# Create a secure agreement and KYC embed session (/reference/post-residency-applications-id-embed-sessions)

Requires `partner:person.embed_session.create`. The application must be partner-owned, complete except for agreement/KYC, and paid. The one-time URL is bound to the parent-held PKCE verifier and may only be framed by the selected allow-listed origin. Issuance is not idempotent: retrying this operation creates a replacement link and revokes any previously active embed session for the application.

Full request/response schemas for this operation: https://docs.eprospera.com/openapi.yaml

Requires `partner:person.embed_session.create`. The application must be partner-owned, complete except for agreement/KYC, and paid. The one-time URL is bound to the parent-held PKCE verifier and may only be framed by the selected allow-listed origin. Issuance is not idempotent: retrying this operation creates a replacement link and revokes any previously active embed session for the application.