Skip to content

Authentication and token endpoints

View as Markdown

Generated project-auth routes and their OpenAPI contracts.

  • Browser auth uses session cookies and exact trusted origins.
  • Auth context and bootstrap routes return the current user, session, membership, and active workspace state.
  • Workspace switching changes the active request authority for later calls.
  • Agent-token creation reveals the raw secret once; list returns metadata and revoke invalidates later bearer calls.
  • Token management is browser/session-only; bearer callers use the represented account and workspace authority.