
}Create embed session
Creates a short-lived iframe session for embedding YoLead chat UI in a customer system. Use the returned expiresAt value to determine when the session expires; do not assume a fixed lifetime.
Required API key scope: read. The startOutboundChat capability requires read-write; requesting it with a read key returns 403. Sending the first message in a new outbound chat also requires outbound chat initiation on the company’s current plan and returns 403 with code 40352 when unavailable.
A read key can only receive showChatsList and showChatPage. A read-write key can receive all supported capabilities. If showChatPage is requested without showChatsList, chatId is required unless startOutboundChat is also requested.
curl --request POST \
--url https://api.yo-lead.com/v1/embed/sessions \
--header 'Content-Type: application/json' \
--header 'X-YoLead-Key: <api-key>' \
--header 'X-YoLead-Signature: <api-key>' \
--header 'X-YoLead-Timestamp: <api-key>' \
--data '
{
"employeeId": "64f000000000000000000001",
"capabilities": [
"showChatPage",
"startOutboundChat",
"showSendInput"
]
}
'import requests
url = "https://api.yo-lead.com/v1/embed/sessions"
payload = {
"employeeId": "64f000000000000000000001",
"capabilities": ["showChatPage", "startOutboundChat", "showSendInput"]
}
headers = {
"X-YoLead-Key": "<api-key>",
"X-YoLead-Timestamp": "<api-key>",
"X-YoLead-Signature": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'X-YoLead-Key': '<api-key>',
'X-YoLead-Timestamp': '<api-key>',
'X-YoLead-Signature': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
employeeId: '64f000000000000000000001',
capabilities: ['showChatPage', 'startOutboundChat', 'showSendInput']
})
};
fetch('https://api.yo-lead.com/v1/embed/sessions', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.yo-lead.com/v1/embed/sessions",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'employeeId' => '64f000000000000000000001',
'capabilities' => [
'showChatPage',
'startOutboundChat',
'showSendInput'
]
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-YoLead-Key: <api-key>",
"X-YoLead-Signature: <api-key>",
"X-YoLead-Timestamp: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.yo-lead.com/v1/embed/sessions"
payload := strings.NewReader("{\n \"employeeId\": \"64f000000000000000000001\",\n \"capabilities\": [\n \"showChatPage\",\n \"startOutboundChat\",\n \"showSendInput\"\n ]\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-YoLead-Key", "<api-key>")
req.Header.Add("X-YoLead-Timestamp", "<api-key>")
req.Header.Add("X-YoLead-Signature", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.yo-lead.com/v1/embed/sessions")
.header("X-YoLead-Key", "<api-key>")
.header("X-YoLead-Timestamp", "<api-key>")
.header("X-YoLead-Signature", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"employeeId\": \"64f000000000000000000001\",\n \"capabilities\": [\n \"showChatPage\",\n \"startOutboundChat\",\n \"showSendInput\"\n ]\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.yo-lead.com/v1/embed/sessions")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-YoLead-Key"] = '<api-key>'
request["X-YoLead-Timestamp"] = '<api-key>'
request["X-YoLead-Signature"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"employeeId\": \"64f000000000000000000001\",\n \"capabilities\": [\n \"showChatPage\",\n \"startOutboundChat\",\n \"showSendInput\"\n ]\n}"
response = http.request(request)
puts response.read_body{
"data": {
"iframeUrl": "https://app.yo-lead.com/embed/chats/outbound#token=eyJ...",
"embedToken": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",
"expiresAt": "2026-05-08T12:00:00.000Z",
"capabilities": [
"showChatPage",
"startOutboundChat",
"showSendInput"
]
}
}Authorizations
Public API key generated in the YoLead UI.
Unix timestamp in milliseconds. Requests must be signed within a 5-minute window.
Hex HMAC-SHA256 signature over <timestamp>.<raw_body> using the API secret.
Body
Embed session settings.
MongoDB ObjectId represented as a 24-character hexadecimal string.
^[0-9a-fA-F]{24}$"64f000000000000000000001"
Requested iframe capabilities. startOutboundChat requires a read-write API key.
1UI/runtime capability granted to the generated iframe session.
showChatsList, showChatPage, startOutboundChat, showSendInput, showStatusButton, showAssigneeButton Chat to open and optionally restrict the session to. Required when showChatPage is requested without showChatsList, unless startOutboundChat is also requested.
^[0-9a-fA-F]{24}$"64f000000000000000000001"
Response
Embed session created.
Show child attributes
Show child attributes