Groundeddocs
ReferencePublic agents and widget

Start an anonymous session with a public agent (sets the session cookie)

POST/v1/public/sessions

The cookie (grounded_anon_{agentId without dashes}, HttpOnly, path /v1/public) holds a random secret stored only as a digest, with the agent, the caller's /24 (IPv4) or /48 (IPv6) prefix and a user-agent hash. It is SameSite=None; Secure; Partitioned for the widget (on HTTPS) and SameSite=Lax for the public page, and lasts ANON_SESSION_TTL after the last use. With a publishable key (the widget) the request's Origin (when cross-origin) and embedOrigin must be allowed by the key (403 origin_not_allowed), and at least one must be given. CAPTCHA runs when configured (403 captcha_failed). Errors: 503 public_disabled, 404 for agents that are not public, 403 agent_disabled (kill switch), 403 invalid_publishable_key, 429/503 from the guardrails.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/v1/public/sessions" \  -H "Content-Type: application/json" \  -d '{    "agentId": "bc309ecf-5f66-4057-93c5-6611cc9cb7b2"  }'
{  "data": {    "agentId": "bc309ecf-5f66-4057-93c5-6611cc9cb7b2",    "channel": "public",    "expiresAt": "2019-08-24T14:15:22Z"  }}