Google Analytics, Leadsy and the TikTok Pixel stay off until you accept. The help chat starts once you have chosen. Read our Privacy Policy.

Skip to content
StellarFirmStellarFirm
Mission manual
Esc

Type a word to search every page. Try , or .

Module 09 · API

StellarFirm API authentication

How authentication works for the StellarFirm API. Which routes need no sign-in, which need a signed-in account, and how to send the session as a Bearer token or a cookie.

View as Markdown
On this page

Some StellarFirm API routes are public and some belong to an account. This page says which is which and how to send the session to the ones that need it.

Public routes#

These need no sign-in and no header:

  • GET /api/health
  • GET /api/site-banner
  • POST /api/email/unsubscribe, which is protected by the signed token in the link instead

Account routes#

These answer for the signed-in account:

  • GET /api/entitlement
  • GET /api/credits/balance

Without a session they answer 401 with the error code signed_out. See Errors.

How to send the session#

There are two ways, and the OpenAPI file names both as security schemes.

SchemeHowWho uses it
bearerAuthAuthorization: Bearer <session token>The desktop app, the phone app, and a program acting for an account
sessionCookieThe __session cookieA browser after you sign in at /sign-in

The session token belongs to a signed-in StellarFirm account. It is short lived and tied to that account, so a program has to be given one by the person whose account it is.

Keep the session private#

  • Send the token only over HTTPS, and only to https://stellarfirm.ai.
  • Never paste a session token into a chat, an issue, or a log.
  • A token that stops working answers 401. Sign in again to get a new one.

What the session can do#

The API routes only read. A session cannot make an assistant send, publish, deploy, or charge. Those steps wait for the CEO's Approve in the app.