v4
latestOpenAPI 3.1.02026-08-086635375.7 KBEngine
create engine session
Start a live persona session.
Two authentication modes are supported via the Authorization: Bearer header:
- Session token (browser clients): pass a session token minted by POST /v1/auth/session-token. The session configuration was bound to the token when it was created, so the body only carries optional clientMetadata. This is the flow the client-side SDKs use; you normally don't call this endpoint yourself.
- API key (server-side SDKs): pass your API key directly and supply the session configuration in the request body — the same shape as the /v1/auth/session-token body (personaConfig, environment, sessionOptions, plus optional clientLabel and clientMetadata; expiresIn and widgetConfig do not apply). This skips the session-token exchange. Only use this from a secure server-side context — never expose an API key in a browser.
post/v1/engine/session
Request body
Response
Session started