Create Session
Sessions
Create Session
This endpoint creates a new session.
POST
Create Session
Sessions are created by making an
POST request to the sessions endpoint. When creating a session, the request body will contain either a userkey or a login and password.
If the member could be authenticated with the provided credentials, a session key should be returned. If an MFA challenge is needed, an MFA challenge response should be returned.
If the member could not be authenticated with the provided credentials, a 401 (Unauthorized) error should be returned.
If a userkey is provided with the success response, it will be stored and used by MX as a credential for that user in future requests. This mechanism allows a partner to initially authenticate a user with a login, password, and MFA, then use the userkey in future sessions.
If MX receives a 401 error on a request with a userkey, it will be assumed that the userkey has become invalid. MX will remove the userkey and retry the authentication with the login and password. This allows a partner to invalidate a userkey to force reauthenication if needed.
Session Fields
Challenge Fields

