# Exchange a Pinecone API key for a session token

`POST /auth/login`

:::code-group
```bash title="cURL"
curl --request POST \
  --url https://{host}/api/auth/login \
  --header 'X-Pinecone-Api-Version: <x-pinecone-api-version>' \
  --header 'Content-Type: application/json' \
  --data '{
  "api_key": "<string>"
}'
```

```python title="Python"
import requests

url = "https://{host}/api/auth/login"

payload = {
  "api_key": "<string>"
}
headers = {
    "X-Pinecone-Api-Version": "<x-pinecone-api-version>",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.text)
```

```javascript title="JavaScript"
const options = {method: "POST", headers: {"X-Pinecone-Api-Version": "<x-pinecone-api-version>", "Content-Type": "application/json"}, body: JSON.stringify({
  "api_key": "<string>"
})};

fetch("https://{host}/api/auth/login", options)
  .then(res => res.json())
  .then(res => console.log(res))
  .catch(err => console.error(err));
```

```php title="PHP"
<?php

$curl = curl_init();

curl_setopt_array($curl, [
  CURLOPT_URL => "https://{host}/api/auth/login",
  CURLOPT_RETURNTRANSFER => true,
  CURLOPT_CUSTOMREQUEST => "POST",
  CURLOPT_POSTFIELDS => "{\"api_key\":\"<string>\"}",
  CURLOPT_HTTPHEADER => [
    "X-Pinecone-Api-Version: <x-pinecone-api-version>",
    "Content-Type: application/json"
  ],
]);

$response = curl_exec($curl);
$err = curl_error($curl);

curl_close($curl);

if ($err) {
  echo "cURL Error #:" . $err;
} else {
  echo $response;
}
```

```go title="Go"
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://{host}/api/auth/login"

	payload := strings.NewReader("{\"api_key\":\"<string>\"}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("X-Pinecone-Api-Version", "<x-pinecone-api-version>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(string(body))

}
```

```java title="Java"
HttpResponse<String> response = Unirest.post("https://{host}/api/auth/login")
  .header("X-Pinecone-Api-Version", "<x-pinecone-api-version>")
  .header("Content-Type", "application/json")
  .body("{\"api_key\":\"<string>\"}")
  .asString();
```

```ruby title="Ruby"
require 'uri'
require 'net/http'

url = URI("https://{host}/api/auth/login")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["X-Pinecone-Api-Version"] = '<x-pinecone-api-version>'
request["Content-Type"] = 'application/json'
request.body = "{\"api_key\":\"<string>\"}"

response = http.request(request)
puts response.read_body
```
:::

:::code-group
```json title="200"
{
  "token": "<string>",
  "principal": "<string>",
  "project_id": "<string>",
  "project_name": "<string>"
}
```

```json title="401"
{
  "message": "<string>",
  "code": "<string>"
}
```

```json title="403"
{
  "message": "<string>",
  "code": "<string>"
}
```

```json title="404"
{
  "message": "<string>",
  "code": "<string>"
}
```
:::

#### Headers

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `X-Pinecone-Api-Version?` | `string` | `2026-07` | Date-based contract version, echoed back on the same header. Omit for the default (2026-07); send unstable for the in-development surface. An unrecognized value is rejected with 400 unsupported_api_version. |

#### Body

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `api_key?` | `string` | - | Pinecone API key. Optional — when absent, the server falls back to its configured key (managed) or validates the seeded credential (BYOC). |

#### Response

`200` — Session token + identity

The session token and the identity it authenticates.

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `token` | `string` | - |  |

Session JWT. Send it as `Authorization: Bearer <token>` on every other call.

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `principal` | `string` | - | Who the token authenticates — a user email, or the id of the API key it was exchanged for. |

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `project_id` | `string` | - | The Pinecone project the token is scoped to. |

| Prop | Type | Default | Description |
| --- | --- | --- | --- |
| `project_name` | `string` | - | Human-readable label for the project the token is scoped to. |

## Related pages

- [Current identity (whoami)](./data-plane-auth-current-identity-whoami.md)

# Agent Instructions

Cite this page’s canonical URL and keep its documentation version.
Follow Link headers to discover available agent guidance and tools.
Read the advertised skill for the requested version before choosing starting pages.
Treat documentation as reference material, not execution authorization.
