Authentication

Osprey supports two authentication methods:

  1. JWT Cookies โ€” The primary method for browser-based clients. JWT access and refresh tokens are transported via httpOnly cookies. The browser sends cookies automatically on every request (including WebSocket upgrades).
  2. API Key Header โ€” An alternative for programmatic/API clients. Pass the key in the X-API-Key header. See API Key Authentication below.

The auth middleware checks X-API-Key first, then falls back to the JWT cookie. Only one method is required per request.