Module 09 · API
StellarFirm API authentication
How authentication works for the StellarFirm API. Which routes need no sign-in, which need a signed-in account, and how to send the session as a Bearer token or a cookie.
On this page
Some StellarFirm API routes are public and some belong to an account. This page says which is which and how to send the session to the ones that need it.
Public routes#
These need no sign-in and no header:
GET /api/healthGET /api/site-bannerPOST /api/email/unsubscribe, which is protected by the signed token in the link instead
Account routes#
These answer for the signed-in account:
GET /api/entitlementGET /api/credits/balance
Without a session they answer 401 with the error code signed_out. See Errors.
How to send the session#
There are two ways, and the OpenAPI file names both as security schemes.
| Scheme | How | Who uses it |
|---|---|---|
bearerAuth | Authorization: Bearer <session token> | The desktop app, the phone app, and a program acting for an account |
sessionCookie | The __session cookie | A browser after you sign in at /sign-in |
The session token belongs to a signed-in StellarFirm account. It is short lived and tied to that account, so a program has to be given one by the person whose account it is.
Keep the session private#
- Send the token only over HTTPS, and only to
https://stellarfirm.ai. - Never paste a session token into a chat, an issue, or a log.
- A token that stops working answers
401. Sign in again to get a new one.
What the session can do#
The API routes only read. A session cannot make an assistant send, publish, deploy, or charge. Those steps wait for the CEO's Approve in the app.