curl --request POST \
--url https://api2.rhombussystems.com/api/org/generateFederatedSessionToken \
--header 'Content-Type: application/json' \
--header 'x-auth-apikey: <api-key>' \
--header 'x-auth-scheme: <x-auth-scheme>' \
--data '
{
"deviceUUid": "AAAAAAAAAAAAAAAAAAAAAA.v0",
"domain": "https://app.example.com",
"durationSec": 3600
}
'import requests
url = "https://api2.rhombussystems.com/api/org/generateFederatedSessionToken"
payload = {
"deviceUUid": "AAAAAAAAAAAAAAAAAAAAAA.v0",
"domain": "https://app.example.com",
"durationSec": 3600
}
headers = {
"x-auth-scheme": "<x-auth-scheme>",
"x-auth-apikey": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'x-auth-scheme': '<x-auth-scheme>',
'x-auth-apikey': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
deviceUUid: 'AAAAAAAAAAAAAAAAAAAAAA.v0',
domain: 'https://app.example.com',
durationSec: 3600
})
};
fetch('https://api2.rhombussystems.com/api/org/generateFederatedSessionToken', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));HttpResponse<String> response = Unirest.post("https://api2.rhombussystems.com/api/org/generateFederatedSessionToken")
.header("x-auth-scheme", "<x-auth-scheme>")
.header("x-auth-apikey", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"deviceUUid\": \"AAAAAAAAAAAAAAAAAAAAAA.v0\",\n \"domain\": \"https://app.example.com\",\n \"durationSec\": 3600\n}")
.asString();{
"federatedSessionToken": "AAAAAAAAAAAAAAAAAAAAAA"
}Generate federated session token
Generate a federated session token login for organization
curl --request POST \
--url https://api2.rhombussystems.com/api/org/generateFederatedSessionToken \
--header 'Content-Type: application/json' \
--header 'x-auth-apikey: <api-key>' \
--header 'x-auth-scheme: <x-auth-scheme>' \
--data '
{
"deviceUUid": "AAAAAAAAAAAAAAAAAAAAAA.v0",
"domain": "https://app.example.com",
"durationSec": 3600
}
'import requests
url = "https://api2.rhombussystems.com/api/org/generateFederatedSessionToken"
payload = {
"deviceUUid": "AAAAAAAAAAAAAAAAAAAAAA.v0",
"domain": "https://app.example.com",
"durationSec": 3600
}
headers = {
"x-auth-scheme": "<x-auth-scheme>",
"x-auth-apikey": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'x-auth-scheme': '<x-auth-scheme>',
'x-auth-apikey': '<api-key>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
deviceUUid: 'AAAAAAAAAAAAAAAAAAAAAA.v0',
domain: 'https://app.example.com',
durationSec: 3600
})
};
fetch('https://api2.rhombussystems.com/api/org/generateFederatedSessionToken', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));HttpResponse<String> response = Unirest.post("https://api2.rhombussystems.com/api/org/generateFederatedSessionToken")
.header("x-auth-scheme", "<x-auth-scheme>")
.header("x-auth-apikey", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"deviceUUid\": \"AAAAAAAAAAAAAAAAAAAAAA.v0\",\n \"domain\": \"https://app.example.com\",\n \"durationSec\": 3600\n}")
.asString();{
"federatedSessionToken": "AAAAAAAAAAAAAAAAAAAAAA"
}Authorizations
Your Rhombus API key. Must be accompanied by the x-auth-scheme header set to api-token (or partner-api-token for partner endpoints).
Headers
Authentication scheme identifier. Use api-token for standard API key authentication, partner-api-token for partner API key authentication. Must be paired with the x-auth-apikey header containing your API key.
api-token, api, partner-api-token, partner-api Body
Request object for generating a federated session token.
RUUID with optional appended facet information
"AAAAAAAAAAAAAAAAAAAAAA.v0"
Optional. The origin that is allowed to use the federated token, specified as a fully qualified URL (scheme and host, plus a port if non-default). On the browser API the value is applied as a CORS allowed-origin, and must match the browser's Origin exactly. For media requests, which are not governed by CORS, the request's Referer is parsed and compared against this value on origin (scheme, host and port) — so the Referer may carry a path and query and still match. Omit the field to leave the token unrestricted, which is required for clients that cannot send a Referer, such as native and on-prem players. This restricts where a token can be used from a browser; it is not a substitute for treating the token as a bearer credential. Both Origin and Referer are supplied by the client, so a non-browser caller holding the token can send either value at will. Use a short durationSec, and deviceUUid where the token only needs one camera's media, to limit a token that has been extracted.
"https://app.example.com"
Duration of the federated session token in seconds
3600
Response
OK
Response object containing the generated federated session token.
base 64 (url-safe) uuid string
"AAAAAAAAAAAAAAAAAAAAAA"