Authorization header. Tokens are obtained through a passwordless magic link flow.
Obtaining a token
Authentication is a three-step flow: 1. Request a magic linkintermediate_session_token along with a list of organizations the user belongs to.
3. Exchange for an org-scoped session
session.jwt. This is the token you’ll use for all subsequent requests.
Making authenticated requests
Pass the session JWT as a bearer token:401 Unauthorized response.
Token expiry
Session tokens expire after a configurable period. When a token expires, re-authenticate using the magic link flow above. The Holos dashboard and apps handle refresh automatically.Organization context
Most endpoints are org-scoped, but the organization is not named in the URL. It comes from the session token, soGET /skills returns the skills of whichever organization your session is currently bound to.
GET /organizations/{id}/members and POST /organizations/{id}/objects/upload.
Authorization is enforced per-org from the member’s role in the bound organization.
