Skip to main content
GET
/
v2
/
session-config
Retrieve session configuration
curl --request GET \
  --url https://{projectId}.frontendapi.corbado.io/v2/session-config \
  --header 'Authorization: Bearer <token>'
import requests

url = "https://{projectId}.frontendapi.corbado.io/v2/session-config"

headers = {"Authorization": "Bearer <token>"}

response = requests.get(url, headers=headers)

print(response.text)
const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};

fetch('https://{projectId}.frontendapi.corbado.io/v2/session-config', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));
<?php

$curl = curl_init();

curl_setopt_array($curl, [
CURLOPT_URL => "https://{projectId}.frontendapi.corbado.io/v2/session-config",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "GET",
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>"
],
]);

$response = curl_exec($curl);
$err = curl_error($curl);

curl_close($curl);

if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}
package main

import (
"fmt"
"net/http"
"io"
)

func main() {

url := "https://{projectId}.frontendapi.corbado.io/v2/session-config"

req, _ := http.NewRequest("GET", url, nil)

req.Header.Add("Authorization", "Bearer <token>")

res, _ := http.DefaultClient.Do(req)

defer res.Body.Close()
body, _ := io.ReadAll(res.Body)

fmt.Println(string(body))

}
HttpResponse<String> response = Unirest.get("https://{projectId}.frontendapi.corbado.io/v2/session-config")
.header("Authorization", "Bearer <token>")
.asString();
require 'uri'
require 'net/http'

url = URI("https://{projectId}.frontendapi.corbado.io/v2/session-config")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Get.new(url)
request["Authorization"] = 'Bearer <token>'

response = http.request(request)
puts response.read_body
{
  "useSessionManagement": true,
  "shortSessionCookieConfig": {
    "domain": "<string>",
    "secure": true,
    "path": "<string>",
    "lifetimeSeconds": 123
  },
  "sessionTokenCookieConfig": {
    "domain": "<string>",
    "secure": true,
    "path": "<string>",
    "lifetimeSeconds": 123
  },
  "frontendApiUrl": "<string>"
}

Authorizations

Authorization
string
header
required

After a user logs in successfully, a session is created and a JWT token is returned. This token represents the user's authenticated session. It must be included in the Authorization header as a Bearer token for all protected endpoints:

Authorization: Bearer <your-token>

The server will validate this token to authorize access.

Response

200 - application/json

Session configuration settings.

useSessionManagement
boolean
required
frontendApiUrl
string