How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Convert Cookie Authentication API

In order to use the Convert app, user has two options to authenticate requests:* Provide authorization token with each request works best for backend systems* Authenticate once using username/password/IDP provider and than send session token together with each requestThese endpoints will handle second case.**IMPORTANT:** currently this is available only for Convert.com's own clients, all other third party clients need to authenticate using API KEY Authentication

Convert Cookie Authentication API is one of 33 APIs that Convert publishes on the APIs.io network, described by a machine-readable OpenAPI specification.

Tagged areas include Cookie Authentication. The published artifact set on APIs.io includes an OpenAPI specification.

This API exposes 5 operations across 5 paths, and defines 117 schemas. It is described by OpenAPI 3.2.0, at version 2.0.0.

Requests are made against 3 base URLs: https://api.convert.com/api/v2, https://apidev.convert.com/api/v2, http://apidev.convert.com:5000/api/v2.

5 operations 5 paths 117 schemas 1 GET4 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
2.0.0
Base URL
https://api.convert.com/api/v2
Authentication
API Key, HTTP Bearer, API Key
Resource Areas
1

Authentication & Security 3

Convert Cookie Authentication API declares 3 security schemes for authenticating requests. An API key is passed in the header as Authorization (requestSigning). It accepts HTTP bearer tokens (secretKey). An API key is passed in the cookie as sid (cookieAuthentication).

  • requestSigning — See [API Key Authentication](tag/API-KEY-Authentication) for more information.
  • secretKey — See [API Key Authentication](tag/API-KEY-Authentication) for more information.
  • cookieAuthentication — Cookie authentication is used against Convert's own IdentityProvider or third party identity providers and is described more in the "[Cookie Authentication](ta…

Paths & Operations 5

Across 5 paths, the API surfaces 5 operations — 1 GET, 4 POST. Each is listed below with its method, path, parameters, and response codes.

Cookie Authentication 5

In order to use the Convert app, user has two options to authenticate requests: Provide authorization token with each request works best for backend systems Authenticate once usin…

POST
/auth
Authenticate user session (Cookie Based)
doAuth body → 200default
POST
/auth/forgotpassword
Request password reset
requestForgotPassword body → 200
POST
/auth/confirmpasswordreset
Confirm new password after reset request
confirmPasswordReset body → 200default
POST
/auth/logout
Log out user session
doLogout body → 200default
GET
/auth/status
Check authentication status
getAuthStatus → 200default

Schemas 117

The contract defines 117 schemas that model the data the API accepts and returns. The most detailed are ReportingSegmentsFilters (7 properties), UserPreferences (6 properties), ResetPasswordConfirmRequestData (5 properties), ProjectLiveFilteringOptions (4 properties). Each schema is shown below with its type and property counts.

ProjectHistoryPersistentOptions
KnowledgeBasesListPersistentOptions
ExperienceHistoryObjects
string
ObservationsListFilteringOptions
ObservationStatuses
string
The current status of an observation in its lifecycle: - active: The observation is current, under consideration, or being actively discussed. This is the defa…
ChangeHistoryObjects
string
ReportingSegmentsCustomSegment
integer
The numerical ID of a custom Convert Audience (of type 'segmentation') that the visitor is a member of. Allows report segmentation based on predefined custom s…
InitiatePasswordAuthRequestData
ResetPasswordConfirmRequestData
object
5 properties 3 required
ProjectHistoryColumnNames
string
Available columns for the project change history log in the UI.
UserLoginProviders
string
The identity provider used for user login: - convert: Standard username/password authentication managed by Convert. - google: Authentication via Google Sign-In…
SortDirection
object
1 property
ExperienceStatuses
string
GoalStatuses
string
The current status of a goal: - active: The goal is active and will track conversions for experiences it's attached to. - archived: The goal is archived and wi…
FeaturesListColumnNames
string
Available columns for the features list in the UI.
ExperienceReportSecondViewPersistentOptions
UserData
object
Detailed information about an authenticated user, including their profile, UI preferences, and security settings.
4 properties
KnowledgeBasesListColumnNames
string
Available columns for the Knowledge Base list in the UI.
ReportingSegmentsFilters
object
A collection of filters used to segment experience report data based on various visitor attributes and traffic sources. Applying these filters allows for deepe…
7 properties
ReportingSegmentsSource
string
The traffic source that brought the visitor to the site (e.g., 'google', 'facebook.com', 'direct', 'newsletter'). Derived from utmsource URL parameters or the…
ReportingSegmentsBrowser
string
The web browser used by the visitor. Used for segmenting reports to understand how experiences perform across different browsers. Knowledge Base: "Using Basic…
OnlyCount
object
1 property
ExperienceHistoryPersistentOptions
ProjectsListPersistentOptions
ProvideMfaCodeAuthRequestData
AuthRequestDataBase
object
Base structure for authentication requests in a cookie-based flow.
2 properties 1 required
TrackingScriptReleaseTypes
string
Defines the update strategy for the project's Convert tracking script: - manual: (Default) The project remains on its current script version. Updates to newer…
LocationsListPersistentOptions
ProjectLiveDataColumnNames
string
Available columns for the project-level live data feed in the UI.
ExperienceReportSectionNames
string
Identifiers for the different collapsible/reorderable sections within the experience report UI.
ObservationsListColumnNames
string
Available columns for the observations list in the UI.
LiveDataExpandFields
string
ErrorData
object
3 properties
UTC_Offset
integer
The time offset from Coordinated Universal Time (UTC) in seconds. For example, UTC-5 (EST) would be -18000. UTC+2 would be 7200. Used for interpreting or displ…
ReportingSegmentsCampaign
string
The campaign name associated with the visitor's session, typically derived from utmcampaign URL parameters. Allows report segmentation by marketing campaign. K…
AccountLiveDataPersistentOptions
ForgotPasswordRequestData
object
1 property
ExperiencesListFilteringOptions
object
AudiencesListPersistentOptions
ExperienceLiveDataColumnNames
string
Available columns for the experience-level live data feed in the UI.
LocationStatuses
string
The current status of a location: - active: The location is active and can be used for targeting experiences. - archived: The location is archived and no longe…
AccountExperiencesListColumnNames
string
Available columns for the account-wide experiences list in the UI.
AuthResponse
object
Response from a cookie-based authentication request. Indicates success (with user data and session cookie), failure (with error details), or the next required…
3 properties 3 required
LocationsListColumnNames
string
Available columns for the locations list in the UI.
LoginMoreData
object
Data returned when an authentication flow requires an additional step (e.g., MFA code input).
2 properties 2 required
NewPasswordAuthData
AccountExperiencesListPersistentOptions
PageNumber
object
1 property
ChangeHistoryExpandFields
string
SuccessData
object
2 properties
ExperiencesListPersistentOptions
SdkKeysListPersistentOptions
object
1 property
AudiencesListFilteringOptions
KnowledgeBasesListFilteringOptions
ReportingSegmentsCountry
string
The two-letter ISO 3166-1 alpha-2 country code of the visitor, determined by IP geolocation. Used for segmenting reports by country to analyze geographical per…
FeaturesListPersistentOptions
GoalsListFilteringOptions
GoalTypes
string
The type of user action or event that this goal tracks as a conversion. - advanced: A goal defined by a complex set of custom rules using the Advanced Goal Edi…
CompassColumnsNames
string
Available tabs for the compass list in the UI.
ReportingSegmentsVisitorType
string
Classifies the visitor as either 'new' or 'returning' based on their site visit history (tracked by Convert cookies). - new: First-time visitor to the site (or…
ExperienceHistoryFilteringOptions
AuthBaseData
object
Base data included in cookie-based authentication steps.
1 property
UserPreferences
object
A collection of user-specific settings that customize their experience within the Convert application UI. These preferences do not impact the execution or beha…
6 properties
LogoutRequestData
object
Specifies which cookie-based sessions to terminate for the authenticated user.
1 property
TimeRange
object
3 properties
CompassColumnsPersistentOptions
object
1 property
ExperienceTypes
string
The type of optimization activity: - a/b: Standard A/B test comparing an original page/element against one or more variations. Changes made via Visual Editor o…
AccountHistoryPersistentOptions
HypothesesListFilteringOptions
AuthRequestData
SignalSessionsListColumnNames
string
Available columns for the Convert Signals™ sessions list in the UI.
ChangeHistoryExpandParameter
object
1 property
AccountHistoryFilteringOptions
KnowledgeBaseStatuses
string
The status of a Knowledge Base entry: - active: The entry is current and relevant. - archived: The entry is kept for historical purposes but may no longer be c…
ProjectLiveFilteringOptions
object
Filters for the live data feed of a single project.
4 properties
ProjectsListColumnNames
string
Available columns for the projects list in the UI.
ColumnPreference
object
Defines user preference for a single column in a UI list view (name and visibility).
2 properties
ExperienceReportFirstViewColumnNames
string
Available columns for the goals-by-variations view in the experience report UI.
HypothesesListPersistentOptions
ChangeHistoryMethods
string
AccountLiveDataColumnNames
string
Available columns for the account-level live data feed in the UI.
AccountHistoryColumnNames
string
Available columns for the account change history log in the UI.
AudiencesListColumnNames
string
Available columns for the audiences list in the UI.
AudienceTypes
string
ReportingSegmentsDeviceCategories
string
The category of device used by the visitor. Enables report segmentation by device type. - iPhone, otherphones, allphones: Mobile phone categories. - desktop: D…
AccountExperiencesListFilteringOptions
object
SignalSessionsListFilteringOptions
ResultsPerPage
object
1 property
AccountLiveDataFilteringOptions
AudienceStatuses
string
The status of an audience: - active: The audience is currently active and can be used for targeting experiences. - archived: The audience is no longer active a…
HypothesesListColumnNames
string
Available columns for the hypotheses list in the UI.
SignalSessionsListPersistentOptions
ExperienceLiveDataFilteringOptions
object
Filters for the live data feed of a single experience.
3 properties
GoalsListColumnNames
string
Available columns for the goals list in the UI.
ConfirmNewPasswordAuthRequestData
LiveDataAutoRefreshSettings
object
1 property
ExperienceLiveDataPersistentOptions
LiveDataEventTypes
string
BaseUiSectionPreference
object
Defines user preference for a section in a UI view (name and visibility).
2 properties
GoalsListPersistentOptions
LocationsListFilteringOptions
ExperienceReportSecondViewColumnNames
string
Available columns for the variations-by-goals view in the experience report UI.
ExperienceReportPersistentOptions
object
1 property
ProjectsListFilteringOptions
ExperiencesListColumnNames
string
Available columns for the experiences list in the UI.
ObservationsListPersistentOptions
SdkKeysListColumnNames
string
Available columns for the sdk keys list in the UI.
PasswordAuthData
FeaturesListFilteringOptions
ChangeHistoryObjectTypes
string
ProjectHistoryFilteringOptions
ExperienceReportFirstViewPersistentOptions
ProjectLiveDataPersistentOptions
MfaCodeAuthData
LiveDataExpandParameter
object
1 property
HypothesisStatuses
string
The current stage or outcome of a hypothesis in its lifecycle: - draft: The hypothesis is still being formulated or refined; not yet ready for testing. - compl…
ExperienceHistoryColumnNames
string
Available columns for the experience change history log in the UI.

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

convert-cookie-authentication-api-openapi.yml Raw ↑

Other APIs Convert publishes across the network.

Convert Experiences REST API v2
Convert Accounts API
Convert AI content API
Convert API Keys API
Convert Audiences API
Convert Bulk API
Convert Cdn Images API
Convert Collaborators API
Convert Domains API
Convert Experience Sections API
Convert Experience Variations API
Convert Experiences API
Where this information came from

This is an independent, third-party profile of Convert Cookie Authentication API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.