---
title: "Create Session"
method: POST
path: "/v1/auth/session"
tags: ["auth"]
---

# Create Session

`POST /v1/auth/session`

Verify the master key and set the HttpOnly session cookie.

## Request body

- CreateSessionRequest — Sign in to the dashboard by proving possession of the master key.
  - `master_key` string, required — The gateway master key; verified once and never stored by the browser.

## Response `200`

Successful Response

- SessionResponse — A freshly minted dashboard session (the token travels only in the cookie).
  - `expires_at` string, date-time, required — When the session cookie stops being accepted.

## Other responses

- `422` — Validation Error

## Changes

- **2026-07-23** `4fc7665de4e1` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/mozilla-ai/apis/otari/changes/v1/auth/session/post.md)

---

[API](https://skmtc.dev/mozilla-ai/apis/otari.md) · [All operations](https://skmtc.dev/mozilla-ai/apis/otari/llms.txt) · [OpenAPI document](https://skmtc.dev/mozilla-ai/apis/otari/revisions/2a163c690f59?raw)
