# Create an app install

Creates an app install. An account installs its own private app with its own key; public and testing installs are made from the Dashboard. An app developer acting on a connected account through `Stripe-Account` installs or reinstalls its app there, and an embedding platform can do the same once the app’s developer approves its request to embed the app. For a private app, creating an install installs the newest completed upload; when that version is already installed with nothing pending, the existing install is returned.

## Request

```curl
curl https://api.stripe.com/v1/apps/installs \
  -u "<<YOUR_SECRET_KEY>>" \
  -H "Stripe-Account: {{CONNECTED_ACCOUNT_ID}}" \
  -d app=app_61VGZkQ7mRbN3xPa41LUZiLcTVChQ9Ye \
  -d channel=public
```

### Response

```json
{
  "id": "appinst_test_61VGZmT4pXc8Rk2w41LUZiLcTVChK7Ab",
  "object": "apps.install",
  "account": "acct_1LQeGxLUZiLcTVCh",
  "app": "app_61VGZkQ7mRbN3xPa41LUZiLcTVChQ9Ye",
  "approval_required": false,
  "auth_code": null,
  "channel": "public",
  "content_security_policy_granted": {
    "connect_src": [
      "https://api.example.com/"
    ],
    "image_src": [
      "https://cdn.example.com/"
    ]
  },
  "content_security_policy_pending": {
    "connect_src": [],
    "image_src": []
  },
  "created": 1725000000,
  "created_by": null,
  "endpoints_granted": [
    "https://example.com/stripe/webhook"
  ],
  "endpoints_pending": [],
  "livemode": false,
  "permissions_granted": [
    "customer_read",
    "event_read"
  ],
  "permissions_pending": [],
  "status": "installing"
}
```

## Parameters

- `app` (string, required)
  The ID of the app to install.

- `channel` (enum, optional)
  The distribution channel to install from. Defaults to `public`, which only app developers and embedding platforms can use. An account installing its own private app must pass `private_test` or `private_live`, matching the mode of the API key.
Possible enum values:
  - `private_live`
    A private app installed in live mode.

  - `private_test`
    A private app installed in test mode.

  - `public`
    The published version of the app.

  - `testing`
    A pre-release version of the app installed for external testing.

- `code_challenge` (string, optional)
  For OAuth apps, the PKCE code challenge used to issue the `auth_code` returned on the install. Must be 43 to 128 characters and contain only letters, numbers, `-`, `.`, `_`, and `~`. Only applies to installs made by the app developer or an embedding platform; ignored when an account installs its own private app.

- `code_challenge_method` (string, optional)
  The method used to derive `code_challenge`. Required when `code_challenge` is provided, and must be `S256`.

## Returns

Returns the app install
