Set this session’s cookie on the host asked through
const url = 'https://api.sloose.com/auth/session/cookie';const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.sloose.com/auth/session/cookie \ --header 'Authorization: Bearer <token>'Better Auth’s own cookie for the bearer’s session, set on the host the request came through — the app’s own, through /api (#771). For a page that holds its session as a bearer from before its host kept the cookie, and has to send the browser somewhere that reads the cookie instead: an authorisation an app asked for, which continues on GET /auth/ba/oauth2/authorize through the same host.
Asked only from one of the app’s own pages (Origin), and only for a browser’s own session: never an API token, a CRM tab’s own session, or a staff member’s view of an org — a view’s cookie would be read by the staff member’s other tabs as their own.
Session only.
Authorizations
Section titled “Authorizations”Responses
Section titled “Responses”The session’s cookie is set on the host asked through.
object
Example
{ "ok": true}No bearer, or one that is expired, revoked or no longer resolves to a member.
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}Not asked from one of the app’s own pages (code: BAD_ORIGIN), a CRM tab’s own session (code: TAB_SESSION), or a staff member’s view of an org (code: STAFF_VIEW).
The error envelope every non-2xx answer uses.
object
Human-readable explanation.
Machine-readable reason. Absent on a few legacy 400s.
Examplegenerated
{ "error": "example", "code": "example"}