Renew a widget session token
Requires a valid widget bearer token with 60 seconds of clock-skew tolerance: serverNow must be strictly before exp + 60 seconds. Hard session expiry has no tolerance. A token beyond the drift window fails with TOKEN_EXPIRED and requires newer credentials or explicit app reauthentication; never recursively renew or automatically replace the session. Resolves the token’s existing session, rechecks current session and authorization policy, and returns fresh credentials for that same session. The required workspace ID must match the authenticated session; no session ID or management credential is supplied. Preserves identity, scope, secrets, pinned parameters, counters, and hard session expiry. Other unexpired tokens remain valid. Returns tokenExpiresAt and sessionExpiresAt with Cache-Control: no-store. Revoked, expired, and exhausted sessions cannot renew.
Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Path Parameters
Required workspace containing the authenticated session. Must match the session resolved from the bearer token; never authorizes access by itself.
Body
RenewWidgetSessionRequest has no session ID or credential in its body. The verified bearer token identifies the existing session. The server rechecks current session and authorization policy before issuing a token. Token validation allows 60 seconds of clock skew: now must be strictly before exp + 60 seconds. Hard session expiry has no tolerance. A token beyond this window cannot renew even while the session remains active.
Response
OK
WidgetSessionCredentials is the browser-safe projection of creation credentials. Renewal returns the same fields, including exact token expiry and immutable session expiry, without importing the management API module. Responses containing credentials use Cache-Control: no-store.
Canonical wsess_ identifier. Ordinary renewal cannot change the session.
Authoritative hostname, without a scheme or path. Use HTTPS with this host; never construct it or accept a host change during renewal.
Short-lived bearer credential for the widget host only.
Exact token expiry, at most 15 minutes after issuance and never later than session_expires_at. Equals JWT exp without the 60-second validation tolerance added. Renew proactively before this timestamp.
Immutable hard session expiry. Issuance never extends this deadline.