Skip to content

Exchange Session

POST /api/sdk/session

The browser widget calls this from the page with the token your backend returned from Mint SDK Token. Do not send your API Bearer token here.

You do not need to call this endpoint or handle the response. The widget uses the result automatically to connect and place calls.

Your page must be served over HTTPS on a hostname you have added under Profile → Call SDK (see the embed guide). For http://localhost, turn on test mode there instead.

Parameter Type Required Description
token string Yes The token from your backend. 16–128 characters.

The examples below are for debugging. Production traffic is the widget in the browser.

Terminal window
curl -X POST https://api.awajdigital.com/api/sdk/session \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
-H "Origin: https://shop.example.com" \
-d '{
"token": "avt_…"
}'

The widget uses this payload automatically. You can ignore these fields unless you are building your own client.

{
"wss_url": "wss://pbxfs1wss.awajdigital.com",
"domain": "agent.example.awajdigital.com",
"extension": "1001",
"sip_username": "1001",
"sip_password": "a1b2c3d4e5f6…",
"expires_in": 43200,
"expires_at": "2026-09-07T00:00:00.000+06:00",
"ice_servers": [
{
"urls": ["stun:stun.l.google.com:19302"]
}
]
}
Field Type Description
wss_url string WebSocket URL the phone registers against.
domain string Domain for this agent.
extension string Extension number.
sip_username string Username for this session.
sip_password string Password for this session. Do not persist in your app.
expires_in integer Advisory lifetime in seconds. Ends sooner if you connect again or revoke.
expires_at string ISO 8601 advisory expiry.
ice_servers array Connection servers (urls, optional username / credential).
Status Code Description
401 token_invalid Token missing, already used, expired, or unknown
403 agent_inactive Agent was deactivated or unapproved after the token was created
403 origin_not_allowed This page is not on HTTPS, or its hostname is not on your Call SDK allowed-domain list (and test mode is off)
422 — Validation failed (token missing or wrong length)
429 — Too many requests
{
"error": "invalid or expired token",
"code": "token_invalid"
}