> ## Documentation Index
> Fetch the complete documentation index at: https://docs.kerne.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Exchange a handoff code for a session

> Single use: the code is deleted from Redis atomically on the first successful exchange.



## OpenAPI

````yaml /openapi.json post /v1/auth/handoff/exchange
openapi: 3.0.0
info:
  title: Kerne API
  description: >-
    Kerne SaaS Foundation as a Service - authentication, authorization, and
    billing management. Errors follow standardized error codes (K1xxx-K9xxx)
    documented at https://docs.kerne.io/errors
  version: 1.0.0
  contact:
    name: Kerne Team
    url: https://kerne.io
    email: support@kerne.io
  license:
    name: Proprietary
    url: https://kerne.io/license
servers:
  - url: https://api.kerne.io
    description: Production Server
security: []
tags:
  - name: Auth
    description: Authentication endpoints
  - name: Waitlist
    description: Waitlist management
  - name: Invitations
    description: Invitation system
  - name: Billing
    description: 'The tenant''s end users: subscription, entitlements, usage, checkout'
  - name: Pricing
    description: Public pricing page data
paths:
  /v1/auth/handoff/exchange:
    post:
      tags:
        - Auth
      summary: Exchange a handoff code for a session
      description: >-
        Single use: the code is deleted from Redis atomically on the first
        successful exchange.
      operationId: AuthController_exchangeHandoff
      parameters: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/HandoffExchangeDto'
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AuthResponseDto'
      security:
        - AppIdentifier: []
components:
  schemas:
    HandoffExchangeDto:
      type: object
      properties:
        code:
          type: string
          description: One-time code minted by POST /auth/handoff
          example: k7F3n2pQ8wZmR1yT9bLxC0aVjHsUdEoI3mNcG5rXfB6hYvW
      required:
        - code
    AuthResponseDto:
      type: object
      properties:
        token:
          type: string
          description: JWT authentication token
          example: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...
        user:
          type: object
          description: Authenticated user information
          properties:
            id:
              type: string
              description: User unique identifier
              example: usr_01234567890abcdef
            email:
              type: string
              description: User email address
              example: user@example.com
        refresh_token:
          type: string
          description: Refresh token for obtaining new access tokens
          example: ref_0123456789abcdef
        expires_at:
          type: string
          description: Token expiration timestamp (ISO)
          example: '2025-01-01T01:00:00.000Z'
      required:
        - token
        - user
        - refresh_token
        - expires_at
  securitySchemes:
    AppIdentifier:
      type: apiKey
      in: header
      name: x-app-id
      description: App identifier (App.id, sent as the x-app-id header)

````