Skip to main content
POST
Sign a browser in

Body

application/json

Exactly one of code, key and token.

code
string

A one-time code from POST /v1/login-codes.

Maximum string length: 200
key
string

An access key (abh_…). It is checked and never kept.

Maximum string length: 200
token
string

A browser token (abb_…) a page kept in its own storage, to copy into the cookie.

Maximum string length: 200
confirm_switch
boolean

True when the person confirmed signing this browser in as someone other than the person its current session belongs to. A page sends it only after the person clicked to switch.

Response

Signed in. The cookie is in Set-Cookie.

id
string
required
Pattern: ^ses_[0-9A-HJKMNP-TV-Z]{26}$
key
object
required

The access key a browser session belongs to; the session ends with it.

started_with
enum<string>
required

How the session started: login_code for aboard open, access_key for a key pasted on the login page.

Available options:
login_code,
access_key
created_at
string<date-time>
required
expires_at
string<date-time>
required
person
object
required
csrf_token
string
required

Send it as X-Aboard-CSRF with every write this session makes. It works only with this session's cookie.