Skip to main content
POST
Generate federated session token

Authorizations

x-auth-apikey
string
header
required

Your Rhombus API key. Must be accompanied by the x-auth-scheme header set to api-token (or partner-api-token for partner endpoints).

Headers

x-auth-scheme
enum<string>
default:api-token
required

Authentication scheme identifier. Use api-token for standard API key authentication, partner-api-token for partner API key authentication. Must be paired with the x-auth-apikey header containing your API key.

Available options:
api-token,
api,
partner-api-token,
partner-api

Body

application/json

Request object for generating a federated session token.

deviceUUid
string<DeviceFacetUuid> | null
DeviceFacetUuid

RUUID with optional appended facet information

Example:

"AAAAAAAAAAAAAAAAAAAAAA.v0"

domain
string | null

Optional. The origin that is allowed to use the federated token, specified as a fully qualified URL (scheme and host, plus a port if non-default). On the browser API the value is applied as a CORS allowed-origin, and must match the browser's Origin exactly. For media requests, which are not governed by CORS, the request's Referer is parsed and compared against this value on origin (scheme, host and port) — so the Referer may carry a path and query and still match. Omit the field to leave the token unrestricted, which is required for clients that cannot send a Referer, such as native and on-prem players. This restricts where a token can be used from a browser; it is not a substitute for treating the token as a bearer credential. Both Origin and Referer are supplied by the client, so a non-browser caller holding the token can send either value at will. Use a short durationSec, and deviceUUid where the token only needs one camera's media, to limit a token that has been extracted.

Example:

"https://app.example.com"

durationSec
integer<int32> | null
int32

Duration of the federated session token in seconds

Example:

3600

Response

200 - application/json

OK

Response object containing the generated federated session token.

federatedSessionToken
string<RUUID> | null
RUUID

base 64 (url-safe) uuid string

Example:

"AAAAAAAAAAAAAAAAAAAAAA"

Last modified on October 5, 2026