> ## Documentation Index
> Fetch the complete documentation index at: https://docs.refmatter.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a bounded human session



## OpenAPI

````yaml /api-reference/openapi.json post /v1/auth/sessions
openapi: 3.1.0
info:
  title: Refmatter API
  version: 0.1.0
  description: >-
    Reference memory for AI creative agents. Every operation carries
    x-implementation-status; only implemented operations are availability
    claims.
servers:
  - url: https://api.refmatter.com
security:
  - bearerApiKey: []
  - sessionCookie: []
tags:
  - name: auth
  - name: workspaces
  - name: ingestions
  - name: references
  - name: media
  - name: sourceRoutes
paths:
  /v1/auth/sessions:
    post:
      tags:
        - auth
      summary: Create a bounded human session
      operationId: authSessionsCreate
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SignIn'
      responses:
        '201':
          description: Session created
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SignInResult'
        '400':
          description: Invalid request
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '401':
          description: Authentication required
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '403':
          description: Action not permitted
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '404':
          description: Resource not found
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '409':
          description: Revision or idempotency conflict
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '422':
          description: Request cannot be fulfilled by the current source contract
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '429':
          description: Rate limited
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '500':
          description: Internal error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '503':
          description: Route or dependency unavailable
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
      security: []
components:
  schemas:
    SignIn:
      $schema: https://json-schema.org/draft/2020-12/schema
      type: object
      properties:
        email:
          type: string
          maxLength: 320
          format: email
          pattern: >-
            ^(?!\.)(?!.*\.\.)([A-Za-z0-9_'+\-\.]*)[A-Za-z0-9_+-]@([A-Za-z0-9][A-Za-z0-9\-]*\.)+[A-Za-z]{2,}$
        password:
          type: string
          minLength: 1
          maxLength: 256
        workspaceId:
          type: string
          pattern: >-
            ^[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
      required:
        - email
        - password
      additionalProperties: false
    SignInResult:
      $schema: https://json-schema.org/draft/2020-12/schema
      type: object
      properties:
        session:
          type: object
          properties:
            id:
              type: string
              pattern: >-
                ^[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
            user:
              type: object
              properties:
                id:
                  type: string
                  pattern: >-
                    ^[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
                email:
                  type: string
                  maxLength: 320
                  format: email
                  pattern: >-
                    ^(?!\.)(?!.*\.\.)([A-Za-z0-9_'+\-\.]*)[A-Za-z0-9_+-]@([A-Za-z0-9][A-Za-z0-9\-]*\.)+[A-Za-z]{2,}$
                displayName:
                  type: string
                  minLength: 1
                  maxLength: 200
              required:
                - id
                - email
                - displayName
              additionalProperties: false
            activeWorkspaceId:
              anyOf:
                - type: string
                  pattern: >-
                    ^[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
                - type: 'null'
            workspaces:
              type: array
              items:
                type: object
                properties:
                  id:
                    type: string
                    pattern: >-
                      ^[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
                  name:
                    type: string
                    minLength: 1
                    maxLength: 200
                  slug:
                    type: string
                    minLength: 1
                    maxLength: 80
                  role:
                    type: string
                    enum:
                      - owner
                      - admin
                      - member
                      - viewer
                required:
                  - id
                  - name
                  - slug
                  - role
                additionalProperties: false
            idleExpiresAt:
              type: string
              pattern: >-
                ^\d{4}-(0[1-9]|1[0-2])-([0-2]\d|3[01])T([01]\d|2[0-3]):[0-5]\d:[0-5]\d(?:\.\d{1,9})?(?:Z|[+-](?:[01]\d|2[0-3]):[0-5]\d)$
            absoluteExpiresAt:
              type: string
              pattern: >-
                ^\d{4}-(0[1-9]|1[0-2])-([0-2]\d|3[01])T([01]\d|2[0-3]):[0-5]\d:[0-5]\d(?:\.\d{1,9})?(?:Z|[+-](?:[01]\d|2[0-3]):[0-5]\d)$
          required:
            - id
            - user
            - activeWorkspaceId
            - workspaces
            - idleExpiresAt
            - absoluteExpiresAt
          additionalProperties: false
      required:
        - session
      additionalProperties: false
    ErrorEnvelope:
      $schema: https://json-schema.org/draft/2020-12/schema
      type: object
      properties:
        error:
          type: object
          properties:
            code:
              type: string
              enum:
                - invalid_input
                - unauthenticated
                - invalid_credential
                - credential_conflict
                - forbidden
                - policy_blocked
                - route_disabled
                - route_degraded
                - not_found
                - bootstrap_conflict
                - last_owner_conflict
                - revision_conflict
                - idempotency_conflict
                - unavailable_private
                - unavailable_restricted
                - unavailable_removed
                - unsupported_object
                - unsupported_media
                - limit_exceeded
                - rate_limited
                - source_changed
                - network_timeout
                - network_transport
                - media_invalid
                - storage_unavailable
                - retry_exhausted
                - internal_error
            message:
              type: string
              minLength: 1
              maxLength: 240
            retryable:
              type: boolean
            requestId:
              type: string
              minLength: 8
              maxLength: 128
              pattern: ^[A-Za-z0-9][A-Za-z0-9._:-]*$
            details:
              type: object
              propertyNames:
                type: string
              additionalProperties:
                type:
                  - string
                  - number
                  - boolean
          required:
            - code
            - message
            - retryable
            - requestId
            - details
          additionalProperties: false
      required:
        - error
      additionalProperties: false
  securitySchemes:
    bearerApiKey:
      type: http
      scheme: bearer
    sessionCookie:
      type: apiKey
      in: cookie
      name: social_session

````