POST
https://api.upstartcommerce.com/api/v1/auth/guest
Issues a short-lived JWT access token for anonymous browsing without credentials.
The endpoint serves both new and returning guests through a single call:
- No cookie (new visitor): creates a new guest session, returns access token,
sets
guest_session HttpOnly cookie.
- Valid cookie (returning visitor): rotates the cookie atomically, returns a
new access token with the same stable session identity.
- Unknown/expired cookie (reuse conflict or expiry): silently creates a new
session (logs a warning server-side), returns access token, sets new cookie.
Access token — short-lived JWT (1 hour), hold in JS memory, send on every API call.
Guest session cookie — long-lived opaque UUID (30 days by default), stored as
HttpOnly; Secure; SameSite=Strict, invisible to JavaScript.
JWT claims: sub = "guest:<stableSessionId>", type = "consumer", roles = [],
tenant from the x-upstart-tenant header. The stableSessionId never changes for the
lifetime of the guest session and can be used as a consistent identity key by downstream
services (e.g. cart-svc).
Rate limiting: requests are rate-limited by client IP (guest:<ip>).
acceptstringGenerated from available response content types
x-upstart-tenantstring<p>Tenant identifier for multi-tenant authentication.</p>
<p>Required when user is authorized for multiple tenants.
Optional when user has exactly one authorized tenant (auto-selected).</p>
Cookiestring<p>Optional <code>guest_session</code> cookie from a previous call</p>
200<p>Guest access token issued. The <code>guest_session</code> cookie in the response replaces
any previously presented cookie — always store the latest value.</p>
400<p>Missing required <code>x-upstart-tenant</code> header</p>
429Rate limit exceeded
500Internal server error
curl --request POST \
--url https://api.upstartcommerce.com/api/v1/auth/guest \
--header 'accept: application/json'