---
title: "Create an auth session"
method: POST
path: "/auth-sessions"
---

# Create an auth session

`POST /auth-sessions`

To launch the authentication flow, create an auth session and pass the returned session's `authFlowUrl` to the client for your end-user to visit in their browser. Demo: https://connect.conductor.is/qbd/demo

## Request body

- object
  - `publishableKey` string, required — Your Conductor publishable key, which we use to create the auth session's `authFlowUrl`.
  - `endUserId` string, required — The ID of the end-user for whom to create the integration connection.
  - `linkExpiryMins` number — The number of minutes after which the auth session will expire. Must be at least 15 minutes and no more than 7 days. If not provided, defaults to 30 minutes.
  - `redirectUrl` string, uri — The URL to which Conductor will redirect the end-user to return to your app after they complete the authentication flow. If not provided, their browser tab will close instead.

## Response `200`

Returns the auth session object.

- AuthSession
  - `id` string, required — The unique identifier for this auth session.
  - `objectType` 'auth_session', required — The type of object. This value is always `"auth_session"`.
  - `createdAt` string, required — The date and time when this auth session record was created.
  - `endUserId` string, required — The ID of the end-user for whom to create an integration connection.
  - `clientSecret` string, required — The secret used in `authFlowUrl` to securely access the authentication flow.
  - `authFlowUrl` string, required — The URL of the authentication flow that you will pass to your client for your user to set up their integration connection.
  - `expiresAt` string, required — The date and time when this auth session expires. By default, this value is 30 minutes from creation. You can extend this time by setting `linkExpiryMins` when creating the auth session.
  - `redirectUrl` string, nullable, required — The URL to which Conductor will redirect your user to return to your app after they complete the authentication flow. If `null`, their browser tab will close instead.

---

[API](https://skmtc.net/conductor-is/apis/conductor-api.md) · [All operations](https://skmtc.net/conductor-is/apis/conductor-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/conductor-is/conductor-api/versions/0b07b3ebe160/schema)
