t.js and the iOS and Android SDKs use. In most integrations, you should not call them directly from application code. They live under /v2/collect/, separately from the /v1/ REST API.
The request bodies for batch and result endpoints use encrypted binary payloads and session-bound integrity checks. The supported public integration surface is the browser SDK, not manual construction of these transport messages.
Endpoint summary
GET /v2/collect/pings/:pingId
Used for timing measurement during session setup.
- Authentication: none
- Path parameter:
pingId - Response:
204 No Content
POST /v2/collect/sessions
Creates or resumes a short-lived unified session and creates a document for the current page lifecycle.
- Authentication:
Authorization: Bearer pk_* - Content type: JSON
Implementation notes:
- The default server sets an HTTP-only
__Host-sidcookie on this call. - A session can span page lifecycles; each creation response identifies the new active document.
- Treat
sessionIdas an opaque identifier. New sessions use thesid_...format, while legacy hex IDs are still accepted. - Native publishable keys are accepted on this endpoint only from the matching iOS or Android SDK. See Authentication.
POST /v2/collect/sessions/:sessionId/documents/:documentId/batches
Submits encrypted observation batches for the current session.
- Authentication:
Authorization: Bearer pk_* - Required headers:
X-Client-KeyX-Batch-SeqContent-Type: application/octet-stream
fingerprint.
Possible failure cases include invalid sequence numbers (session.sequence_mismatch), invalid sessions (session.invalid_or_expired), and transport.session_reset_required. The last is a 409 with retryable set to true, and the client recovers by starting a new session.
Example transport error:
POST /v2/collect/sessions/:sessionId/documents/:documentId/results
Requests a fresh sealed handoff for the accumulated session data.
- Authentication:
Authorization: Bearer pk_* - Required headers:
X-Client-KeyContent-Type: application/octet-stream
GET /v1/sessions/:sessionId as the secondary integration method.
POST /v2/collect/network-checks
Compares the HTTP request path with the WebSocket probe path used during VPN and proxy detection.
- Authentication: none
- Content type: JSON