BeeraSafe

Authentication

Session-cookie auth for every API call, and what to do when a request returns 401.

Last updated · September 2026

On this page

All APIs authenticate with the same signed session cookie the web app uses, or with a CLI Bearer token. Sign in through the normal flow, keep the cookie, and send it with each request. Terminal callers mint a token once via POST /api/cli/token — see Bolt CLI.

Making an authenticated request

cURL with a session cookiebash
curl https://your-domain.com/api/auth/me \
  -H 'Cookie: bolt_session=<session-token>'
cURL with a CLI tokenbash
curl https://your-domain.com/api/dashboard/stats \
  -H 'Authorization: Bearer <cli-token>'
JavaScript (same origin)javascript
const res = await fetch("/api/auth/me", { credentials: "include" });
const me = await res.json();
// { authenticated: true, email, role, isAdmin, products, tokenBalance }

When auth fails

StatusMeaningWhat to do
401Missing, expired, or revoked session.Sign in again and retry with a fresh cookie.
403Signed in, but lacking permission (e.g. non-admin on an admin route, or non-member on an org route).Check roles and organization membership.
Keep tokens server-side
The session cookie is HttpOnly in the browser. Never copy session tokens into client-side logs, URLs, or error reports.