SG Ground Truth

POST /internal_api/session

post_internal_api_session

Renews the session behind the _session_id cookie: {"message": "OK"} and expiresAt moves to now plus the site's expiry window. 401 without the cookie.

API

The renew half of the web app's session checker. A client that wants a session to outlive the site's idle window calls this, or spends the session token at the token endpoint, before the window closes.

Params

part value
path <site>/internal_api/session
Cookie _session_id=<session token>
body none

Sample requests

r = requests.post(f"{site}/internal_api/session", cookies={"_session_id": session_token}, timeout=30)
{"message": "OK"}

GET /internal_api/session read back before and after, on the probed site:

before  expiresAt 1788975773
after   expiresAt 1788975774      now + 86400

Response codes

status when
200 renewed
401 no _session_id cookie, or one the site no longer holds

Edge cases

  • It is not needed to keep a REST client alive: minting a bearer with grant_type=session_token moves expiresAt by the same amount, recorded at most once every 300s (052_app_session_launcher). It is the call for a client that holds a session token and has nothing to mint for a while.
  • The web app calls it only when the page saw input in the last three minutes; a client renewing on a timer keeps a session alive indefinitely, which is the behaviour the site's User Session Expiry preference exists to bound. Renew on use, not on a clock.

Every entry on this site is the output of a probe in probes/. The corpus is generated by running those probes against a live Flow Production Tracking site, not written from memory.

Not affiliated with or endorsed by Autodesk. Flow Production Tracking is their product; this is an independent record of how its REST API answers.