> ## Documentation Index
> Fetch the complete documentation index at: https://docs.b3os.org/llms.txt
> Use this file to discover all available pages before exploring further.

# Mint a per-user app session token for a login-required deep-agent artifact

Mints a per-user app token for the signed-in viewer opening a login-required deep-agent artifact. Authed as the b3 user; the viewer's id + active org come from the auth context, not the body. The server resolves the artifact's org from the :appId (deep-agent run id), verifies the workflow is in it and the viewer is acting within it, then signs a token carrying the viewer's id.

` POST /v1/app-gateway/{appId}/session `

Mint a per-user app session token for a login-required deep-agent artifact

Mints a per-user app token for the signed-in viewer opening a login-required deep-agent artifact. Authed as the b3 user; the viewer's id + active org come from the auth context, not the body. The server resolves the artifact's org from the :appId (deep-agent run id), verifies the workflow is in it and the viewer is acting within it, then signs a token carrying the viewer's id.

## Parameters

### ` appId ` (path, required)

Deep-agent run id (app id)

- ` value `: type ` string `

## Request body (required)

Content type: ` application/json `

Viewer token mint params

- ` value `: type ` unknown `

  - ` oneOf alternative 1 `: type ` object `

  - ` oneOf alternative 2 `: type ` object `

    - ` workflowId `: type ` string `

## Responses

### ` 200 ` — OK

Content type: ` application/json `

- ` value `: type ` object `

  - ` exp `: type ` string `

  - ` token `: type ` string `

### ` 401 ` — Unauthorized

Content type: ` application/json `

- ` value `: type ` object `

  - ` code `: type ` integer `

  - ` details `: type ` array `

    - ` array item `: type ` unknown `

  - ` message `: type ` string `

  - ` requestId `: type ` string `

### ` 403 ` — Forbidden

Content type: ` application/json `

- ` value `: type ` object `

  - ` code `: type ` integer `

  - ` details `: type ` array `

    - ` array item `: type ` unknown `

  - ` message `: type ` string `

  - ` requestId `: type ` string `

### ` 404 ` — Not Found

Content type: ` application/json `

- ` value `: type ` object `

  - ` code `: type ` integer `

  - ` details `: type ` array `

    - ` array item `: type ` unknown `

  - ` message `: type ` string `

  - ` requestId `: type ` string `

## Request examples

### cURL

```curl
curl -X POST 'https://api.example.com/v1/app-gateway/string/session' \
  -H 'Authorization: Bearer YOUR_API_TOKEN' \
  -H 'Content-Type: application/json' \
  -d '{}'
```

### JavaScript

```javascript
const response = await fetch('https://api.example.com/v1/app-gateway/string/session', {
  method: 'POST',
  headers: {
      "Authorization": "Bearer YOUR_API_TOKEN",
      "Content-Type": "application/json"
  },
  body: JSON.stringify({})
});

const data = await response.json();
console.log(data);
```

### Python

```python
import requests

headers = {
    'Authorization': 'Bearer YOUR_API_TOKEN'
}

response = requests.post('https://api.example.com/v1/app-gateway/string/session', headers=headers, json={})
print(response.json())
```

### Go

```go
package main

import (
	"fmt"
	"io"
	"net/http"
	"strings"
)

func main() {
	body := strings.NewReader(`{}`)
	req, _ := http.NewRequest("POST", "https://api.example.com/v1/app-gateway/string/session", body)
	req.Header.Set("Authorization", "Bearer YOUR_API_TOKEN")
	req.Header.Set("Content-Type", "application/json")

	resp, _ := http.DefaultClient.Do(req)
	defer resp.Body.Close()
	result, _ := io.ReadAll(resp.Body)
	fmt.Println(string(result))
}
```