Skip to main content
POST

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Path Parameters

workspaceId
string
required

Required workspace containing the authenticated session. Must match the session resolved from the bearer token; never authorizes access by itself.

Body

application/json

RenewWidgetSessionRequest has no session ID or credential in its body. The verified bearer token identifies the existing session. The server rechecks current session and authorization policy before issuing a token. Token validation allows 60 seconds of clock skew: now must be strictly before exp + 60 seconds. Hard session expiry has no tolerance. A token beyond this window cannot renew even while the session remains active.

Response

OK

WidgetSessionCredentials is the browser-safe projection of creation credentials. Renewal returns the same fields, including exact token expiry and immutable session expiry, without importing the management API module. Responses containing credentials use Cache-Control: no-store.

sessionId
string
required
read-only

Canonical wsess_ identifier. Ordinary renewal cannot change the session.

host
string
required
read-only

Authoritative hostname, without a scheme or path. Use HTTPS with this host; never construct it or accept a host change during renewal.

token
string
required
read-only

Short-lived bearer credential for the widget host only.

tokenExpiresAt
string<date-time>
required
read-only

Exact token expiry, at most 15 minutes after issuance and never later than session_expires_at. Equals JWT exp without the 60-second validation tolerance added. Renew proactively before this timestamp.

sessionExpiresAt
string<date-time>
required
read-only

Immutable hard session expiry. Issuance never extends this deadline.