Skip to content
GuidesAPI v1admin-sdk 1.1.52Search docs⌘K
Build an app · Embedded apps
Guides / Build an app

Embedded apps

An embedded app runs inside the merchant's Inkress dashboard, with the merchant's identity and Inkress's own buttons and dialogs.

App Bridge

@inkress/app-bridge runs in your page inside the dashboard. It tells you which merchant is looking and gives you a short-lived session token instead of a stored OAuth token in the browser.

From session token to access token

Your server swaps the session token for a normal access token at /api/v1/hooks/oauth/token with grant_type=urn:ietf:params:oauth:grant-type:token-exchange, your client ID and secret, the session token as subject_token and subject_token_type=urn:ietf:params:oauth:token-type:jwt. Then call the API as that merchant.

App Kit for React Router

@inkress/app-kit does this for React Router 7 apps: the session, OAuth, an authenticated SDK in loaders, and webhooks.

Turning embedding on for an approved app sends it back to review, because it adds screens to the merchant's dashboard. Standalone apps on your own site use the same OAuth flow and tokens.
Was this page helpful?Updated Oct 8, 2026