auth

Start Guest Session

Changed on

Start a guest (Supabase anonymous) session for the Axel web server.

No captcha: the gateway creates the anonymous user with the service role. Order: ParamStore kill switch (403 guest_disabled), web-server signature with a visitor key (403 guest_session_unsigned), per-address caps (429 guest_rate_limited), then Supabase (503 guest_session_unavailable when it refuses, times out, or the service key is missing).

post/auth/guest-session

Request

  • Base URL: https://api.helloaxel.com (the document declares no server; this is the origin it was published from)
  • URL: https://api.helloaxel.com/auth/guest-session
  • Auth: none declared

Headers

X-Axel-Flight-Sourcestring nullable

Percent-encoded FlightCheckSource JSON (2048 characters maximum) written by the Axel web server; its client_key keys the per-address caps.

X-Axel-Flight-Source-Signaturestring nullable

HMAC-SHA256 (hex) of X-Axel-Flight-Source by the Axel web server. Required: only the web server may start a guest session.

Response

Successful Response

access_tokenstring required
refresh_tokenstring required
expires_ininteger required
expires_atinteger nullable
user_idstring uuid required

Changes