Skip to main content
POST
Trade a portal token for a session cookie

Authorizations

Authorization
string
header
required

A hpt_… customer portal token, as Authorization: Bearer. Stored hashed and looked up by its full SHA-256 hash; shown once at issue. The query string (?token=) is not accepted: a token there ends up in request logs and traces. A browser page trades the token for a portalSession cookie with POST /portal/api/session.

Response

Session started. The cookie is in Set-Cookie; the body says when it ends.

ok
enum<boolean>
required
Available options:
true
expires_at
string<date-time>
required