Skip to main content
The endpoints in this reference authenticate with the session of a signed-in Connie user, the same way the Connie app does. There’s no separate API token for them.
Treat your session like your password. It contains your sign-in, including a token that can start new sessions. Don’t paste it into shared tools, chat messages, tickets or screenshots, and never send it to support. To end every copied session, click your name in Connie → Logout: that signs you out everywhere.

Get your session

1

Sign in

Open connie.ai in Chrome, Edge or Firefox and sign in.
2

Open the developer tools

Press F12 (or Cmd+Option+I on Mac) and open the Network tab. Reload the page.
3

Copy the Cookie header

Click any request whose address starts with https://connie.ai/api/. Under Request Headers, find cookie and copy its whole value. It contains several cookies whose names start with __Host-sb- and end in -auth-token (sometimes split into .0 and .1 parts). Copy all of it.
4

Send it with each request

Add the header Cookie: <the value you copied> to every request.
In your request, open Headers and add a key Cookie with the copied value. Add the workspace parameter shown on the endpoint’s page (usually workspaceId) under Params.

How long a session lasts

  • The access part of the session expires after about an hour. The Connie app refreshes it for you in the browser, but these endpoints don’t refresh it.
  • When it expires, requests return 401 with {"error":"Unauthorized - please sign in","code":"SESSION_EXPIRED"}. Reload connie.ai in your browser and copy the Cookie header again.
  • Logging out of Connie ends the session immediately.
For anything that has to run unattended, use the MCP server with OAuth or a workspace API key instead. Those credentials don’t expire every hour and can be revoked on their own.

Choose the workspace

Pass the workspace on every request. Most endpoints take ?workspaceId=<id> in the query string or the x-workspace-id header; some use workspace_id, the path, or the JSON body instead. Each endpoint’s page in this reference shows the exact parameter. Your workspace ID is the code after connie.ai/ in your browser’s address bar (how to find it).
If you leave the workspace out, many endpoints don’t fail: they answer for the first workspace you joined. If you belong to more than one workspace, that looks like empty or wrong data with no error.

Where requests can come from

  • Postman, curl, scripts and servers: fine.
  • JavaScript on another website: blocked. Browser requests to https://connie.ai/api/ from any other site return 403 {"error":"Browser origin denied."}, and requests that change data from another site return “Cross-origin request blocked”. Call the API from a server or script instead.

What you can do

Requests run as you, with your permissions in that workspace. Endpoints that are owner/admin only in the app (such as billing and member management) refuse other roles with 403. Actions that cost credits are charged to the workspace exactly as in the app. See Credits.

Troubleshooting

Why: the Cookie header is missing or incomplete, or the session expired ("code":"SESSION_EXPIRED"). Fix: reload connie.ai, copy the whole Cookie header again (all parts) and resend.
Why: API keys only work with the MCP server at https://mcp.connie.ai, not with these endpoints. Fix: use the Cookie header here, or use MCP with your key. See API keys.
Why: you called the API from JavaScript on another website. Fix: call it from a server, script or Postman.
Why: the workspaceId is wrong, or you aren’t a member. Fix: check the ID in your address bar, or ask an admin to invite you.
Why: no workspaceId was sent, so the endpoint used the first workspace you joined. Fix: add ?workspaceId=<id> or the x-workspace-id header.