Skip to main content
POST
Exchange a handoff code for a session

Authorizations

x-app-id
string
header
required

App identifier (App.id, sent as the x-app-id header)

Body

application/json
code
string
required

One-time code minted by POST /auth/handoff

Example:

"k7F3n2pQ8wZmR1yT9bLxC0aVjHsUdEoI3mNcG5rXfB6hYvW"

Response

200 - application/json
token
string
required

JWT authentication token

Example:

"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."

user
object
required

Authenticated user information

refresh_token
string
required

Refresh token for obtaining new access tokens

Example:

"ref_0123456789abcdef"

expires_at
string
required

Token expiration timestamp (ISO)

Example:

"2025-01-01T01:00:00.000Z"