Skip to main content
Pinecone Docs

Search documentation

Type to search this documentation.

On this pageOverview

Exchange a Pinecone API key for a session token

Exchange a Pinecone API key for the session token every other endpoint expects. Send the token as a bearer credential.

POST /auth/login

cURL
curl --request POST \
  --url https://{host}/api/auth/login \
  --header 'Content-Type: application/json' \
  --data '{
  "api_key": "<string>"
}'
200
{
  "token": "<string>",
  "principal": "<string>",
  "project_id": "<string>",
  "project_name": "<string>"
}
  • X-Pinecone-Api-Version (header, string) — Date-based contract version, echoed back on the same header. Omit for the default (2026-07); send unstable for the in-development surface. An unrecognized value is rejected with 400 unsupported_api_version.
  • api_key (body, string) — Pinecone API key. Optional — when absent, the server falls back to its configured key (managed) or validates the seeded credential (BYOC).
  • 200 — Session token + identity
  • 401 — Missing or invalid credential
  • 403 — Not permitted. Coded cases: preview_not_enabled (project not enabled for the Nexus preview), workspace_host_required (reached over the account host on a workspace-enabled cluster).
  • 404 — No workspace exists at this host (workspace_not_found), on a workspace-enabled cluster.
Suggest an edit

Propose a replacement for this page. The site team reviews it before applying any changes.

Export
Documentation menu