openapi: 3.2.0 info: title: login Tokens API version: '' servers: - url: https://{tenant}.{region}.qlikcloud.com variables: region: default: us description: The region the tenant is hosted in tenant: default: your-tenant description: Name of the tenant that will be called tags: - name: Tokens paths: /login/jwt-session: post: tags: - Tokens summary: Exchange a token responses: '200': content: application/json: schema: type: object headers: Set-Cookie: schema: type: string example: eas.sid=spn3PWVdGDmSs2NH6kEgpIwZft2utI2m;eas.sid.sig=s43MYzD54Z7NsayOdPD0pXm24fc;_csrfToken=jQrrL9KC-OomYaTw2vY8B2sR1uddfwH2q_js;_csrfToken.sig=GRB6I20vR-tlgmFceq8a9mSGyCE description: session cookie and CSRF token along with their signatures description: Successfully exchanged JWT for session. '401': content: application/json: schema: $ref: '#/components/schemas/Errors' description: Unauthorized. description: 'Exchanges a token in the form of a user JWT for a session cookie. The JWT should be securely signed with an algorithm other than HS, and it should contain the following claims: 1. iss: identifies the principal that issued the JWT; it must match the issuer in the IDP definition. 2. aud: identifies the recipients of the JWT, which in this case is "qlik.api/login/jwt-session". 3. sub: identifies the subject of the JWT. 4. subType: the type of identifier the sub represents, which in this case is "user". 5. name: the name of the user. 6. email: the email address of the user. 7. email_verified: a claim indicating to Qlik that the JWT source has verified that the email address belongs to the subject. 9. jti: JWT ID; it should be unique for each consumed JWT token. 10. iat: identifies the time at which the JWT was issued. 11. nbf: identifies the starting time on which the JWT is accepted. The current unix time must be passed this value. 12. exp: identifies the expiration time after which the JWT is not accepted. 13. keyid: identifies the KeyID used to sign the JWT; it must match the KeyID in the IDP definition. And the time window between exp and nbf should not exceed 1 hour.' x-qlik-visibility: public x-qlik-stability: stable x-qlik-deprecated: false x-qlik-tier: tier: '2' limit: 100 operationId: postLoginJwtSession x-operation-id-source: derived components: schemas: Errors: type: object properties: errors: type: array items: $ref: '#/components/schemas/Error' description: List of errors and their properties. description: A representation of the errors encountered from the HTTP request. Error: type: object required: - code - title properties: code: type: string description: The error code. meta: type: object description: Non-standard information about the error. title: type: string description: The error title. detail: type: string description: The detailed error message. status: type: string description: The http status code. description: An error object.