Exchange a Pinecone API key for a session token
Exchange a Pinecone API key for the session token every other endpoint expects. Send the token as a bearer credential.
POST /auth/login
curl --request POST \
--url https://{host}/api/auth/login \
--header 'X-Pinecone-Api-Version: <x-pinecone-api-version>' \
--header 'Content-Type: application/json' \
--data '{
"api_key": "<string>"
}'import requests
url = "https://{host}/api/auth/login"
payload = {
"api_key": "<string>"
}
headers = {
"X-Pinecone-Api-Version": "<x-pinecone-api-version>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {method: "POST", headers: {"X-Pinecone-Api-Version": "<x-pinecone-api-version>", "Content-Type": "application/json"}, body: JSON.stringify({
"api_key": "<string>"
})};
fetch("https://{host}/api/auth/login", options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://{host}/api/auth/login",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => "{\"api_key\":\"<string>\"}",
CURLOPT_HTTPHEADER => [
"X-Pinecone-Api-Version: <x-pinecone-api-version>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://{host}/api/auth/login"
payload := strings.NewReader("{\"api_key\":\"<string>\"}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-Pinecone-Api-Version", "<x-pinecone-api-version>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://{host}/api/auth/login")
.header("X-Pinecone-Api-Version", "<x-pinecone-api-version>")
.header("Content-Type", "application/json")
.body("{\"api_key\":\"<string>\"}")
.asString();require 'uri'
require 'net/http'
url = URI("https://{host}/api/auth/login")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-Pinecone-Api-Version"] = '<x-pinecone-api-version>'
request["Content-Type"] = 'application/json'
request.body = "{\"api_key\":\"<string>\"}"
response = http.request(request)
puts response.read_body{
"token": "<string>",
"principal": "<string>",
"project_id": "<string>",
"project_name": "<string>"
}{
"message": "<string>",
"code": "<string>"
}{
"message": "<string>",
"code": "<string>"
}{
"message": "<string>",
"code": "<string>"
}Headers
Section titled “Headers”X-Pinecone-Api-Version?stringDate-based contract version, echoed back on the same header. Omit for the default (2026-07); send unstable for the in-development surface. An unrecognized value is rejected with 400 unsupported_api_version.
api_key?stringPinecone API key. Optional — when absent, the server falls back to its configured key (managed) or validates the seeded credential (BYOC).
Response
Section titled “Response”200 — Session token + identity
The session token and the identity it authenticates.
tokenstringrequiredSession JWT. Send it as Authorization: Bearer <token> on every other call.
principalstringrequiredWho the token authenticates — a user email, or the id of the API key it was exchanged for.
project_idstringrequiredThe Pinecone project the token is scoped to.
project_namestringrequiredHuman-readable label for the project the token is scoped to.