---
title: "Create Link Token"
method: POST
path: "/link/token/create"
tags: ["plaid"]
---

# Create Link Token

`POST /link/token/create`

The `/link/token/create` endpoint creates a `link_token`, which is required as a parameter when initializing Link. Once Link has been initialized, it returns a `public_token`. For most Plaid products, the `public_token` is saved and exchanged for an `access_token` via `/item/public_token/exchange` as part of the main Link flow. For more details, see the [Link flow overview](https://plaid.com/docs/link/#link-flow-overview).

A `link_token` generated by `/link/token/create` is also used to initialize other Link flows, such as the [update mode](https://plaid.com/docs/link/update-mode) flow for tokens with expired credentials, or the Identity Verification flow.

## Request body

- LinkTokenCreateRequest — LinkTokenCreateRequest defines the request schema for `/link/token/create`
  - `client_id` string — Your Plaid API `client_id`. The `client_id` is required and may be provided either in the `PLAID-CLIENT-ID` header or as part of a request body.
  - `secret` string — Your Plaid API `secret`. The `secret` is required and may be provided either in the `PLAID-SECRET` header or as part of a request body.
  - `client_name` string, required — The name of your application, as it should be displayed in Link. Maximum length of 30 characters. If a value longer than 30 characters is provided, Link will display "This Application" instead.
  - `language` string, required — The language that Link should be displayed in. When initializing with Identity Verification, this field is not used; for more details, see [Identity Verification supported languages](https://plaid.com/docs/identity-verification/#supported-languages). Supported languages are: - Danish (`'da'`) - Dutch (`'nl'`) - English (`'en'`) - Estonian (`'et'`) - French (`'fr'`) - German (`'de'`) - Hindi (`'hi'`) - Italian (`'it'`) - Latvian (`'lv'`) - Lithuanian (`'lt'`) - Norwegian (`'no'`) - Polish (`'pl'`) - Portuguese (`'pt'`) - Romanian (`'ro'`) - Spanish (`'es'`) - Swedish (`'sv'`) - Vietnamese (`'vi'`) When using a Link customization, the language configured here must match the setting in the customization, or the customization will not be applied.
  - `country_codes` CountryCode[], required — Specify an array of Plaid-supported country codes using the ISO-3166-1 alpha-2 country code standard. Institutions from all listed countries will be shown. For a complete mapping of supported products by country, see https://support.plaid.com/hc/en-us/articles/27895826947735-What-Plaid-products-are-supported-in-each-country-and-region. For access to additional countries beyond what you have been approved for, [contact sales](https://plaid.com/contact/), your account manager, or support. If using Identity Verification, `country_codes` should be set to the country where your company is based, not the country where your user is located. For all other products, `country_codes` represents the location of your user's financial institution. If Link is launched with multiple country codes, only products that you are enabled for in all countries will be used by Link. While all countries are enabled by default in Sandbox, in Production only the countries you have requested access for are shown. To request access to additional countries, [file a product access Support ticket](https://dashboard.plaid.com/support/new/product-and-development/product-troubleshooting/request-product-access) via the Plaid dashboard. If using a Link customization, make sure the country codes in the customization match those specified in `country_codes`, or the customization may not be applied. If using the Auth features Instant Match, Instant Micro-deposits, Same-Day Micro-deposits, Automated Micro-deposits, or Database Auth, `country_codes` must be set to `['US']`.
  - `user` LinkTokenCreateRequestUser — An object specifying information about the end user who will be linking their account. **Required** if `user_id` isn't included.
    - `client_user_id` string, required — A unique ID representing the end user. Typically this will be a user ID number from your application. Personally identifiable information, such as an email address or phone number, should not be used in the `client_user_id`. It is currently used as a means of searching logs for the given user in the Plaid Dashboard.
    - `legal_name` string — The user's full legal name, used for [micro-deposit based verification flows](https://plaid.com/docs/auth/coverage/). For a small number of customers on legacy flows, providing this field is required to enable micro-deposit-based flows. For all other customers, this field is optional. Providing the user's name in this field when using micro-deposit-based verification will streamline the end user experience, as the user will not be prompted to enter their name during the Link flow; Plaid will use the provided legal name instead.
    - `name` object, nullable — The user's full name. Optional if using the [Identity Verification](https://plaid.com/docs/api/products/identity-verification) product; if not using Identity Verification, this field is not allowed. Users will not be asked for their name when this field is provided.
      - `given_name` string, required — A string with at least one non-whitespace character, with a max length of 100 characters.
      - `family_name` string, required — A string with at least one non-whitespace character, with a max length of 100 characters.
    - `phone_number` string — The user's phone number in [E.164](https://en.wikipedia.org/wiki/E.164) format. If supplied, will be used when applicable to prefill phone number fields in Link for the [returning user flow](https://plaid.com/docs/link/returning-user) and the [Identity Verification flow](https://plaid.com/docs/identity-verification). Phone number input is validated against valid number ranges; number strings that do not match a real-world phone numbering scheme may cause the request to fail, even in the Sandbox test environment.
    - `phone_number_verified_time` string, date-time, nullable — The date and time the phone number was verified in [ISO 8601](https://wikipedia.org/wiki/ISO_8601) format (`YYYY-MM-DDThh:mm:ssZ`). This was previously an optional field used in the [returning user experience](https://plaid.com/docs/link/returning-user). This field is no longer required to enable the returning user experience. Only pass a verification time for a phone number that you have verified. If you have performed verification but don't have the time, you may supply a signal value of the start of the UNIX epoch. Example: `2020-01-01T00:00:00Z`
    - `email_address` string — The user's email address. Can be used to prefill Link fields when used with [Identity Verification](https://plaid.com/docs/identity-verification).
    - `email_address_verified_time` string, date-time, nullable — The date and time the email address was verified in [ISO 8601](https://wikipedia.org/wiki/ISO_8601) format (`YYYY-MM-DDThh:mm:ssZ`). This was previously an optional field used in the [returning user experience](https://plaid.com/docs/link/returning-user). This field is no longer required to enable the returning user experience. Only pass a verification time for an email address that you have verified. If you have performed verification but don't have the time, you may supply a signal value of the start of the UNIX epoch. Example: `2020-01-01T00:00:00Z`
    - `ssn` string — Deprecated and not currently used, use the `id_number` field instead.
    - `date_of_birth` string, date, nullable — To be provided in the format "yyyy-mm-dd". Can be used to prefill Link fields when used with Identity Verification.
    - `address` object, nullable — The user's address. Used only for Identity Verification and the Identity Match in Link workflows. If provided for Identity Verification, the user will not be shown fields to enter their address in the Identity Verification flow. If provided for Identity Match, the provided data will be used to match against the user's address. May be omitted, but if not omitted, all fields marked as required must be provided.
      - `street` string, nullable — The primary street portion of an address. If an address is provided, this field will always be filled. A string with at least one non-whitespace alphabetical character, with a max length of 80 characters.
      - `street2` string, nullable — Extra street information, like an apartment or suite number. If provided, a string with at least one non-whitespace character, with a max length of 50 characters.
      - `city` string, nullable — City from the address. A string with at least one non-whitespace alphabetical character, with a max length of 100 characters.
      - `region` string, nullable — A subdivision code. "Subdivision" is a generic term for "state", "province", "prefecture", "zone", etc. For the list of valid codes, see [country subdivision codes](https://plaid.com/documents/country_subdivision_codes.json). Country prefixes are omitted, since they are inferred from the `country` field.
      - `postal_code` string, nullable — The postal code for the associated address. Between 2 and 10 alphanumeric characters. For US-based addresses this must be 5 numeric digits.
      - `country` string, required — Valid, capitalized, two-letter ISO code representing the country of this object. Must be in ISO 3166-1 alpha-2 form.
    - `id_number` object, nullable — The user's ID number. Used only for Identity Verification. If provided, the user will not be shown fields to enter their ID number in the Identity Verification flow. May be omitted, but if not omitted, all fields marked as required must be provided.
      - `value` string, required — Value of the identity document typed in by the user. Alpha-numeric, with all formatting characters stripped. For specific format requirements by ID type, see [Input Validation Rules](https://plaid.com/docs/identity-verification/hybrid-input-validation/#id-numbers).
      - `type` 'ar_dni' | 'au_drivers_license' | 'au_passport' | 'br_cpf' | 'ca_sin' | 'cl_run' | 'cn_resident_card' | 'co_nit' | 'dk_cpr' | 'eg_national_id' | 'es_dni' | 'es_nie' | 'hk_hkid' | 'in_pan' | 'in_epic' | 'it_cf' | 'jo_civil_id' | 'jp_my_number' | 'ke_huduma_namba' | 'kw_civil_id' | 'mx_curp' | 'mx_rfc' | 'my_nric' | 'ng_nin' | 'nz_drivers_license' | 'om_civil_id' | 'ph_psn' | 'pl_pesel' | 'ro_cnp' | 'sa_national_id' | 'se_pin' | 'sg_nric' | 'tr_tc_kimlik' | 'us_ssn' | 'us_ssn_last_4' | 'za_smart_id', required — A globally unique and human readable ID type, specific to the country and document category. For more context on this field, see [Input Validation Rules](https://plaid.com/docs/identity-verification/hybrid-input-validation/#id-numbers).
  - `user_id` string — A `user_id` generated using `/user/create`. Required for integrations that began using Plaid Protect, Multi-Item Link, or Plaid Check Consumer Report after December 10, 2025. For more details, see [New User APIs](https://plaid.com/docs/api/users/user-apis). One of either the `user_id` or the `user` field is required.
  - `products` Products[], nullable — List of Plaid product(s) that the linked Item must support. If launching Link in update mode, should be omitted (unless you are using update mode to add a credit product, such as Assets, Statements, Income, or Plaid Check Consumer Report, to an existing Item); at least one `product` is required otherwise. To maximize the number of institutions and accounts available, initialize Link with the minimal product set required for your use case, as the products specified will limit which institutions and account types will be available to your users in Link. Only institutions that support *all* requested products can be selected; if a user attempts to select an institution that does not support a listed product, a "Connectivity not supported" error message will appear in Link. For each specified product, the Item connected by the user must contain at least one compatible account. For details on compatible product / account type combinations, see [the account type/product support matrix](https://plaid.com/docs/api/accounts/#account-type--product-support-matrix). To add products without limiting the institution list or account types, use the [`optional_products`](https://plaid.com/docs/api/link/#link-token-create-request-optional-products) or [`required_if_supported_products`](https://plaid.com/docs/api/link/#link-token-create-request-required-if-supported-products) fields. Products can also be added to an Item by calling the product endpoint after obtaining an access token; this may require the product to be listed in the [`additional_consented_products`](https://plaid.com/docs/api/link/#link-token-create-request-additional-consented-products) array. For details, see [Choosing when to initialize products](https://plaid.com/docs/link/initializing-products/). `balance` is *not* a valid value, the Balance product does not require explicit initialization and will automatically be initialized when any other product is initialized. If launching Link with CRA products, `cra_base_report` is required and must be included in the `products` array. Note that, unless you have opted to disable Instant Match support, institutions that support Instant Match will also be shown in Link if `auth` is specified as a product, even though these institutions do not contain `auth` in their product array. In Production, you will be billed for each product that you specify when initializing Link. Note that a product cannot be removed from an Item once the Item has been initialized with that product. To stop billing on an Item for subscription-based products, such as Liabilities, Investments, and Transactions, remove the Item via `/item/remove`.
  - `required_if_supported_products` Products[], nullable — List of Plaid product(s) you wish to use only if the institution and account(s) selected by the user support the product. Institutions that do not support these products will still be shown in Link. The products will only be extracted and billed if the user selects an institution and account type that supports them. There should be no overlap between this array and the `products`, `optional_products`, or `additional_consented_products` arrays. The `products` array must have at least one product. For more details on using this feature, see [Required if Supported Products](https://plaid.com/docs/link/initializing-products/#required-if-supported-products).
  - `optional_products` Products[], nullable — List of Plaid product(s) that will enhance the consumer's use case, but that your app can function without. Plaid will attempt to fetch data for these products on a best-effort basis, and failure to support these products will not affect Item creation. There should be no overlap between this array and the `products`, `required_if_supported_products`, or `additional_consented_products` arrays. The `products` array must have at least one product. For more details on using this feature, see [Optional Products](https://plaid.com/docs/link/initializing-products/#optional-products).
  - `additional_consented_products` Products[], nullable — List of additional Plaid product(s) you wish to collect consent for to support your use case. These products will not be billed until you start using them by calling the relevant endpoints. `balance` is *not* a valid value, the Balance product does not require explicit initialization and will automatically have consent collected. Institutions that do not support these products will still be shown in Link. There should be no overlap between this array and the `products` or `required_if_supported_products` arrays. If you include `signal` in `additional_consented_products`, you will need to call [`/signal/prepare`](https://plaid.com/docs/api/products/signal/#signalprepare) before calling `/signal/evaluate` for the first time on an Item in order to get the most accurate results. For more details, see [`/signal/prepare`](https://plaid.com/docs/api/products/signal/#signalprepare).
  - `webhook` string, url — The destination URL to which any webhooks should be sent. Note that webhooks for Payment Initiation (e-wallet transactions only), Transfer, Bank Transfer (including Auth micro-deposit notification webhooks), Monitor, and Identity Verification are configured via the Dashboard instead. In update mode, this field will not have an effect; to update the webhook receiver endpoint for an existing Item, use `/item/webhook/update` instead.
  - `access_token` string, nullable — The `access_token` associated with the Item to update or reference, used when updating, modifying, or accessing an existing `access_token`. Used when launching Link in update mode, when completing the Same-Day Micro-deposit (manual) flow, or (optionally) when initializing Link for a returning user as part of the Transfer UI flow.
  - `access_tokens` string[] — A list of access tokens associated with the items to update in Link update mode for the Assets product. Using this instead of the `access_token` field allows the updating of multiple items at once. This feature is in closed beta, please contact your account manager for more info.
  - `link_customization_name` string — The name of the Link customization from the Plaid Dashboard to be applied to Link. If not specified, the `default` customization will be used. When using a Link customization, the language in the customization must match the language selected via the `language` parameter, and the countries in the customization should match the country codes selected via `country_codes`.
  - `appearance_mode` 'LIGHT' | 'DARK' | 'SYSTEM' | 'null', nullable — Enum representing the desired appearance mode for Link, used to force light or dark modes or set Link to change depending on user system settings. Currently in closed beta.
  - `redirect_uri` string — A URI indicating the destination where a user should be forwarded after completing the Link flow; used to support OAuth authentication flows when launching Link in the browser or another app. The `redirect_uri` should not contain any query parameters. When used in Production, must be an https URI. Note that any redirect URI must also be added to the Allowed redirect URIs list in the [developer dashboard](https://dashboard.plaid.com/team/api). If initializing on Android, `android_package_name` must be specified instead and `redirect_uri` should be left blank.
  - `android_package_name` string — The name of your app's Android package. Required if using the `link_token` to initialize Link on Android. Any package name specified here must also be added to the Allowed Android package names setting on the [developer dashboard](https://dashboard.plaid.com/team/api). When creating a `link_token` for initializing Link on other platforms, `android_package_name` must be left blank and `redirect_uri` should be used instead.
  - `institution_data` LinkTokenCreateInstitutionData — A map containing data used to highlight institutions in Link.
    - `routing_number` string — The routing number of the bank to highlight in Link. Note: in rare cases, a single routing number can be associated with multiple institutions, e.g. due to a brokerage using another institution to manage ACH on its sweep accounts. If this happens, the bank will not be highlighted in Link even if the routing number is provided.
  - `card_switch` LinkTokenCreateCardSwitch — A map containing data to pass in for the Card Switch flow.
    - `card_bin` string, required — The BIN (Bank Identification Number) of the card to switch.
  - `account_filters` LinkTokenAccountFilters — By default, Link will provide limited account filtering: it will only display Institutions that are compatible with all products supplied in the `products` parameter of `/link/token/create`, and, if `auth` is specified in the `products` array, will also filter out accounts other than `checking`, `savings`, and `cash management` accounts on the Account Select pane. You can further limit the accounts shown in Link by using `account_filters` to specify the account subtypes to be shown in Link. Only the specified subtypes will be shown. This filtering applies to both the Account Select view (if enabled) and the Institution Select view. Institutions that do not support the selected subtypes will be omitted from Link. To indicate that all subtypes should be shown, use the value `"all"`. If the `account_filters` filter is used, any account type for which a filter is not specified will be entirely omitted from Link. For a full list of valid types and subtypes, see the [Account schema](https://plaid.com/docs/api/accounts#account-type-schema). The filter may or may not impact the list of accounts shown by the institution in the OAuth account selection flow, depending on the specific institution. If the user selects excluded account subtypes in the OAuth flow, these accounts will not be added to the Item. If the user selects only excluded account subtypes, the link attempt will fail and the user will be prompted to try again.
    - `depository` DepositoryFilter — A filter to apply to `depository`-type accounts
      - `account_subtypes` DepositoryAccountSubtype[], required — An array of account subtypes to display in Link. If not specified, all account subtypes will be shown. For a full list of valid types and subtypes, see the [Account schema](https://plaid.com/docs/api/accounts#account-type-schema).
      - `limited_purpose_types` LimitedPurposeType[] — An array of limited purpose types. Restricts which kinds of limited purpose checking accounts may be connected in Link to prevent users from connecting them for unsupported use cases. Required when 'limited purpose checking' is in the subtypes filter.
    - `credit` CreditFilter — A filter to apply to `credit`-type accounts
      - `account_subtypes` CreditAccountSubtype[], required — An array of account subtypes to display in Link. If not specified, all account subtypes will be shown. For a full list of valid types and subtypes, see the [Account schema](https://plaid.com/docs/api/accounts#account-type-schema).
    - `loan` LoanFilter — A filter to apply to `loan`-type accounts
      - `account_subtypes` LoanAccountSubtype[], required — An array of account subtypes to display in Link. If not specified, all account subtypes will be shown. For a full list of valid types and subtypes, see the [Account schema](https://plaid.com/docs/api/accounts#account-type-schema).
    - `investment` InvestmentFilter — A filter to apply to `investment`-type accounts (or `brokerage`-type accounts for API versions 2018-05-22 and earlier).
      - `account_subtypes` InvestmentAccountSubtype[], required — An array of account subtypes to display in Link. If not specified, all account subtypes will be shown. For a full list of valid types and subtypes, see the [Account schema](https://plaid.com/docs/api/accounts#account-type-schema).
    - `other` OtherFilter — A filter to apply to `other`-type accounts
      - `account_subtypes` OtherAccountSubtype[], required — An array of account subtypes to display in Link. If not specified, all account subtypes will be shown. For a full list of valid types and subtypes, see the [Account schema](https://plaid.com/docs/api/accounts#account-type-schema).
  - `eu_config` LinkTokenEUConfig — Configuration parameters for EU flows
    - `headless` boolean — If `true`, open Link without an initial UI. Defaults to `false`.
  - `institution_id` string — Used for certain legacy use cases
  - `payment_configuration` LinkTokenCreateRequestPaymentConfiguration — Specifies options for initializing Link for use with the Pay By Bank flow. This is an optional field to configure the user experience, and currently requires the amount field to be set.
    - `amount` string, required — The amount of the transfer (decimal string with two digits of precision e.g. "10.00").
    - `description` string — The description of the transfer that provides the payment context. The max length is 256.
  - `payment_initiation` LinkTokenCreateRequestPaymentInitiation — Specifies options for initializing Link for use with the Payment Initiation (Europe) product. This field is required if `payment_initiation` is included in the `products` array. Either `payment_id` or `consent_id` must be provided.
    - `payment_id` string — The `payment_id` provided by the `/payment_initiation/payment/create` endpoint.
    - `consent_id` string — The `consent_id` provided by the `/payment_initiation/consent/create` endpoint.
  - `employment` LinkTokenCreateRequestEmployment — Specifies options for initializing Link for use with the Employment product. This field is required if `employment` is included in the `products` array.
    - `employment_source_types` EmploymentSourceType[] — The types of source employment data that users will be permitted to share. Options include `bank` and `payroll`. Currently you can only specify one of these options.
    - `bank_employment` LinkTokenCreateRequestEmploymentBankIncome — Specifies options for initializing Link for use with Bank Employment. This field is required if `employment` is included in the `products` array and `bank` is specified in `employment_source_types`.
      - `days_requested` integer, required — The number of days of data to request for the Bank Employment product.
  - `income_verification` LinkTokenCreateRequestIncomeVerification — Specifies options for initializing Link for use with the Income product. This field is required if `income_verification` is included in the `products` array.
    - `income_verification_id` string — The `income_verification_id` of the verification instance, as provided by `/income/verification/create`. Replaced by the user token.
    - `asset_report_id` string — The `asset_report_id` of an asset report associated with the user, as provided by `/asset_report/create`. Providing an `asset_report_id` is optional and can be used to verify the user through a streamlined flow. If provided, the bank linking flow will be skipped.
    - `access_tokens` AccessToken[], nullable — An array of access tokens corresponding to Items that a user has previously connected with. Data from these institutions will be cross-referenced with document data received during the Document Income flow to help verify that the uploaded documents are accurate. If the `transactions` product was not initialized for these Items during Link, it will be initialized after this Link session. This field should only be used with the `payroll` income source type.
    - `income_source_types` IncomeVerificationSourceType[] — The types of source income data that users will be permitted to share. Options include `bank` and `payroll`. Currently you can only specify one of these options.
    - `bank_income` LinkTokenCreateRequestIncomeVerificationBankIncome — Specifies options for initializing Link for use with Bank Income. This field is required if `income_verification` is included in the `products` array and `bank` is specified in `income_source_types`.
      - `days_requested` integer, required — The number of days of data to request for the Bank Income product
      - `enable_multiple_items` boolean, nullable — Whether to enable multiple Items to be added in the Link session. This setting is deprecated and has been replaced by the more general `enable_multi_item_link` setting, which supports all products.
    - `payroll_income` LinkTokenCreateRequestIncomeVerificationPayrollIncome — Specifies options for initializing Link for use with Payroll Income (including Document Income). Further customization options for Document Income, such as customizing which document types may be uploaded, are also available via the [Link Customization pane](https://dashboard.plaid.com/link) in the Dashboard. (Requires Production enablement.)
      - `flow_types` IncomeVerificationPayrollFlowType[], nullable — The types of payroll income verification to enable for the Link session. If none are specified, then users will see both document and digital payroll income.
      - `is_update_mode` boolean — An identifier to indicate whether the income verification Link token will be used for update mode. This field is only relevant for participants in the Payroll Income Refresh beta.
      - `item_id_to_update` string, nullable — Uniquely identify a payroll income Item to update with. This field is only relevant for participants in the Payroll Income Refresh beta.
      - `parsing_config` IncomeVerificationDocParsingConfig[], nullable — The types of analysis to enable for document uploads. If this field is not provided, then docs will undergo OCR parsing only.
    - `stated_income_sources` LinkTokenCreateRequestUserStatedIncomeSource[] — A list of user stated income sources
      - `employer` string — The employer corresponding to an income source specified by the user
      - `category` 'OTHER' | 'SALARY' | 'UNEMPLOYMENT' | 'CASH' | 'GIG_ECONOMY' | 'RENTAL' | 'CHILD_SUPPORT' | 'MILITARY' | 'RETIREMENT' | 'LONG_TERM_DISABILITY' | 'BANK_INTEREST' — The income category for a specified income source
      - `pay_per_cycle` number, double — The income amount paid per cycle for a specified income source
      - `pay_annual` number, double — The income amount paid annually for a specified income source
      - `pay_type` 'UNKNOWN' | 'GROSS' | 'NET' — The pay type - `GROSS`, `NET`, or `UNKNOWN` for a specified income source
      - `pay_frequency` 'UNKNOWN' | 'WEEKLY' | 'BIWEEKLY' | 'SEMI_MONTHLY' | 'MONTHLY' — The pay frequency of a specified income source
  - `base_report` LinkTokenCreateRequestBaseReport — Specifies options for initializing Link for use with the Base Report product. This field is required if `assets` is included in the `products` array and the client is CRA-enabled.
    - `days_requested` integer, required — The maximum integer number of days of history to include in the Base Report.
    - `client_report_id` string, nullable — Client-generated identifier, which can be used by lenders to track loan applications.
  - `credit_partner_insights` LinkTokenCreateRequestCreditPartnerInsights — Specifies options for initializing Link for use with the Credit Partner Insights product.
    - `days_requested` integer — The maximum integer number of days of history to compute Credit Partner Insights. Defaults to 180 if not specified
  - `cra_options` LinkTokenCreateRequestCraOptions — Specifies options for initializing Link for use with Plaid Check products
    - `days_requested` integer, required — The number of days of history to include in Plaid Check products. Maximum is 731; minimum is 180. If a value lower than 180 is provided, a minimum of 180 days of history will be requested.
    - `days_required` integer — The minimum number of days of data required for the report to be successfully generated.
    - `client_report_id` string, nullable — Client-generated identifier, which can be used by lenders to track loan applications.
    - `partner_insights` LinkTokenCreateRequestCraOptionsPartnerInsights — Specifies options for initializing Link for use with the Credit Partner Insights product.
      - `prism_versions` PrismVersions, nullable — The versions of Prism products to evaluate
        - `firstdetect` '3' | 'null', nullable — The version of Prism FirstDetect. If not specified, will default to v3.
        - `detect` '4.1' | '4' | 'null', nullable — The version of Prism Detect
        - `cashscore` '4.1' | '4' | '3_lite' | '3' | 'null', nullable — The version of Prism CashScore. If not specified, will default to v3.
        - `extend` '4.1' | '4' | 'null', nullable — The version of Prism Extend
        - `insights` '4.1' | '4' | '3' | 'null', nullable — The version of Prism Insights. If not specified, will default to v3.
      - `fico` CraPartnerInsightsFicoInput, nullable — Configuration for the FICO products used in the Partner Insights product.
        - `fico_lender_id` string, required — ID provided by FICO that uniquely identifies the lender. Required for UltraFICO® score generation. Sometimes referred to as Lender Org ID.
        - `lender_application_id` string, required — Client-generated identifier that uniquely identifies the FICO Application across FICO systems.
        - `ultrafico_score_requests` CraPartnerInsightsUltraFicoScoreRequest[], required — A list of UltraFICO® scoring requests. Each request contains all configuration required to generate an UltraFICO score.
          - `ultrafico_score_version` '1.0', required — The version of the UltraFICO® score.
          - `fico_scoring_request_id` string — FICO identifier for a particular scoring request. Should only be provided by FICO as part of the FICO-led flow.
          - `request_correlation_id` string — Client-generated identifier that can be used to correlate scoring requests with their scoring results.
          - `base_fico_score` CraPartnerInsightsBaseFicoScore, required — Details about the base FICO score associated with an UltraFICO® scoring request.
            - `bureau` 'EQUIFAX' | 'EXPERIAN' | 'TRANSUNION', required — The credit bureau that provided the base FICO score.
            - `score` integer, required — Numeric value of the base FICO score.
            - `reason_codes` string[] — Reason codes associated with the score, in priority order. May contain up to 4 items.
            - `reason_code_1` string, nullable — Deprecated. Use `reason_codes` instead. The first reason code associated with the score.
            - `reason_code_2` string, nullable — Deprecated. Use `reason_codes` instead. The second reason code associated with the score.
            - `reason_code_3` string, nullable — Deprecated. Use `reason_codes` instead. The third reason code associated with the score.
            - `reason_code_4` string, nullable — Deprecated. Use `reason_codes` instead. The fourth reason code associated with the score.
            - `did_inquiries_adversely_affect_score` boolean, nullable — Whether inquiries adversely affected the score but were not represented in one of the four reason codes. Sometimes referred to as the FACTA Flag.
            - `base_fico_score_version` '8' | '9' | '10' | '10T', required — The version of the base FICO score model.
    - `base_report` LinkTokenCreateRequestCraOptionsBaseReport — Specifies options for initializing Link for use with the Base Report product, specifically the `client_report_id`.
      - `client_report_id` string, nullable — Client-generated identifier, which can be used by lenders to track loan applications.
      - `gse_options` LinkTokenCreateRequestCraOptionsBaseReportGSEOptions, nullable — Specifies options for initializing Link to create reports that can be shared with GSEs for mortgage verification.
        - `report_types` GSEReportType[], required — Specifies which types of reports should be made available to GSEs.
      - `require_identity` boolean, nullable — Indicates that the report must include identity information. If identity information is not available, the report will fail.
      - `home_lending_report_options` CraCheckReportHomeLendingReportOptions, nullable — Options for configuring Home Lending Report (Verification Report) generation.
        - `reports_requested` CraCheckReportVerificationGetReportType[], required — Specifies which types of home lending reports to generate.
        - `employment_refresh_options` CraCheckReportCreateEmploymentRefreshOptions, nullable — Defines configuration options for the Employment Refresh Report.
          - `days_requested` integer, required — The number of days of data to request for the report. This field is required if an Employment Refresh Report is requested. Maximum is 731.
    - `cashflow_insights` LinkTokenCreateRequestCraOptionsCashflowInsights — Specifies options for initializing Link for use with the Cashflow Insights product.
      - `attributes_version` 'v1.0' | 'v2.0' | 'CFI1', nullable — The version of cashflow attributes. Required if using Cash Flow Insights.
    - `lend_score` LinkTokenCreateRequestCraOptionsLendScore — Specifies options for initializing Link for use with the CRA LendScore product.
      - `lend_score_version` 'v1.0' | 'v2.0' | 'LS1', nullable — The version of the LendScore to use. Required if using LendScore.
    - `network_insights` LinkTokenCreateRequestCraOptionsNetworkInsights — Specifies options for initializing Link for use with the CRA Network Insights product.
      - `network_insights_version` 'NI1', nullable — The version of Network Insights. Required if using Network Insights.
    - `include_investments` boolean, nullable — Indicates that investment data should be extracted from the linked account(s).
    - `income_insights` LinkTokenCreateRequestCraOptionsIncomeInsights — Specifies options for initializing Link for use with the CRA Income Insights product.
      - `income_insights_filter` IncomeInsightsFilter, nullable — Filters the returned income streams based on the specified income categories. If no filters are requested, streams from the following default set of categories are returned: - `EARNED_INCOME.*` (`EARNED_INCOME.SALARY`, `EARNED_INCOME.GIG_ECONOMY`, `EARNED_INCOME.SELF_EMPLOYED`) - `BENEFITS.DISABILITY` - `RETIREMENT.*` (`RETIREMENT.GOVERNMENT_DERIVED`, `RETIREMENT.PRIVATE_RETIREMENT`, `RETIREMENT.PLAN_DISTRIBUTION`) The final list of income categories is generated by adding the `included_categories`, then removing the `excluded_categories`. Priority is given to `excluded_categories` in the case of collisions. Filter patterns supported: - `*`: All categories - `PRIMARY.*`: All categories within the specified primary category - `PRIMARY.SECONDARY`: A specific income category For a list of income categories, see the [Income V2 Category Taxonomy](https://plaid.com/documents/income-v2-category-taxonomy.csv).
        - `included_categories` string[], required — Includes income streams matching the specified categories.
        - `excluded_categories` string[] — Excludes income streams matching the specified categories.
      - `income_insights_version` 'II2', nullable, required — The version of Income Insights to use. This value is not shared across API calls for the same resource. If it is omitted from a request, the default version is used, even if a version was set in an earlier call such as `/link/token/create` or `/cra/check_report/create`.
  - `consumer_report_permissible_purpose` 'ACCOUNT_REVIEW_CREDIT' | 'ACCOUNT_REVIEW_NON_CREDIT' | 'EXTENSION_OF_CREDIT' | 'LEGITIMATE_BUSINESS_NEED_TENANT_SCREENING' | 'LEGITIMATE_BUSINESS_NEED_OTHER' | 'WRITTEN_INSTRUCTION_PREQUALIFICATION' | 'WRITTEN_INSTRUCTION_OTHER' | 'ELIGIBILITY_FOR_GOVT_BENEFITS' — Describes the reason you are generating a Consumer Report for this user. When calling `/link/token/create`, this field is required when using Plaid Check (CRA) products; invalid if not using Plaid Check (CRA) products. `ACCOUNT_REVIEW_CREDIT`: In connection with a consumer credit transaction for the review or collection of an account pursuant to FCRA Section 604(a)(3)(A). `ACCOUNT_REVIEW_NON_CREDIT`: For a legitimate business need of the information to review a non-credit account provided primarily for personal, family, or household purposes to determine whether the consumer continues to meet the terms of the account pursuant to FCRA Section 604(a)(3)(F)(2). `EXTENSION_OF_CREDIT`: In connection with a credit transaction initiated by and involving the consumer pursuant to FCRA Section 604(a)(3)(A). `LEGITIMATE_BUSINESS_NEED_TENANT_SCREENING`: For a legitimate business need in connection with a business transaction initiated by the consumer primarily for personal, family, or household purposes in connection with a property rental assessment pursuant to FCRA Section 604(a)(3)(F)(i). `LEGITIMATE_BUSINESS_NEED_OTHER`: For a legitimate business need in connection with a business transaction made primarily for personal, family, or household initiated by the consumer pursuant to FCRA Section 604(a)(3)(F)(i). `WRITTEN_INSTRUCTION_PREQUALIFICATION`: In accordance with the written instructions of the consumer pursuant to FCRA Section 604(a)(2), to evaluate an application's profile to make an offer to the consumer. `WRITTEN_INSTRUCTION_OTHER`: In accordance with the written instructions of the consumer pursuant to FCRA Section 604(a)(2), such as when an individual agrees to act as a guarantor or assumes personal liability for a consumer, business, or commercial loan. `ELIGIBILITY_FOR_GOVT_BENEFITS`: In connection with an eligibility determination for a government benefit where the entity is required to consider an applicant's financial status pursuant to FCRA Section 604(a)(3)(D).
  - `auth` LinkTokenCreateRequestAuth — Specifies options for initializing Link for use with the Auth product. This field can be used to enable or disable extended Auth flows for the resulting Link session. Omitting any field will result in a default that can be configured by your account manager. The default behavior described in the documentation is the default behavior that will apply if you have not requested your account manager to apply a different default. If you have enabled the [Dashboard Account Verification pane](https://dashboard.plaid.com/account-verification), the settings enabled there will override any settings in this object.
    - `auth_type_select_enabled` boolean — Specifies whether Auth Type Select is enabled for the Link session, allowing the end user to choose between linking via a credentials-based flow (i.e. Instant Auth, Instant Match, Automated Micro-deposits) or a manual flow that does not require login (all other Auth flows) prior to selecting their financial institution. Default behavior is `false`.
    - `automated_microdeposits_enabled` boolean — Specifies whether the Link session is enabled for the Automated Micro-deposits flow. Default behavior is `false`.
    - `instant_match_enabled` boolean — Specifies whether the Link session is enabled for the Instant Match flow. Instant Match is enabled by default. Instant Match can be disabled by setting this field to `false`.
    - `same_day_microdeposits_enabled` boolean — Specifies whether the Link session is enabled for the Same-Day Micro-deposits flow. Default behavior is `false`.
    - `instant_microdeposits_enabled` boolean — Specifies whether the Link session is enabled for the Instant Micro-deposits flow. Default behavior for Plaid teams created after November 2023 is `false`; default behavior for Plaid teams created before that date is `true`.
    - `reroute_to_credentials` 'OFF' | 'OPTIONAL' | 'FORCED' — Specifies what type of [Reroute to Credentials](https://plaid.com/docs/auth/coverage/flow-options/#removing-manual-verification-entry-points-with-reroute-to-credentials) pane should be used in the Link session for the Same-Day Micro-deposits flow. Default behavior is `OPTIONAL`.
    - `database_match_enabled` boolean — Database Match has been deprecated and replaced with Database Auth. Use the [Account Verification Dashboard](https://dashboard.plaid.com/account-verification) to enable Database Auth.
    - `database_insights_enabled` boolean — Database Insights has been deprecated and replaced with Database Auth. Use the [Account Verification Dashboard](https://dashboard.plaid.com/account-verification) to enable Database Auth. In Canada, Database Auth is in early availability and cannot yet be managed via the Dashboard; it must be enabled by passing `database_insights_enabled: true` in `/link/token/create`.
    - `flow_type` 'FLEXIBLE_AUTH' — This field has been deprecated in favor of `auth_type_select_enabled`.
    - `sms_microdeposits_verification_enabled` boolean — Specifies whether the Link session is enabled for SMS micro-deposits verification. Default behavior is `true`.
  - `transfer` LinkTokenCreateRequestTransfer — Specifies options for initializing Link for use with the Transfer product.
    - `intent_id` string — The `id` returned by the `/transfer/intent/create` endpoint.
    - `authorization_id` string — The `id` returned by the `/transfer/authorization/create` endpoint. Used to indicate Link session to complete required user action in order to make a decision for the authorization. If set, `access_token` can be omitted.
    - `payment_profile_token` string — The `payment_profile_token` returned by the `/payment_profile/create` endpoint.
  - `update` LinkTokenCreateRequestUpdate — Specifies options for initializing Link for [update mode](https://plaid.com/docs/link/update-mode).
    - `account_selection_enabled` boolean — If `true`, enables [update mode with Account Select](https://plaid.com/docs/link/update-mode/#using-update-mode-to-request-new-accounts) for institutions in the US and Canada that do not use OAuth, or that use OAuth but do not have their own account selection flow. For institutions in the US that have an OAuth account selection flow (i.e. most OAuth-enabled institutions), update mode with Account Select will always be enabled, regardless of the value of this field.
    - `reauthorization_enabled` boolean — Note: this field is not currently used. Plaid may enable this field in the future if 1033-related expiration begins to be enforced. By default, Plaid will enable the reauthorization flow during update mode for an Item enabled for [Data Transparency Messaging](https://plaid.com/docs/link/data-transparency-messaging-migration-guide/) if the Item expires within six months. During a reauthorization flow, an end user will review Plaid's end user privacy policy, use case and data scope consents, and account access consents; they may also be required to log in to their financial institution's OAuth flow. After the end user successfully completes the reauthorization flow, the Item's expiration date will be extended to 12 months from the time that the reauthorization took place. This field allows you to optionally override the default reauthorization scheduling logic to either forcibly enable or disable the reauthorization flow for a given update mode session. This field does not impact the flow for Items at institutions in the EU or UK.
    - `user` boolean — If `true`, a `user_token` or `user_id` must also be provided, and Link will open in update mode for the given user.
    - `item_ids` ItemId[], nullable — An array of `item_id`s associated with the user to be updated in update mode. If empty or `null`, this field will default to initializing update mode for the most recent unhealthy Item associated with the user. A `user_token` must also be provided to use this field.
  - `identity_verification` LinkTokenCreateRequestIdentityVerification — Specifies option for initializing Link for use with the Identity Verification product.
    - `template_id` string, required — ID of the associated Identity Verification template. Like all Plaid identifiers, this is case-sensitive.
    - `consent` boolean — A flag specifying whether the end user has already agreed to a privacy policy specifying that their data will be shared with Plaid for verification purposes. If `gave_consent` is set to `true`, the `accept_tos` step will be marked as `skipped` and the end user's session will start at the next step requirement.
    - `gave_consent` boolean — A flag specifying whether the end user has already agreed to a privacy policy specifying that their data will be shared with Plaid for verification purposes. If `gave_consent` is set to `true`, the `accept_tos` step will be marked as `skipped` and the end user's session will start at the next step requirement.
  - `statements` LinkTokenCreateRequestStatements — Specifies options for initializing Link for use with the Statements product. This field is required for the statements product.
    - `start_date` string, date, required — The start date for statements, in [ISO 8601](https://wikipedia.org/wiki/ISO_8601) "YYYY-MM-DD" format, e.g. "2020-10-30".
    - `end_date` string, date, required — The end date for statements, in [ISO 8601](https://wikipedia.org/wiki/ISO_8601) "YYYY-MM-DD" format, e.g. "2020-10-30". You can request up to two years of data.
  - `third_party_user_token` string — A third party user token associated with the current user.
  - `investments` LinkTokenInvestments — Configuration parameters for the Investments product
    - `allow_unverified_crypto_wallets` boolean — If `true`, allow self-custody crypto wallets to be added without requiring signature verification. Defaults to `false`.
    - `allow_manual_entry` boolean — If `true`, allow users to manually enter Investments account and holdings information. Defaults to `false`.
  - `investments_auth` LinkTokenInvestmentsAuth — Configuration parameters for the Investments Move product
    - `manual_entry_enabled` boolean, nullable — If `true`, show institutions that use the manual entry fallback flow.
    - `masked_number_match_enabled` boolean, nullable — If `true`, show institutions that use the masked number match fallback flow.
    - `stated_account_number_enabled` boolean, nullable — If `true`, show institutions that use the stated account number fallback flow.
    - `rollover_401k_enabled` boolean, nullable — If `true`, the fee and contribution details for 401k accounts will be returned.
  - `hosted_link` LinkTokenCreateHostedLink — Configuration parameters for Hosted Link. To enable the session for Hosted Link, send this object in the request. It can be empty.
    - `delivery_method` 'sms' | 'email' — How Plaid should deliver the Plaid Link session to the customer. Only available to customers enabled for Link Delivery (beta). To request Link Delivery access, contact your account manager. 'sms' will deliver via SMS. Must pass `user.phone_number`. 'email' will deliver via email. Must pass `user.email_address`. In the Sandbox environment, this field will be ignored; use the Production environment to test Link Delivery instead.
    - `completion_redirect_uri` string — URI that Hosted Link will redirect to upon completion of the Link flow. This will only occur in Hosted Link sessions, not in other implementation methods.
    - `url_lifetime_seconds` integer — How many seconds the link will be valid for. Must be positive. Cannot be longer than 21 days. The default lifetime is 7 days for links delivered by email, 1 day for links delivered via SMS, and 30 minutes for links not sent via Plaid Link delivery. This parameter will override the value of all three link types.
    - `is_mobile_app` boolean — This indicates whether the client is opening Hosted Link in a mobile app in an `AsWebAuthenticationSession` or Chrome custom tab.
  - `transactions` LinkTokenTransactions — Configuration parameters for the Transactions product
    - `days_requested` integer — The maximum number of days of transaction history to request for the Transactions product. The more transaction history is requested, the longer the historical update poll will take. The default value is 90 days. In Production, if a value under 30 is provided, a minimum of 30 days of history will be requested. Once Transactions has been added to an Item, this value cannot be updated. Customers using [Recurring Transactions](https://plaid.com/docs/api/products/transactions/#transactionsrecurringget) should request at least 180 days of history for optimal results.
  - `cashflow_report` LinkTokenCashflowReport — Configuration parameters for the Cashflow Report product. Currently in closed beta.
    - `days_requested` integer — Number of days of transaction history to request in the Cashflow Report product.
  - `cra_enabled` boolean — If `true`, request a CRA connection. Defaults to `false`.
  - `identity` LinkTokenCreateIdentity — Identity object used to specify document upload
    - `is_document_upload` boolean — Used to specify whether the Link session is Identity Document Upload
    - `account_ids` string[] — An array of `account_ids`. Currently can only contain one `account_id`. Must be populated if using Document Upload.
    - `parsing_configs` IncomeVerificationDocParsingConfig[] — An array of parsing configurations. Valid parsing configurations are `ocr` and `risk_signals`. If parsing configurations are omitted, defaults to `ocr`
  - `financekit_supported` boolean — If `true`, indicates that client supports linking FinanceKit / AppleCard items. Defaults to `false`.
  - `enable_multi_item_link` boolean — If `true`, enable linking multiple items in the same Link session. Defaults to `false`.
  - `user_token` string — A user token generated using `/user/create`. Any Item created during the Link session will be associated with the user. Integrations that began using Plaid Protect, Multi-Item Link, or Plaid Check Consumer Report before December 10, 2025 use this field instead of the `user_id`.

## Response `200`

OK

- LinkTokenCreateResponse — LinkTokenCreateResponse defines the response schema for `/link/token/create`
  - `link_token` string, required — A `link_token`, which can be supplied to Link in order to initialize it and receive a `public_token`, which can be exchanged for an `access_token`.
  - `expiration` string, date-time, required — The expiration date and time for the `link_token`, in [ISO 8601](https://wikipedia.org/wiki/ISO_8601) format. By default, a `link_token` created to generate a `public_token` that will be exchanged for a new `access_token` expires after 4 hours, and a `link_token` created for an existing Item (such as when updating an existing `access_token` by launching Link in update mode) expires after 30 minutes. If using [Hosted Link](https://plaid.com/docs/link/hosted-link/), the `link_token` will expire at the same time as the Hosted Link URL, and you can customize the duration using the `hosted_link.url_lifetime_seconds` option in the request. If using Link Delivery (beta), the `link_token` will expire by default after 24 hours if sent via SMS and after 7 days if sent via email. If using Identity Verification, Link token expiration will not be enforced; an Identity Verification Link session can be created with an expired Link token.
  - `request_id` string, required — A unique identifier for the request, which can be used for troubleshooting. This identifier, like all Plaid identifiers, is case sensitive.
  - `hosted_link_url` string — A URL of a Plaid-hosted Link flow that will use the Link token returned by this request. Only present if the session is enabled for Hosted Link. To enable the session for Hosted Link, send a `hosted_link` object in the request.
  - `user_id` string — A unique user identifier, created by `/user/create`. Integrations that began using `/user/create` after December 10, 2025 use this field to identify a user instead of the `user_token`. For more details, see [New User APIs](https://plaid.com/docs/api/users/user-apis).

## Other responses

- `default` — Error response

---

[API](https://skmtc.net/plaid/apis/the-plaid-api.md) · [All operations](https://skmtc.net/plaid/apis/the-plaid-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/plaid/the-plaid-api/versions/64c4514ea59b/schema)
