Session Required
session_required403
This endpoint is for the signed-in dashboard; API keys can't use it.
What this means
The request carried a valid API key, but the endpoint manages the account itself: billing, plans, API keys, connected AI apps, the signing secret, logs, data export or account deletion. Those endpoints accept only a signed-in dashboard session. The key is fine and keeps working for everything it is meant for; this request just used the wrong kind of credential.
When you'll see this
- A script called an account endpoint such as
GET /v1/accountorPOST /v1/account/keyswith an API key. - An integration that used to manage keys or billing with an API key, before account management became dashboard-only.
- A tool tried to approve an AI-app connection or cancel a plan on a user's behalf with their API key.
Learn more about how this works
Asterwise uses two kinds of credentials. An API key calls the calculation endpoints (/v1/astro/*, /v1/numerology/*, /v1/tarot/* and the rest) and can read its own record at GET /v1/keys/me and GET /v1/keys/me/usage. A dashboard session, created when a person signs in at asterwise.com, is the only credential that can change the account: spend money, create or revoke keys, connect or disconnect AI apps, or delete the account.
The split limits the damage of a leaked key. A key pasted into a public repository or a client-side bundle can be used to run calculations until you revoke it, but it can't revoke your other keys, change your plan, read your invoices or delete your account.
Example response
{
"success": false,
"error": "session_required",
"message": "This endpoint is for the signed-in dashboard; API keys can't use it. API keys call the calculation endpoints and GET /v1/keys/me.",
"details": [],
"retry_after": null,
"doc_url": "https://docs.asterwise.com/reference/errors/session_required/",
"request_id": "req_01HXYZABCDEFGH",
"timestamp": "2026-05-25T12:34:56Z"
}
- Do account tasks in the dashboard at asterwise.com/dashboard.
- To check a key from code, call
GET /v1/keys/me(its record) orGET /v1/keys/me/usage(the account's usage this month) with that key. - Keep using the API key for calculation endpoints; nothing about it needs to change.
This error is not retriable: the same request with the same credential will always be refused. Treat it as a configuration mistake and surface it, rather than retrying.
Python:
Production handler
- Python
- TypeScript
import httpx
def key_info(base_url: str, api_key: str) -> dict:
"""What an API key may read about itself."""
response = httpx.get(
f"{base_url}/v1/keys/me/usage",
headers={"Authorization": f"Bearer {api_key}"},
timeout=15,
)
if response.status_code == 403 and response.json().get("error") == "session_required":
raise RuntimeError("Account endpoints need a dashboard sign-in, not an API key.")
response.raise_for_status()
return response.json()["data"]
async function keyInfo(baseUrl: string, apiKey: string) {
const response = await fetch(`${baseUrl}/v1/keys/me/usage`, {
headers: { Authorization: `Bearer ${apiKey}` },
});
if (response.status === 403) {
const body = await response.json();
if (body.error === "session_required") {
throw new Error("Account endpoints need a dashboard sign-in, not an API key.");
}
}
if (!response.ok) throw new Error(`HTTP ${response.status}`);
return (await response.json()).data;
}
Avoid this error by
- Use API keys only for calculation endpoints and
/v1/keys/me. - Manage keys, plans and connected apps in the dashboard.
- Keep keys out of browsers and public repositories anyway: a leaked key still spends your monthly calls.