Cognite Sessions API

Sessions are used to maintain access to CDF resources for an extended period of time. The methods available to extend a sessions lifetime are client credentials and token exchange. Sessions depend on the project OIDC configuration and may become invalid in the following cases - Project OIDC configuration has been updated through the [update project](#operation/updateProject) endpoint. This action invalidates all of the project's sessions. - The session was invalidated through the identity provider.

OpenAPI Specification

cognite-sessions-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: Cognite 3D Asset Mapping Sessions API
  description: "# Introduction\nThis is the reference documentation for the Cognite API with\nan overview of all the available methods.\n\n# Postman\nSelect the **Download** button to download our OpenAPI specification to get started.\n\nTo import your data into Postman, select **Import**, and the Import modal opens.\nYou can import items by dragging or dropping files or folders. You can choose how to import your API and manage the import settings in **View Import Settings**.\n\nIn the Import Settings, set the **Folder organization** to **Tags**, select\n**Enable optional parameters** to turn off the settings, and select **Always inherit authentication** to turn on the settings. Select **Import**.\n\nSet the Authorization to **Oauth2.0**. By default, the settings are for Open Industrial Data. Navigate to [Cognite Hub](https://hub.cognite.com/open-industrial-data-211) to understand how to get the credentials for use in Postman.\n\nFor more information, see [Getting Started with Postman](https://developer.cognite.com/dev/guides/postman/).\n\n# Pagination\nMost resource types can be paginated, indicated by the field `nextCursor` in the response.\nBy passing the value of `nextCursor` as the cursor you will get the next page of `limit` results.\nNote that all parameters except `cursor` has to stay the same.\n\n# Parallel retrieval\nAs general guidance, Parallel Retrieval is a technique that should be used when due to query complexity, retrieval of data in a single request is significantly slower than it would otherwise be for a simple request.  Parallel retrieval does not act as a speed multiplier on optimally running queries.  By parallelizing such requests, data retrieval performance can be tuned to meet the client application needs. \n\nCDF supports parallel retrieval through the `partition` parameter, which has the format `m/n` where `n` is the amount of partitions you would like to split the entire data set into.\nIf you want to download the entire data set by splitting it into 10 partitions, do the following in parallel with `m` running from 1 to 10:\n  - Make a request to `/events` with `partition=m/10`.\n  - Paginate through the response by following the cursor as explained above. Note that the `partition` parameter needs to be passed to all subqueries.\n\nProcessing of parallel retrieval requests is subject to concurrency quota availability. The request returns the `429` response upon exceeding concurrency limits. See the Request throttling chapter below.\n\nTo prevent unexpected problems and to maximize read throughput, you should at most use 10 partitions. \nSome CDF resources will automatically enforce a maximum of 10 partitions.\nFor more specific and detailed information, please read the ```partition``` attribute documentation for the CDF resource you're using.  \n\n# Requests throttling\nCognite Data Fusion (CDF) returns the HTTP `429` (too many requests) response status code when project capacity exceeds the limit.\n\nThe throttling can happen:\n  - If a user or a project sends too many (more than allocated) concurrent requests.\n  - If a user or a project sends a too high (more than allocated) rate of requests in a given amount of time.\n\nCognite recommends using a retry strategy based on truncated exponential backoff to handle sessions with HTTP response codes 429.\n\nCognite recommends using a reasonable number (up to 10) of  `Parallel retrieval` partitions.\n\nFollowing these strategies lets you slow down the request frequency to maximize productivity without having to re-submit/retry failing requests.\n\nSee more [here](https://docs.cognite.com/dev/concepts/resource_throttling).\n\n# API versions\n## Version headers\nThis API uses calendar versioning, and version names follow the `YYYYMMDD` format.\nYou can find the versions currently available by using the version selector at the top of this page.\n\nTo use a specific API version, you can pass the `cdf-version: $version` header along with your requests to the API.\n\n## Beta versions\nThe beta versions provide a preview of what the stable version will look like in the future.\nBeta versions contain functionality that is reasonably mature, and highly likely to become a part of the stable API.\n\nBeta versions are indicated by a `-beta` suffix after the version name. For example, the beta version header for the\n2023-01-01 version is then `cdf-version: 20230101-beta`.\n\n## Alpha versions\nAlpha versions contain functionality that is new and experimental, and not guaranteed to ever become a part of the stable API.\nThis functionality presents no guarantee of service, so its use is subject to caution.\n\nAlpha versions are indicated by an `-alpha` suffix after the version name. For example, the alpha version header for\nthe 2023-01-01 version is then `cdf-version: 20230101-alpha`."
  version: v1
  contact:
    name: Cognite Support
    url: https://support.cognite.com
    email: support@cognite.com
servers:
- url: https://{cluster}.cognitedata.com/api/v1/projects/{project}
  description: The URL for the CDF cluster to connect to
  variables:
    cluster:
      enum:
      - api
      - az-tyo-gp-001
      - az-eastus-1
      - az-power-no-northeurope
      - westeurope-1
      - asia-northeast1-1
      - gc-dsm-gp-001
      default: api
      description: The CDF cluster to connect to
    project:
      default: publicdata
      description: The CDF project name.
security:
- oidc-token:
  - https://{cluster}.cognitedata.com/.default
- oauth2-client-credentials:
  - https://{cluster}.cognitedata.com/.default
- oauth2-open-industrial-data:
  - https://api.cognitedata.com/.default
- oauth2-auth-code:
  - https://{cluster}.cognitedata.com/.default
tags:
- name: Sessions
  description: "Sessions are used to maintain access to CDF resources for an extended period of time. The methods available to extend a sessions lifetime are client credentials and token exchange.\nSessions depend on the project OIDC configuration and may become invalid in the following cases\n- Project OIDC configuration has been updated through the [update project](#operation/updateProject)\n  endpoint. This action invalidates all of the project's sessions.\n\n- The session was invalidated through the identity provider.\n"
paths:
  /sessions:
    get:
      x-capability: sessionsAcl:LIST
      tags:
      - Sessions
      operationId: listSessions
      summary: List sessions
      description: '


        > **Required capabilities:** `sessionsAcl:LIST`


        List all sessions in the current project.'
      parameters:
      - in: query
        name: status
        description: 'If given, only sessions with the given status are returned.

          '
        schema:
          type: string
          enum:
          - ready
          - active
          - cancelled
          - revoked
          - access_lost
      - name: cursor
        in: query
        description: Cursor to use for paging through results.
        schema:
          type: string
      - name: limit
        in: query
        description: Return up to this many results. Maximum is 1000. Default is 25.
        schema:
          maximum: 1000
          type: integer
          format: int32
          default: 25
      responses:
        '200':
          description: A list of sessions in the current project.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SessionList'
        '400':
          $ref: '#/components/responses/ErrorResponse'
    post:
      x-capability: sessionsAcl:CREATE
      tags:
      - Sessions
      operationId: createSessions
      summary: Create sessions
      description: '


        > **Required capabilities:** `sessionsAcl:CREATE`


        Create sessions'
      requestBody:
        description: A request containing the information needed to create a session.
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateSessionRequestList'
      responses:
        '200':
          description: List of session creation related information
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/CreateSessionResponseList'
        '400':
          $ref: '#/components/responses/ErrorResponse'
  /sessions/byids:
    post:
      x-capability: sessionsAcl:LIST
      tags:
      - Sessions
      operationId: getSessionsByIds
      summary: Retrieve sessions with given IDs
      description: '


        > **Required capabilities:** `sessionsAcl:LIST`


        Retrieves sessions with given IDs. The request will fail if any of the IDs does not belong to an existing session.'
      requestBody:
        description: List of session IDs to retrieve
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SessionReferenceIds'
      responses:
        '200':
          description: A list of sessions with the given ids
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SessionByIds'
              example:
                items:
                - id: 105049194919491
                  type: TOKEN_EXCHANGE
                  status: ACTIVE
                  creationTime: 1638795559528
                  expirationTime: 1638795559628
        '400':
          $ref: '#/components/responses/ErrorResponse'
  /sessions/revoke:
    post:
      x-capability: sessionsAcl:DELETE
      tags:
      - Sessions
      operationId: revokeSessions
      summary: Revoke sessions
      description: '


        > **Required capabilities:** `sessionsAcl:DELETE`


        Revoke access to a session. Revocation is idempotent.

        Revocation of a session may in some cases take up to 1 hour to take effect.

        '
      requestBody:
        description: A request containing the information needed to revoke sessions.
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RevokeSessionRequestList'
      responses:
        '200':
          description: 'List of revoked sessions.

            If the user does not have the `sessionsAcl:LIST` capability, then only the session IDs will be present in the response.

            '
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SessionList'
              example:
                items:
                - id: 0
                  type: CLIENT_CREDENTIALS
                  status: REVOKED
                  creationTime: 1638795554528
                  expirationTime: 1638795554528
                  clientId: client-123
        '400':
          $ref: '#/components/responses/ErrorResponse'
components:
  responses:
    ErrorResponse:
      description: The response for a failed request.
      content:
        application/json:
          schema:
            type: object
            required:
            - error
            properties:
              error:
                $ref: '#/components/schemas/Error'
  schemas:
    EpochTimestamp:
      description: The number of milliseconds since 00:00:00 Thursday, 1 January 1970, Coordinated Universal Time (UTC), minus leap seconds.
      type: integer
      minimum: 0
      format: int64
      example: 1730204346000
    CreateSessionWithTokenExchangeRequest:
      description: 'Credentials for a session using token exchange to reuse the user''s credentials.

        '
      type: object
      required:
      - tokenExchange
      properties:
        tokenExchange:
          type: boolean
          enum:
          - true
          description: Use token exchange for the session. Must be `true`.
    CreateSessionResponse:
      description: 'A response with the ID, nonce and other information related to the session. The nonce

        is short-lived and should be immediately passed to the endpoint that will use

        the session.

        '
      type: object
      required:
      - id
      - status
      - nonce
      properties:
        id:
          description: ID of the session
          type: number
        type:
          type: string
          description: Values reserved for future use
          anyOf:
          - enum:
            - CLIENT_CREDENTIALS
            - TOKEN_EXCHANGE
            - ONESHOT_TOKEN_EXCHANGE
        status:
          description: Current status of the session
          type: string
          enum:
          - READY
          - ACTIVE
          - CANCELLED
          - EXPIRED
          - REVOKED
          - ACCESS_LOST
        nonce:
          description: Nonce to be passed to the internal service that will bind the session
          type: string
        clientId:
          description: Client ID in identity provider. Returned only if the session was created using client credentials
          type: string
    Session:
      type: object
      properties:
        id:
          description: ID of the session
          type: number
        type:
          type: string
          description: Values reserved for future use
          anyOf:
          - enum:
            - CLIENT_CREDENTIALS
            - TOKEN_EXCHANGE
            - ONESHOT_TOKEN_EXCHANGE
        status:
          description: Current status of the session
          type: string
          enum:
          - READY
          - ACTIVE
          - CANCELLED
          - EXPIRED
          - REVOKED
          - ACCESS_LOST
        creationTime:
          description: Session creation time, in milliseconds since 1970
          allOf:
          - $ref: '#/components/schemas/EpochTimestamp'
        expirationTime:
          description: Session expiry time, in milliseconds since 1970. This value is updated on refreshing a token
          allOf:
          - $ref: '#/components/schemas/EpochTimestamp'
        clientId:
          description: Client ID in identity provider. Returned only if the session was created using client credentials
          type: string
    SessionReferenceIds:
      type: object
      required:
      - items
      properties:
        items:
          type: array
          items:
            type: object
            required:
            - id
            properties:
              id:
                $ref: '#/components/schemas/CogniteInternalId'
          maxItems: 1000
          minItems: 1
    SessionList:
      type: object
      properties:
        items:
          type: array
          items:
            $ref: '#/components/schemas/Session'
        nextCursor:
          type: string
          description: Cursor to get the next page of results (if available).
        previousCursor:
          type: string
          description: Cursor to get the previous page of results (if available).
    CreateSessionWithClientCredentialsRequest:
      description: 'Credentials for a session using client credentials from an identity provider.

        '
      type: object
      required:
      - clientId
      - clientSecret
      properties:
        clientId:
          type: string
          description: Client ID in identity provider
        clientSecret:
          type: string
          description: Client secret in identity provider
    SessionByIds:
      type: object
      properties:
        items:
          type: array
          items:
            $ref: '#/components/schemas/Session'
    CreateSessionResponseList:
      description: ''
      type: object
      properties:
        items:
          type: array
          items:
            $ref: '#/components/schemas/CreateSessionResponse'
    RevokeSessionRequest:
      description: ''
      type: object
      required:
      - id
      properties:
        id:
          description: ID of the session
          type: number
    CreateSessionRequest:
      description: ''
      oneOf:
      - $ref: '#/components/schemas/CreateSessionWithClientCredentialsRequest'
      - $ref: '#/components/schemas/CreateSessionWithTokenExchangeRequest'
      - $ref: '#/components/schemas/CreateSessionWithOneshotTokenExchangeRequest'
    CogniteInternalId:
      description: A server-generated ID for the object.
      type: integer
      minimum: 1
      maximum: 9007199254740991
      format: int64
    RevokeSessionRequestList:
      description: ''
      type: object
      properties:
        items:
          type: array
          minItems: 1
          items:
            $ref: '#/components/schemas/RevokeSessionRequest'
    CreateSessionWithOneshotTokenExchangeRequest:
      description: 'Credentials for a session using one-shot token exchange to reuse the user''s credentials.

        One-shot sessions are short-lived sessions that are not refreshed and do not require support for token exchange from the identity provider.

        '
      type: object
      required:
      - oneshotTokenExchange
      properties:
        oneshotTokenExchange:
          type: boolean
          enum:
          - true
          description: Use one-shot token exchange for the session. Must be `true`.
    Error:
      type: object
      required:
      - code
      - message
      description: Cognite API error.
      properties:
        code:
          type: integer
          description: HTTP status code.
          format: int32
          example: 401
        message:
          type: string
          description: Error message.
          example: Could not authenticate.
        missing:
          type: array
          description: List of lookup objects that do not match any results.
          items:
            type: object
            additionalProperties: true
        duplicated:
          type: array
          description: List of objects that are not unique.
          items:
            type: object
            additionalProperties: true
    CreateSessionRequestList:
      description: ''
      type: object
      properties:
        items:
          type: array
          minItems: 1
          maxItems: 1
          items:
            $ref: '#/components/schemas/CreateSessionRequest'
  securitySchemes:
    oidc-token:
      type: http
      scheme: bearer
      bearerFormat: OpenID Connect or OAuth2 token
      description: Access token issued by the CDF project's configured identity provider. Access token must be an OpenID Connect token, and the project must be configured to accept OpenID Connect tokens. Use a header key of 'Authorization' with a value of 'Bearer $accesstoken'. The token can be obtained through any flow supported by the identity provider.
    oauth2-client-credentials:
      type: oauth2
      description: Access token issued by the CDF project's configured identity provider. Access token must be an OpenID Connect token, and the project must be configured to accept OpenID Connect tokens. Use a header key of 'Authorization' with a value of 'Bearer $accesstoken'. The token can be obtained through any flow supported by the identity provider.
      flows:
        clientCredentials:
          tokenUrl: https://your-idps.token.url/
          scopes:
            default: https://{cluster}.cognitedata.com/.default
    oauth2-auth-code:
      type: oauth2
      description: Access token issued by the CDF project's configured identity provider. Access token must be an OpenID Connect token, and the project must be configured to accept OpenID Connect tokens. Use a header key of 'Authorization' with a value of 'Bearer $accesstoken'. The token can be obtained through any flow supported by the identity provider.
      flows:
        authorizationCode:
          authorizationUrl: https://your-idps.authorization.url/
          tokenUrl: https://your-idps.token.url/
          scopes:
            default: https://{cluster}.cognitedata.com/.default
    oauth2-open-industrial-data:
      type: oauth2
      description: Auth flow for Open Industrial Data. Get your client secret from https://hub.cognite.com/open-industrial-data-211.
      flows:
        clientCredentials:
          tokenUrl: https://login.microsoftonline.com/48d5043c-cf70-4c49-881c-c638f5796997/oauth2/v2.0/token
          scopes:
            default: https://api.cognitedata.com/.default
    org-oidc-token:
      type: openIdConnect
      openIdConnectUrl: https://auth.cognite.com/.well-known/openid-configuration
      description: 'Access token issued by the Cognite authorization server, and valid for the target organization. The token must

        be an OpenID Connect token, and it can be obtained by performing an OIDC login flow toward `auth.cognite.com`.

        This is a single URL for all CDF organizations.'
x-tagGroups:
- name: Changelog
  tags:
  - Changelog
- name: Organizations and projects
  tags:
  - Organizations
  - Projects
- name: Identity and access management
  tags:
  - Principals
  - Groups
  - Security categories
  - Sessions
  - Token
  - User profiles
  - Project Deletion Reporting
- name: Data modeling
  tags:
  - Data Modeling
  - Data models
  - Spaces
  - Views
  - Containers
  - Nodes
  - Instances
  - Statistics
  - Streams
  - Records
- name: Asset-centric data model
  tags:
  - Assets
  - Time series
  - Synthetic Time Series
  - Data point subscriptions
  - Events
  - Files
  - Sequences
  - Geospatial
  - Seismic
- name: 3D
  tags:
  - 3D Models
  - 3D Model Revisions
  - 3D Files
  - 3D Asset Mapping
  - 3D Contextualization
  - 3D Jobs
  - 3D Migration
  - 3D Scenes
- name: Contextualization
  tags:
  - Entity matching
  - Entity matching pipelines
  - Engineering diagrams
  - Vision
  - Advanced joins
- name: Cognite AI
  tags:
  - Agents
  - Skills
  - Chat Completions
  - Document AI
  - Models
- name: Documents
  tags:
  - Documents
  - Document preview
- name: Data ingestion
  tags:
  - Raw
  - Extraction Pipelines
  - Extraction Pipelines Runs
  - Extraction Pipelines Config
  - Extractors
- name: Data organization
  tags:
  - Data sets
  - Data domains
  - Data products
  - Rule sets
  - Labels
  - Relationships
  - Annotations
- name: Transformations
  tags:
  - Transformations
  - Transformation Jobs
  - Transformation Schedules
  - Transformation Notifications
  - Query
  - Schema
- name: Functions
  tags:
  - Functions
  - Function calls
  - Function schedules
- name: Hosted Extractors
  tags:
  - Sources
  - Jobs
  - Destinations
  - Mappings
- name: PostgreSQL Gateway
  tags:
  - Postgres Gateway Users
  - Postgres Gateway Tables
- name: SAP Writeback
  tags:
  - SAP Instances
  - SAP Endpoints
  - Schema Mappings
  - Writeback Requests
- name: Data workflows
  tags:
  - Workflows
  - Workflow versions
  - Workflow executions
  - Workflow triggers
  - Tasks
  - Workers
- name: Simulators
  tags:
  - Simulators
  - Simulator Integrations
  - Simulator Models
  - Simulator Routines
  - Simulation Runs
  - Simulator Logs
- name: Units
  tags:
  - Units
  - Unit Systems
- name: ''
  tags:
  - ''