> ## Documentation Index
> Fetch the complete documentation index at: https://docs.connie.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> How to authenticate API requests with your Connie browser session, how long it lasts, and how to keep it safe.

The endpoints in this reference authenticate with the **session of a signed-in Connie user**, the same way the Connie app does. There's no separate API token for them.

<Warning>
  **Treat your session like your password.** It contains your sign-in, including a token that can start new sessions. Don't paste it into shared tools, chat messages, tickets or screenshots, and never send it to support. To end every copied session, click your name in Connie → **Logout**: that signs you out everywhere.
</Warning>

## Get your session

<Steps>
  <Step title="Sign in">
    Open [connie.ai](https://connie.ai) in Chrome, Edge or Firefox and sign in.
  </Step>

  <Step title="Open the developer tools">
    Press **F12** (or **Cmd+Option+I** on Mac) and open the **Network** tab. Reload the page.
  </Step>

  <Step title="Copy the Cookie header">
    Click any request whose address starts with `https://connie.ai/api/`. Under **Request Headers**, find **cookie** and copy its whole value. It contains several cookies whose names start with `__Host-sb-` and end in `-auth-token` (sometimes split into `.0` and `.1` parts). Copy all of it.
  </Step>

  <Step title="Send it with each request">
    Add the header `Cookie: <the value you copied>` to every request.
  </Step>
</Steps>

<Tabs>
  <Tab title="Postman">
    In your request, open **Headers** and add a key `Cookie` with the copied value. Add the workspace parameter shown on the endpoint's page (usually `workspaceId`) under **Params**.
  </Tab>

  <Tab title="curl">
    ```bash theme={null}
    curl "https://connie.ai/api/notifications?workspace_id=YOUR_WORKSPACE_ID" \
      -H "Cookie: PASTE_THE_COOKIE_VALUE_HERE"
    ```
  </Tab>
</Tabs>

## How long a session lasts

* The access part of the session expires after **about an hour**. The Connie app refreshes it for you in the browser, but these endpoints don't refresh it.
* When it expires, requests return `401` with `{"error":"Unauthorized - please sign in","code":"SESSION_EXPIRED"}`. Reload connie.ai in your browser and copy the Cookie header again.
* Logging out of Connie ends the session immediately.

For anything that has to run unattended, use the [MCP server](/mcp/overview) with OAuth or a workspace [API key](/developers/api-keys) instead. Those credentials don't expire every hour and can be revoked on their own.

## Choose the workspace

Pass the workspace on every request. Most endpoints take `?workspaceId=<id>` in the query string or the `x-workspace-id` header; some use `workspace_id`, the path, or the JSON body instead. Each endpoint's page in this reference shows the exact parameter. Your workspace ID is the code after `connie.ai/` in your browser's address bar ([how to find it](/navigating-connie#links-and-your-workspace-id)).

<Warning>
  If you leave the workspace out, many endpoints don't fail: they answer for the **first workspace you joined**. If you belong to more than one workspace, that looks like empty or wrong data with no error.
</Warning>

## Where requests can come from

* **Postman, curl, scripts and servers:** fine.
* **JavaScript on another website:** blocked. Browser requests to `https://connie.ai/api/` from any other site return `403` `{"error":"Browser origin denied."}`, and requests that change data from another site return "Cross-origin request blocked". Call the API from a server or script instead.

## What you can do

Requests run as you, with your permissions in that workspace. Endpoints that are owner/admin only in the app (such as billing and member management) refuse other roles with `403`. Actions that cost credits are charged to the workspace exactly as in the app. See [Credits](/billing/credits).

## Troubleshooting

<AccordionGroup>
  <Accordion title="401 Unauthorized - please sign in">
    **Why:** the Cookie header is missing or incomplete, or the session expired (`"code":"SESSION_EXPIRED"`). **Fix:** reload connie.ai, copy the whole Cookie header again (all parts) and resend.
  </Accordion>

  <Accordion title="401 when I send my sk_ API key">
    **Why:** API keys only work with the MCP server at `https://mcp.connie.ai`, not with these endpoints. **Fix:** use the Cookie header here, or use MCP with your key. See [API keys](/developers/api-keys).
  </Accordion>

  <Accordion title="403 Browser origin denied.">
    **Why:** you called the API from JavaScript on another website. **Fix:** call it from a server, script or Postman.
  </Accordion>

  <Accordion title="403 User is not a member of this workspace">
    **Why:** the `workspaceId` is wrong, or you aren't a member. **Fix:** check the ID in your address bar, or ask an admin to invite you.
  </Accordion>

  <Accordion title="The response is empty or shows another workspace's data">
    **Why:** no `workspaceId` was sent, so the endpoint used the first workspace you joined. **Fix:** add `?workspaceId=<id>` or the `x-workspace-id` header.
  </Accordion>
</AccordionGroup>

## Related

* [Errors and limits](/api-reference/errors)
* [API keys](/developers/api-keys) — for the MCP server
* [Build on Connie](/developers/overview)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.