DocsAPI reference

Enter support session

Starts working inside a customer's workspace, from the admin console.

post/api/auth/support/enter
Authentication
Bearer token
Body
application/json
Version
2026-09-03

Takes the token POST /internal/admin/impersonate just returned and puts it in the HttpOnly ic_support cookie, so the customer surfaces - app. and dashboard. - pick it up on their next refresh. The caller must be the operator who opened the session, signed in as themselves.

Headers#

  • Idempotency-Keystring

    A unique key of your choosing, so this request can be retried safely. The first request with a given key executes; every replay returns that first response unchanged, with Idempotent-Replay: true set.

    Generate one key per action, not per session - reusing a key with a different body is refused with 422 rather than silently replaying the wrong answer. Keys are remembered for 24 hours. A request that failed releases its key, so a retry after fixing the payload runs normally.

    Up to 255 characters

Request body#

application/json · required

SupportEnterRequest

  • tokenstringrequired

    16–200 characters

Responses#

  • 200OKapplication/json

    SupportSessionInfo

    • expires_atstring (date-time)required
    • org_idstringrequired
    • org_namestringrequired
    • session_idstringrequired
    • writebooleanrequired
    5 response headers
    RateLimit-Limit

    Requests permitted in the current window.

    RateLimit-Remaining

    Requests left in the current window. Back off before it reaches 0.

    RateLimit-Reset

    Seconds until the current window resets.

    X-API-Version

    The dated version of the API contract that served this response, e.g. 2026-09-03. Pin against it; it changes only when a response shape changes incompatibly.

    X-Request-ID

    Quote this in a support request to identify the call.

  • 422Validation error

    The shared error envelope, served as application/problem+json with error.code set to validation_error. Its details name each field that failed and why.

Errors#

Failures use one envelope on every endpoint, described in Retries, versioning and limits. The codes you are most likely to meet here:

  • validation_error · 422 — The payload was well-formed JSON but failed schema validation.
  • unauthenticated · 401 — The request carried no API key, or one the API could not verify.
  • forbidden · 403 — The key is valid, but it is not allowed to do this — either the scope is missing or the resource belongs to another workspace.
  • idempotency_key_reused · 422 — This `Idempotency-Key` was used before, for a request with a different body.
  • rate_limited · 429 — Too many requests in the current window. The limit is per workspace, and some endpoints add a per-agent limit on top.

More Auth endpoints#

Something unclear or missing? Tell us and we’ll fix it.