Skip to main content
The Session API manages browser-based authentication for the Springwinter dashboard. It issues session cookies, provides CSRF protection for mutating requests, and lets you inspect or destroy the current session. For programmatic or CI access, use an API token with an Authorization: Bearer header instead — session cookies are designed for interactive browser use and are not convenient for scripts. See the API Tokens reference for details.

Get a CSRF Token

GET /api/csrf Issue a new CSRF token for the current session. Include the returned value as an X-CSRF-Token header on every subsequent POST, PATCH, PUT, or DELETE request that uses cookie-based authentication.
string
A short-lived CSRF token. Pass this as the X-CSRF-Token request header on mutating API calls made with a session cookie.
If you authenticate with an Authorization: Bearer token instead of a session cookie, you do not need a CSRF token — it is only required for cookie-authenticated requests.

Get the Current User

GET /api/session Return the account details of the currently authenticated user, including their organization.
string
Unique identifier for the authenticated user.
string
Email address associated with the account.
string
Display name of the user.
object
The organization the user belongs to.

Sign In

POST /api/session Authenticate with an email address and password. On success, the response sets an HttpOnly session cookie that authenticates subsequent requests.
string
required
The email address registered to your Springwinter account.
string
required
Your account password. For accounts created with Google or Microsoft sign-in, use those OAuth flows instead — this endpoint accepts passwords only for email-based accounts.
Most integrations are easier with an API token than with session cookies. Tokens do not require CSRF headers, do not expire on browser close, and are straightforward to rotate. Create one in Settings → API Tokens or via the API Tokens endpoint.

Sign Out

DELETE /api/session Destroy the current session and clear the session cookie.
Session cookies are HttpOnly — client-side JavaScript cannot read them. This prevents cross-site scripting attacks from stealing credentials, but it also means you must use the DELETE endpoint (not client-side code) to sign out programmatically.