(C) 2014 Martin Wawrusch

Exposes routes to aquire and destroy sessions for APIs


  • Requires HAPI >= 10.0.0 and hapi-oauth-store-multi-tenant

Routes exposed

POST /sessions



on success with 201, otherwise 422

DELETE /sessions/me expects a token (24 char hex string, mongodb uid) in the credentials, deletes the session if exists, returns 204 on success

Change Log


  • Most of the API is now fully validated, although the individual validation needs more fine tuning.
  • BREAKING: Posting to create a session now requires a clientId, the options parameter is now ignored.

