> ## Documentation Index
> Fetch the complete documentation index at: https://allhandsai-chore-regenerate-agent-sdk-openapi.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Create Workspace Session

> Mint a workspace-scoped session cookie.

Caller must already be authenticated by the ``X-Session-API-Key``
header (enforced by the parent router's dependency). The cookie value
is the validated session API key itself; it is HttpOnly so JS in
workspace HTML cannot read it back.



## OpenAPI

````yaml /openapi/agent-sdk.json post /api/auth/workspace-session
openapi: 3.1.0
info:
  description: OpenHands Agent Server - REST/WebSocket interface for OpenHands AI Agent
  title: OpenHands Agent Server
  version: 1.52.0
servers: []
security: []
paths:
  /api/auth/workspace-session:
    post:
      tags:
        - Auth
      summary: Create Workspace Session
      description: |-
        Mint a workspace-scoped session cookie.

        Caller must already be authenticated by the ``X-Session-API-Key``
        header (enforced by the parent router's dependency). The cookie value
        is the validated session API key itself; it is HttpOnly so JS in
        workspace HTML cannot read it back.
      operationId: create_workspace_session_api_auth_workspace_session_post
      responses:
        '204':
          description: Cookie set
        '401':
          description: Missing or invalid X-Session-API-Key header
      security:
        - APIKeyHeader: []
components:
  securitySchemes:
    APIKeyHeader:
      in: header
      name: X-Session-API-Key
      type: apiKey

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.