> ## Documentation Index
> Fetch the complete documentation index at: https://docs.trylath.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> Every Lath operation is POST https://platform.trylath.com/<operation name with dots replaced by slashes>, with a JSON body and `Authorization: Bearer <key>`. `email.send` is POST /email/send.
> Branch on `error.code`, never on `error.message`. Every refusal also carries `error.fix`, which names the next step.
> Send an `Idempotency-Key` header on any operation that is not retry-safe, so a retry cannot run it twice.
> A `lath_test_` key emails only the account's own members and sends no SMS; a `lath_live_` key reaches real recipients and is billed.
> The OpenAPI document, generated from the same registry as the routes, is at https://platform.trylath.com/openapi.json.

# billing.payment.setup

> Starts adding a card to this account. Returns a URL on the payment processor's own hosted page where the card is entered; nothing is charged there, and the card details never reach Lath. Open the URL, complete it, then call billing.payment.get to confirm what is on file. The link is single-use and expires; call this again for a fresh one.



## OpenAPI

````yaml /api-reference/openapi.json post /billing/payment/setup
openapi: 3.1.0
info:
  title: Lath API
  version: 0.1.0
  description: >-
    Every operation is one POST. The same set is reachable over MCP, the SDK and
    the CLI; nothing is dashboard-only.
servers:
  - url: https://platform.trylath.com
    description: This deployment
security: []
paths:
  /billing/payment/setup:
    post:
      tags:
        - billing
      summary: billing.payment.setup
      description: >-
        Starts adding a card to this account. Returns a URL on the payment
        processor's own hosted page where the card is entered; nothing is
        charged there, and the card details never reach Lath. Open the URL,
        complete it, then call billing.payment.get to confirm what is on file.
        The link is single-use and expires; call this again for a fresh one.
      operationId: billing.payment.setup
      parameters:
        - name: Idempotency-Key
          in: header
          required: false
          schema:
            type: string
          description: >-
            Replays the stored response for the same key and input; refuses
            different input.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $schema: https://json-schema.org/draft/2020-12/schema
              type: object
              properties:
                successUrl:
                  type: string
                  maxLength: 2000
                  format: uri
                  description: Where the processor sends the person after the card is saved
                cancelUrl:
                  description: Where they go if they back out; defaults to successUrl
                  type: string
                  maxLength: 2000
                  format: uri
              required:
                - successUrl
              additionalProperties: false
      responses:
        '200':
          description: '{ activityId, result }. activityId is empty for reads.'
          content:
            application/json:
              schema:
                type: object
                properties:
                  activityId:
                    type: string
                    description: The activity this call created, or empty for a read.
                  result:
                    $schema: https://json-schema.org/draft/2020-12/schema
                    type: object
                    properties:
                      url:
                        type: string
                      sessionId:
                        type: string
                      currentCard: {}
                    required:
                      - url
                      - sessionId
                      - currentCard
                    additionalProperties: {}
                required:
                  - activityId
                  - result
        '400':
          description: invalid_input or invalid_json
        '401':
          description: unauthenticated
        '403':
          description: forbidden
        '404':
          description: not_found
        '409':
          description: 'conflict: idempotency_mismatch, email_taken, last_key'
        '413':
          description: body_too_large
        '429':
          description: rate_limited
      security:
        - bearer: []
components:
  securitySchemes:
    bearer:
      type: http
      scheme: bearer
      description: >-
        A Lath API key: lath_live_sk… or lath_test_sk… on a server,
        lath_live_pk… or lath_test_pk… in a browser.

````