Skip to main content
POST
Mint a runtime session token

Authorizations

Authorization
string
header
required

An app API key, e.g. Authorization: Bearer sk_live_…. Secret (sk_) for writes/sessions; publishable (pk_) is read-only (browser-safe).

Body

application/json
worldId
string<uuid>
required

The world to run (its UUID, not the slug). Accepts a world you generated via the API, and ALSO a world you built in the web Studio: a Studio world's UUID is allowed when the key's account owns (authored) it, even though it has no app_id. See the 'Run a Studio world' guide.

playerIdentity
string

Your stable id for the end-user.

origin
string

The embedding origin; binds the token's aud and CSP frame-ancestors.

ttlSeconds
integer
default:300
Required range: 60 <= x <= 3600

Response

A session token

token
string

Short-lived signed token for the embed SDK.

expiresIn
integer

Seconds until expiry.

worldId
string<uuid>
slug
string | null
jti
string<uuid>