Console Auth Flow
StateSet Console supports multiple auth modes and issues a signed session cookie for protected routes.Supported Modes
- Email/password: proxied to Sandbox API login
- API key: validated locally in the console
- Token refresh: re-issues a session using an existing JWT
- Dev login: optional in non-production
Session Cookies
session: signed JWT containingorgIdanduserIdsandbox_session: sandbox token used for Sandbox API callsapi_key: stored API key for API-key auth
Typical Flow
- Client posts credentials to
/api/auth/login. - Console validates via Sandbox API or local API key logic.
- Console sets session cookies and returns user/org metadata.