On this page
Docs / Authentication
Authentication
Ruleset v1.2.0. Engine 1.2.0. Group: Contract.
There is no public API key. People sign in with email and password. The cookie is ai_session, host-only, HttpOnly, SameSite=Lax, and lasts 7 days. Unverified sign-in is 403. A disabled account is 403. Bad credentials are 401. Verification and activation links expire in 24 hours. Password reset expires in 1 hour. An invite expires in 48 hours. GET /logout revokes the session. Do not put secrets in a query string. Verification mail is sent on this deployment.
GET /api/v1/session
{"error":"unauthenticated"}