---
title: "Authenticate and start a session (deprecated)"
method: POST
path: "/handshake"
tags: ["Authentication"]
---

# Authenticate and start a session (deprecated)

`POST /handshake`

When you do not have an API key you can request a session token using handshake which can then be used as your authentication token.

## Query parameters

- `auth` string
- `user` string
- `timestamp` integer
- `version` string

## Response `200`

Session info or error

- object

## Other responses

- `400` — Ampache API error response payload.

## Changes

- **2026-07-17** `9abb9bf6d3bf` — 2 info
  - endpoint deprecated
  - removed the non-success response with the status `400`
- **2026-07-17** `aff89ca1eeff` — 1 info
  - endpoint reactivated
- **2026-06-25** `7ed7a764efd9` — 1 info
  - added the non-success response with the status `400`
- **2026-02-26** `c3f202b17eb7` — 2 info
  - the endpoint scheme security `ApiKeyAuthHeader` was added to the API
  - the endpoint scheme security `ApiKeyAuthQuery` was added to the API
- **2026-02-19** `07f53972fdd7` — 2 info
  - the endpoint scheme security `ApiKeyAuthHeader` was removed from the API
  - the endpoint scheme security `ApiKeyAuthQuery` was removed from the API

[Change history](https://skmtc.dev/ampache/apis/ampache-rest-api/changes/handshake/post.md)

---

[API](https://skmtc.dev/ampache/apis/ampache-rest-api.md) · [All operations](https://skmtc.dev/ampache/apis/ampache-rest-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/ampache/ampache-rest-api/revisions/0366bc42fb8f/schema)
