Authorization: Bearer header instead — session cookies are designed for interactive browser use and are not convenient for scripts. See the API Tokens reference for details.
Get a CSRF Token
GET /api/csrf Issue a new CSRF token for the current session. Include the returned value as anX-CSRF-Token header on every subsequent POST, PATCH, PUT, or DELETE request that uses cookie-based authentication.
string
A short-lived CSRF token. Pass this as the
X-CSRF-Token request header on mutating API calls made with a session cookie.If you authenticate with an
Authorization: Bearer token instead of a session cookie, you do not need a CSRF token — it is only required for cookie-authenticated requests.Get the Current User
GET /api/session Return the account details of the currently authenticated user, including their organization.string
Unique identifier for the authenticated user.
string
Email address associated with the account.
string
Display name of the user.
object
The organization the user belongs to.
Sign In
POST /api/session Authenticate with an email address and password. On success, the response sets an HttpOnly session cookie that authenticates subsequent requests.string
required
The email address registered to your Springwinter account.
string
required
Your account password. For accounts created with Google or Microsoft sign-in, use those OAuth flows instead — this endpoint accepts passwords only for email-based accounts.
Sign Out
DELETE /api/session Destroy the current session and clear the session cookie.Session cookies are
HttpOnly — client-side JavaScript cannot read them. This prevents cross-site scripting attacks from stealing credentials, but it also means you must use the DELETE endpoint (not client-side code) to sign out programmatically.