Authentication
Osprey supports two authentication methods:
- JWT Cookies โ The primary method for browser-based clients. JWT access and refresh tokens are transported via httpOnly cookies. The browser sends cookies automatically on every request (including WebSocket upgrades).
- API Key Header โ An alternative for programmatic/API clients. Pass the key in the
X-API-Key header. See API Key Authentication below.
The auth middleware checks X-API-Key first, then falls back to the JWT cookie. Only one method is required per request.