On this page

Docs / Authentication

Authentication

Ruleset v1.2.0. Engine 1.2.0. Group: Contract.

There is no public API key. People sign in with email and password. The cookie is ai_session, host-only, HttpOnly, SameSite=Lax, and lasts 7 days. Unverified sign-in is 403. A disabled account is 403. Bad credentials are 401. Verification and activation links expire in 24 hours. Password reset expires in 1 hour. An invite expires in 48 hours. GET /logout revokes the session. Do not put secrets in a query string. Verification mail is sent on this deployment.

GET /api/v1/session
{"error":"unauthenticated"}

Previous: MCPNext: Errors