Auth

Reissue a direct token without changing which resource it is bound to.

Extends a boot session past the 4 hour token expiry while keeping the same allowed_resource_id, so a conversation in progress is not interrupted.

Unlike POST /auth/boot this endpoint is authenticated: present the current direct token as Bearer <token>. The resource assignment is copied from that token and never read from the request body, so a caller cannot name a resource it does not already hold.

Refreshing does not extend a session indefinitely. Each token carries an absolute ceiling fixed at the original boot, and the reissued token inherits it unchanged. Revoking the direct link (regenerating its hash), deleting the direct record, or deactivating the customer all take effect on the next refresh.

post/auth/boot/refresh

Response

Token reissued. allowed_resource_id and scope_version are unchanged; only expire moves. resource_data is always omitted here (the client already holds it from the original boot), so the response is the boot response minus that field.

tokenstring

JWT token string for API authentication. Pass as Bearer <token> in the Authorization header.

type'direct'

Token type. Always "direct" for boot tokens.

resource_typestring

The type of resource this token is scoped to (e.g., "ai").

resource_idstring uuid

The UUID of the resource this token is scoped to. Returned from the resource creation endpoint (e.g., POST /ais).

customer_idstring uuid

The UUID of the customer that owns the resource. Returned from the POST /auth/signup response.

expirestring date-time

Token expiry timestamp in ISO 8601 format.

allowed_resource_idstring uuid

The single resource this token may act on, assigned at boot before the resource exists. The resource created with this token takes this id, so two visitors of the same public link cannot reach each other's conversation. Clients do not need to send it anywhere; the server takes the target from the token.

scope_versioninteger

Version of the token's scope contract. Bumping it invalidates every outstanding token in one step; clients treat the resulting 401 as a signal to boot again.

Example response

{
  "token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJjdXN0b21lcl9pZCI6IjU1MGU4NDAwLWUyOWItNDFkNC1hNzE2LTQ0NjY1NTQ0MDAwMCJ9.abc123",
  "type": "direct",
  "resource_type": "ai",
  "resource_id": "550e8400-e29b-41d4-a716-446655440000",
  "customer_id": "660e8400-e29b-41d4-a716-446655440001",
  "expire": "2026-04-07T12:00:00Z",
  "allowed_resource_id": "770e8400-e29b-41d4-a716-446655440002",
  "scope_version": 2,
  "resource_data": {
    "public_display_config": {
      "primary_color": "#1a73e8",
      "secondary_color": "#f5f5f5",
      "header_background_color": "#1a73e8",
      "header_text_color": "#ffffff",
      "logo_url": "https://cdn.example.com/logo.png",
      "position": "bottom_right",
      "theme_mode": "light",
      "header_title": "Support",
      "header_subtitle": "We usually reply in a few minutes",
      "connecting_indicator_enabled": true,
      "connecting_indicator_text": "Connecting…",
      "typing_indicator_enabled": true,
      "border_radius": "rounded",
      "font_size": "default"
    }
  }
}

Changes

Changed in 1 of the 97 revisions of this API.1