> ## Documentation Index
> Fetch the complete documentation index at: https://docs.kerne.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Mint a one-time cross-origin session handoff code

> For apps/portal (hosted auth UI, a different origin than the tenant's app_url) to hand its session off after redirecting - the code, not the session itself, travels through the URL.



## OpenAPI

````yaml /openapi.json post /v1/auth/handoff
openapi: 3.0.0
info:
  title: Kerne API
  description: >-
    Kerne SaaS Foundation as a Service - authentication, authorization, and
    billing management. Errors follow standardized error codes (K1xxx-K9xxx)
    documented at https://docs.kerne.io/errors
  version: 1.0.0
  contact:
    name: Kerne Team
    url: https://kerne.io
    email: support@kerne.io
  license:
    name: Proprietary
    url: https://kerne.io/license
servers:
  - url: https://api.kerne.io
    description: Production Server
security: []
tags:
  - name: Auth
    description: Authentication endpoints
  - name: Waitlist
    description: Waitlist management
  - name: Invitations
    description: Invitation system
  - name: Billing
    description: 'The tenant''s end users: subscription, entitlements, usage, checkout'
  - name: Pricing
    description: Public pricing page data
paths:
  /v1/auth/handoff:
    post:
      tags:
        - Auth
      summary: Mint a one-time cross-origin session handoff code
      description: >-
        For apps/portal (hosted auth UI, a different origin than the tenant's
        app_url) to hand its session off after redirecting - the code, not the
        session itself, travels through the URL.
      operationId: AuthController_handoff
      parameters: []
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HandoffResponseDto'
      security:
        - AppIdentifier: []
        - JWT: []
components:
  schemas:
    HandoffResponseDto:
      type: object
      properties:
        code:
          type: string
          description: One-time opaque code for cross-origin session handoff
          example: k7F3n2pQ8wZmR1yT9bLxC0aVjHsUdEoI3mNcG5rXfB6hYvW
        expires_at:
          type: string
          description: Code expiration timestamp (ISO) - short-lived, single use
          example: '2025-01-01T00:01:00.000Z'
      required:
        - code
        - expires_at
  securitySchemes:
    AppIdentifier:
      type: apiKey
      in: header
      name: x-app-id
      description: App identifier (App.id, sent as the x-app-id header)
    JWT:
      scheme: bearer
      bearerFormat: JWT
      type: http
      description: JWT token obtained from /v1/auth/token

````