POST
Refresh the session token

Authorizations

Authorization
string
header
required

Developer session token from POST /v1/auth/login or POST /v1/auth/register. Valid 7 days.

Authenticates the developer control plane. It also reaches the server and build endpoints, which a dashboard has to drive and which no session can otherwise call: an API key's value is returned once, at mint, so nothing can read back a key for an existing project. On those endpoints a session names its project with project_id, or is resolved from the resource it addresses, and is always checked against the account that owns it.

It reaches no player-facing game endpoint.

Response

A new session. The previous token is now dead.

An authenticated developer session. Send token as Authorization: Bearer <token> on every developer endpoint.

Tokens last 7 days. POST /v1/auth/refresh issues a new one and immediately invalidates the token used to request it, so a client holds exactly one valid token at a time.

token
string
required

JWT bearer token. Store it where a password would go, not in logs.

Example:

"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."

token_type
string
required
Allowed value: "Bearer"
expires_at
string<date-time>
required

7 days after issue.

Example:

"2026-09-28T14:00:00Z"

account
object
required

A developer account. One human, one login, one Stripe customer.