CAIN-42 CAIN Studio

API reference · Trust Fabric

Exchange an API key for a short-lived browser session

POST /fabric/identity/sessions

Last reviewed 2026-10-02

POST /fabric/identity/sessions

So a browser never has to hold the raw key.

The workbench used to keep a full-privilege, non-expiring credential in localStorage. This is read-scoped and expires, so an injected script gets something far less useful and for far less long.

Responses

StatusMeaningBody
200Successful ResponseJSON
422Validation ErrorHTTPValidationError
401No key, or a key that is not validJSON detail
429Rate limit for your plan reached; retry after the Retry-After secondsJSON detail

Try it

This call changes data in the account the key belongs to.

The request goes from your browser straight to this site. Your key is not stored unless you tick the box, and then only in this tab's session storage.

Code

curl -sS -X POST 'https://cainstudio.online/fabric/identity/sessions' \
  -H "X-API-Key: $CAIN_API_KEY"

Schemas used

HTTPValidationError · ValidationError

← Verify an Ed25519 signature against a registered principal · all 79 Trust Fabric calls · Inspect the session token in use →

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem