Spoar
Dev widget

Start the dev widget

GET
/v2/widget/session

Called from the customer site with credentials: include. The project is the one whose allowedOrigins lists the Origin header; the caller needs the admin session cookie and admin rights on that project. Answers a widget token (wt_, 15 minutes, admin scope, this project only) for the other widget reads, so the cookie is never sent again. Call it again to refresh. CORS allows credentials on this route for any origin a project lists.

Authorization

session
__Secure-ra.session_token<token>

The admin session cookie set by GitHub sign-in at /v2/auth. The browser sends it on its own.

In: cookie

Response Body

application/json

application/json

application/json

application/json

application/json

application/json

application/json

application/json

curl -X GET "https://example.com/v2/widget/session"
{  "project": "noorderlicht-lease",  "access": "admin",  "user": {    "id": "u_01j8z7",    "name": "Remco"  },  "release": "2026.10.03-a1",  "token": "wt_xxxxxxxxxxxxxxxx",  "expiresAt": "2026-10-03T14:32:00.000Z",  "features": {    "logs": true,    "speed": true,    "issues": true  }}