Dev widget
Start the dev widget
GET
Called from the customer site with credentials: include. The project is the one whose allowedOrigins lists the Origin header; the caller needs the admin session cookie and admin rights on that project. Answers a widget token (wt_, 15 minutes, admin scope, this project only) for the other widget reads, so the cookie is never sent again. Call it again to refresh. CORS allows credentials on this route for any origin a project lists.
Authorization
session __Secure-ra.session_token<token>
The admin session cookie set by GitHub sign-in at /v2/auth. The browser sends it on its own.
In: cookie
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
application/json
application/json
curl -X GET "https://example.com/v2/widget/session"{ "project": "noorderlicht-lease", "access": "admin", "user": { "id": "u_01j8z7", "name": "Remco" }, "release": "2026.10.03-a1", "token": "wt_xxxxxxxxxxxxxxxx", "expiresAt": "2026-10-03T14:32:00.000Z", "features": { "logs": true, "speed": true, "issues": true }}