Skip to main content
POST
Mint a one-time cross-origin session handoff code

Authorizations

x-app-id
string
header
required

App identifier (App.id, sent as the x-app-id header)

Response

200 - application/json
code
string
required

One-time opaque code for cross-origin session handoff

Example:

"k7F3n2pQ8wZmR1yT9bLxC0aVjHsUdEoI3mNcG5rXfB6hYvW"

expires_at
string
required

Code expiration timestamp (ISO) - short-lived, single use

Example:

"2025-01-01T00:01:00.000Z"