Cobalt Session Token API

Generate session tokens for linked account authentication.

OpenAPI Specification

cobalt-session-token-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: Cobalt Applications Session Token API
  description: The Cobalt API enables developers to programmatically manage integrations, linked accounts, configurations, events, webhooks, executions, public workflows, and datastores within the Cobalt embedded integration platform. Cobalt helps product and engineering teams build native integrations, deploy them within days, and monetize them with the help of AI agents.
  version: 2.0.0
  contact:
    name: Cobalt Support
    url: https://www.gocobalt.io/
  termsOfService: https://docs.gocobalt.io/governance/terms-of-use
  license:
    name: Proprietary
    url: https://docs.gocobalt.io/governance/terms-of-use
servers:
- url: https://api.gocobalt.io/api/v2
  description: Cobalt Production API
security:
- apiKey: []
tags:
- name: Session Token
  description: Generate session tokens for linked account authentication.
paths:
  /public/session-token:
    post:
      operationId: createSessionToken
      summary: Cobalt Generate Token for Linked Account
      description: Generates a session token for a linked account. Session tokens expire in 24 hours and are used to authenticate client-side SDK calls.
      tags:
      - Session Token
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
              - linked_account_id
              properties:
                linked_account_id:
                  type: string
                  description: The unique identifier of the linked account.
      responses:
        '200':
          description: Session token generated successfully.
          content:
            application/json:
              schema:
                type: object
                properties:
                  token:
                    type: string
                    description: The session token for the linked account.
        '401':
          description: Unauthorized - Invalid API key.
        '400':
          description: Bad request - Missing required parameters.
components:
  securitySchemes:
    apiKey:
      type: apiKey
      in: header
      name: x-api-key
      description: API key for authentication. Found in Cobalt dashboard under Settings > Developer > Setup tab.
    sessionToken:
      type: apiKey
      in: header
      name: Authorization
      description: Session token generated via the Session Token endpoint.