auth

Mint a short-lived, single-use live-voice WS token for the web SPA.

Requires session auth + CSRF (enforced by DRF SessionAuthentication for this unsafe POST) and the Vellum-Organization-Id header. The caller must own the requested assistant within the resolved organization.

post/v1/auth/live-voice-token/

Request

  • The document declares no server URL.
  • Auth: one of:
    • API key in cookie sessionid
    • API key in header X-Session-Token

Headers

Vellum-Organization-Idstring uuid

Required if using Cookie-based or X-Session-Token authentication methods.

Request body

assistantIdstring uuid required

Response

tokenstring required
expiresAtstring date-time required

Changes

No recorded changes to this operation across all 50 revisions of this API.