Skip to content

Set this session’s cookie on the host asked through

POST
/auth/session/cookie
curl --request POST \
--url https://api.sloose.com/auth/session/cookie \
--header 'Authorization: Bearer <token>'

Better Auth’s own cookie for the bearer’s session, set on the host the request came through — the app’s own, through /api (#771). For a page that holds its session as a bearer from before its host kept the cookie, and has to send the browser somewhere that reads the cookie instead: an authorisation an app asked for, which continues on GET /auth/ba/oauth2/authorize through the same host.

Asked only from one of the app’s own pages (Origin), and only for a browser’s own session: never an API token, a CRM tab’s own session, or a staff member’s view of an org — a view’s cookie would be read by the staff member’s other tabs as their own.

Session only.

The session’s cookie is set on the host asked through.

Media typeapplication/json
object
ok
required
boolean
Example
{
"ok": true
}

No bearer, or one that is expired, revoked or no longer resolves to a member.

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

Not asked from one of the app’s own pages (code: BAD_ORIGIN), a CRM tab’s own session (code: TAB_SESSION), or a staff member’s view of an org (code: STAFF_VIEW).

Media typeapplication/json

The error envelope every non-2xx answer uses.

object
error
required

Human-readable explanation.

string
code

Machine-readable reason. Absent on a few legacy 400s.

string
key
additional properties
Examplegenerated
{
"error": "example",
"code": "example"
}

Report a problem with this page