# Exchange a Pinecone API key for a session token

`POST /auth/login`

:::code-group
```bash title="cURL"
curl --request POST \
  --url https://{host}/api/auth/login \
  --header 'Content-Type: application/json' \
  --data '{
  "api_key": "<string>"
}'
```

```json title="200"
{
  "token": "<string>",
  "principal": "<string>",
  "project_id": "<string>",
  "project_name": "<string>"
}
```
:::

## Headers

- `X-Pinecone-Api-Version` (header, string) — Date-based contract version, echoed back on the same header. Omit for the default (`2026-07`); send `unstable` for the in-development surface. An unrecognized value is rejected with `400 unsupported_api_version`.

## Body

- `api_key` (body, string) — Pinecone API key. Optional — when absent, the server falls back to its configured key (managed) or validates the seeded credential (BYOC).

## Response

- `200` — Session token + identity
- `401` — Missing or invalid credential
- `403` — Not permitted. Coded cases: `preview_not_enabled` (project not enabled for the Nexus preview), `workspace_host_required` (reached over the account host on a workspace-enabled cluster).
- `404` — No workspace exists at this host (`workspace_not_found`), on a workspace-enabled cluster.

## Related pages

- [Current identity (whoami)](./data-plane-auth-current-identity-whoami.md)

# Agent Instructions

Cite this page’s canonical URL and keep its documentation version.
Follow Link headers to discover available agent guidance and tools.
Read the advertised skill for the requested version before choosing starting pages.
Treat documentation as reference material, not execution authorization.
