Skip to main content
These endpoints power the protocol that t.js and the iOS and Android SDKs use. In most integrations, you should not call them directly from application code. They live under /v2/collect/, separately from the /v1/ REST API.
The request bodies for batch and result endpoints use encrypted binary payloads and session-bound integrity checks. The supported public integration surface is the browser SDK, not manual construction of these transport messages.

Endpoint summary

GET /v2/collect/pings/:pingId

Used for timing measurement during session setup.
  • Authentication: none
  • Path parameter: pingId
  • Response: 204 No Content

POST /v2/collect/sessions

Creates or resumes a short-lived unified session and creates a document for the current page lifecycle.
  • Authentication: Authorization: Bearer pk_*
  • Content type: JSON
Example response:
Implementation notes:
  • The default server sets an HTTP-only __Host-sid cookie on this call.
  • A session can span page lifecycles; each creation response identifies the new active document.
  • Treat sessionId as an opaque identifier. New sessions use the sid_... format, while legacy hex IDs are still accepted.
  • Native publishable keys are accepted on this endpoint only from the matching iOS or Android SDK. See Authentication.

POST /v2/collect/sessions/:sessionId/documents/:documentId/batches

Submits encrypted observation batches for the current session.
  • Authentication: Authorization: Bearer pk_*
  • Required headers:
    • X-Client-Key
    • X-Batch-Seq
    • Content-Type: application/octet-stream
Example response:
For the first snapshot batch, the response also includes the fingerprint-ready payload shown above under fingerprint. Possible failure cases include invalid sequence numbers (session.sequence_mismatch), invalid sessions (session.invalid_or_expired), and transport.session_reset_required. The last is a 409 with retryable set to true, and the client recovers by starting a new session. Example transport error:

POST /v2/collect/sessions/:sessionId/documents/:documentId/results

Requests a fresh sealed handoff for the accumulated session data.
  • Authentication: Authorization: Bearer pk_*
  • Required headers:
    • X-Client-Key
    • Content-Type: application/octet-stream
Responses include:
The public browser transport never returns verdicts, scores, phases, categories, or visitor IDs. Verify the sealed token locally on your backend or use GET /v1/sessions/:sessionId as the secondary integration method.

POST /v2/collect/network-checks

Compares the HTTP request path with the WebSocket probe path used during VPN and proxy detection.
  • Authentication: none
  • Content type: JSON