> ## Documentation Index
> Fetch the complete documentation index at: https://api-docs.rhombus.community/llms.txt
> Use this file to discover all available pages before exploring further.

# Generate federated session token

> Generate a federated session token login for organization



## OpenAPI

````yaml https://api2.rhombussystems.com/api/openapi/public.json post /api/org/generateFederatedSessionToken
openapi: 3.0.1
info:
  contact:
    email: developer@rhombussystems.com
  description: >-
    This API is for use by Rhombus customers and partners.


    ## Authentication


    All requests require two headers:

    - `x-auth-scheme` — The authentication scheme identifier. Use `api-token`
    for standard API key auth, or `partner-api-token` for partner API auth.

    - `x-auth-apikey` — Your Rhombus API key.


    Example:

    ```

    POST /api/camera/getMinimalCameraStateList

    x-auth-scheme: api-token

    x-auth-apikey: YOUR_API_KEY

    Content-Type: application/json

    ```
  title: Rhombus API
  version: '1.0'
servers:
  - description: Production Server
    url: https://api2.rhombussystems.com
security:
  - ApiKeyAuth: []
paths:
  /api/org/generateFederatedSessionToken:
    post:
      tags:
        - Org Webservice
      summary: Generate federated session token
      description: Generate a federated session token login for organization
      operationId: generateFederatedSessionToken
      parameters:
        - description: >-
            Authentication scheme identifier. Use `api-token` for standard API
            key authentication, `partner-api-token` for partner API key
            authentication. Must be paired with the `x-auth-apikey` header
            containing your API key.
          example: api-token
          in: header
          name: x-auth-scheme
          required: true
          schema:
            type: string
            default: api-token
            enum:
              - api-token
              - api
              - partner-api-token
              - partner-api
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Org_GenerateFederatedSessionTokenRequest'
      responses:
        '200':
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Org_GenerateFederatedSessionTokenResponse'
          description: OK
components:
  schemas:
    Org_GenerateFederatedSessionTokenRequest:
      type: object
      description: Request object for generating a federated session token.
      properties:
        deviceUUid:
          type: string
          format: DeviceFacetUuid
          description: RUUID with optional appended facet information
          example: AAAAAAAAAAAAAAAAAAAAAA.v0
          nullable: true
        domain:
          type: string
          description: >-
            Optional. The origin that is allowed to use the federated token,
            specified as a fully qualified URL (scheme and host, plus a port if
            non-default). On the browser API the value is applied as a CORS
            allowed-origin, and must match the browser's Origin exactly. For
            media requests, which are not governed by CORS, the request's
            Referer is parsed and compared against this value on origin (scheme,
            host and port) — so the Referer may carry a path and query and still
            match. Omit the field to leave the token unrestricted, which is
            required for clients that cannot send a Referer, such as native and
            on-prem players. This restricts where a token can be used from a
            browser; it is not a substitute for treating the token as a bearer
            credential. Both Origin and Referer are supplied by the client, so a
            non-browser caller holding the token can send either value at will.
            Use a short durationSec, and deviceUUid where the token only needs
            one camera's media, to limit a token that has been extracted.
          example: https://app.example.com
          nullable: true
        durationSec:
          type: integer
          format: int32
          description: Duration of the federated session token in seconds
          example: 3600
          nullable: true
    Org_GenerateFederatedSessionTokenResponse:
      type: object
      description: Response object containing the generated federated session token.
      properties:
        federatedSessionToken:
          type: string
          format: RUUID
          description: base 64 (url-safe) uuid string
          example: AAAAAAAAAAAAAAAAAAAAAA
          nullable: true
  securitySchemes:
    ApiKeyAuth:
      description: >-
        Your Rhombus API key. Must be accompanied by the `x-auth-scheme` header
        set to `api-token` (or `partner-api-token` for partner endpoints).
      in: header
      name: x-auth-apikey
      type: apiKey

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.