Exchange a Pinecone API key for a session token
Exchange a Pinecone API key for the session token every other endpoint expects. Send the token as a bearer credential.
POST /auth/login
curl --request POST \
--url https://{host}/api/auth/login \
--header 'Content-Type: application/json' \
--data '{
"api_key": "<string>"
}'{
"token": "<string>",
"principal": "<string>",
"project_id": "<string>",
"project_name": "<string>"
}Headers
Section titled “Headers”X-Pinecone-Api-Version(header, string) — Date-based contract version, echoed back on the same header. Omit for the default (2026-07); sendunstablefor the in-development surface. An unrecognized value is rejected with400 unsupported_api_version.
api_key(body, string) — Pinecone API key. Optional — when absent, the server falls back to its configured key (managed) or validates the seeded credential (BYOC).
Response
Section titled “Response”200— Session token + identity401— Missing or invalid credential403— Not permitted. Coded cases:preview_not_enabled(project not enabled for the Nexus preview),workspace_host_required(reached over the account host on a workspace-enabled cluster).404— No workspace exists at this host (workspace_not_found), on a workspace-enabled cluster.