Create new session
Create a new Session
POST
/appid-{appId}/{tenantId}/recipe/sessionAuthorization
api-keyAPI key · headerrequiredThe core service API token. If you are using a self-hosted core service and you have not generated a token, you can omit the header.
Path parameters
tenantIdstringThe tenant against which the request is made. If left empty, the default tenant will be used.
Header parameters
ridstringcdi-versionstringX.Y of the X.Y.Z CDI version.
Request body
application/jsonuserIduserIduserDataInJWTuserDataInJWTshould be a JSON object (not a JSON literal nor an array)
userDataInDatabaseuserDataInDatabaseshould be a JSON object (not a JSON literal nor an array)
enableAntiCsrfenableAntiCsrfuseDynamicSigningKeybooleanDecides if the token should be signed with a dynamic or static key, defaults to true
Responses
200Create a new Session
statusstatusOKAllowed:
OKsessionsessionShow propertiesHide properties
handlehandleuserIduserIduserDataInJWTuserDataInJWTshould be a JSON object (not a JSON literal nor an array)
tenantIdtenantIdrecipeUserIduserIdaccessTokencookieInfoShow propertiesHide properties
tokentokenexpiryexpirycreatedTimetimeCreatedrefreshTokencookieInfoShow propertiesHide properties
tokentokenexpiryexpirycreatedTimetimeCreatedantiCsrfTokentoken400error code 400
string401error code 401
string404error code 404
string500error code 500
stringTry it
Server
Authorization
Parameters
Bodyapplication/json
Request
curl -X POST "/appid-{appId}/public/recipe/session" \
-H "api-key: YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"userId": "fa7a0841-b533-4478-95533-0fde890c3483",
"userDataInJWT": {
"test": 123
},
"userDataInDatabase": {
"test": 123
},
"enableAntiCsrf": false,
"useDynamicSigningKey": false
}'const response = await fetch("/appid-{appId}/public/recipe/session", {
method: "POST",
headers: {
"api-key": "YOUR_API_KEY",
"Content-Type": "application/json"
},
body: JSON.stringify({
"userId": "fa7a0841-b533-4478-95533-0fde890c3483",
"userDataInJWT": {
"test": 123
},
"userDataInDatabase": {
"test": 123
},
"enableAntiCsrf": false,
"useDynamicSigningKey": false
})
});import requests
response = requests.post(
"/appid-{appId}/public/recipe/session",
headers={
"api-key": "YOUR_API_KEY",
"Content-Type": "application/json"
},
json={
"userId": "fa7a0841-b533-4478-95533-0fde890c3483",
"userDataInJWT": {
"test": 123
},
"userDataInDatabase": {
"test": 123
},
"enableAntiCsrf": False,
"useDynamicSigningKey": False
},
)Response
{
"status": "OK",
"session": {
"handle": "68en6gd6-865b-4af6-ba00-96e5c153257d",
"userId": "fa7a0841-b533-4478-95533-0fde890c3483",
"userDataInJWT": {
"test": 123
},
"tenantId": "customer1",
"recipeUserId": "fa7a0841-b533-4478-95533-0fde890c3483"
},
"accessToken": {
"token": "ZTRiOTBjNz...jI5MTZlODkxw",
"expiry": 1637262633029,
"createdTime": 1637262633029
},
"refreshToken": {
"token": "ZTRiOTBjNz...jI5MTZlODkxw",
"expiry": 1637262633029,
"createdTime": 1637262633029
},
"antiCsrfToken": "ZTRiOTBjNz...jI5MTZlODkxw"
}"string""Invalid API key""Not Found""Internal Error"