Sessions & Authentication
User login, session management, and API key operations
Sessions & Authentication
Authentication domain handles user login, session management, and API key operations.
Key Concepts
- Session: Server-side state tied to a refresh token (UUID)
- Access Token: Short-lived JWT for API requests
- Refresh Token: Long-lived session identifier for token renewal
- API Key: Credentials for programmatic access
Endpoints Overview
Session Flow
MFA States
API Key Permissions
API keys can have a subset of user permissions: