canonical: https://jentic.com/apis/vtex.local/session-manager-api

# Vtex Session Manager API

Session Manager tracks the current browsing sessions of all customers on the VTEX platform. Important session information is automatically captured and stored in a secure and easily accessible location. This includes data such as relevant cookies, query strings, authentication credentials, current profile and pricing information, if applicable. Session Manager API allows developers to retrieve and. The API exposes 4 endpoints secured with apiKey authentication.

## For AI agents

Programmatically create new session, get session. Covers 4 operations with apiKey authentication.

## Scope

Does not handle payments, communications, or crm - use for identity and authentication only.

## Capabilities

- Create new session
- Get session
- Edit session
- Query and filter Session Manager API records by parameters
- Monitor Session Manager API operational status and events

## Use cases

### Identity and Authentication Operations

Use the Session Manager API to perform identity auth operations programmatically. The API provides 4 endpoints covering core functionality including create new session, get session, edit session.

Example prompt: Call POST `/api/sessions` to create new session

### Automated Session Management

Automate session operations by combining multiple Session Manager API endpoints. Agents can get session and then edit session in a single workflow.

Example prompt: Call GET `/api/sessions` to get session, then verify the result

### AI Agent Integration via Jentic

AI agents discover and call Session Manager API endpoints through Jentic without managing credentials directly. An agent searches for the required operation by intent, receives the matching endpoint schema, and executes the call with Jentic-managed authentication. This eliminates the need to read API documentation or handle apiKey tokens manually.

Example prompt: Search Jentic for 'create new session', load the operation schema, and execute with Jentic-managed credentials

## Key endpoints

| Method | Path | Description |
| --- | --- | --- |
| POST | `/api/sessions` | Create new session |
| GET | `/api/sessions` | Get session |
| PATCH | `/api/sessions` | Edit session |
| GET | `/api/segments` | Get segment |

## Key resources

- **Session** — Operations related to Session
- **Segment** — Operations related to Segment

## Why Jentic

- **Setup:** Wiring the VTEX Session Manager API by hand means carrying the vtex_session and vtex_segment cookies on each request and templating the {accountName} and {environment} host into every call. Through Jentic you install once, import the Session Manager API from the API Directory, store the session credential once, and your agent calls it.
- **Permission scoping:** The Session Manager API acts on the current session through the request body and cookies rather than a resource id in the path, so limit the agent to the operations it needs, such as reading session data. You choose whether to include writes like creating or patching a session.
- **Credential handling:** Your VTEX session credential is stored once, encrypted, by your own Jentic One instance and injected at execution time. It never enters the agent's prompt, logs, or context.
- **Discovery method:** Agents search Jentic by intent such as 'create a new session' or 'read the current session segments', and Jentic returns the matching Session Manager API operation with its input schema so the agent calls the right endpoint without browsing the reference docs.

## Related APIs

- **Auth0** — Alternative identity auth API
- **Okta** — Alternative identity auth API

## FAQ

### What authentication does the Session Manager API use?

The Session Manager API uses an API key passed in the `vtex_session` cookie. Through Jentic, these credentials are stored encrypted in your Jentic One instance and injected at execution time, so raw secrets never enter the agent context.

### Can I create new session with the Session Manager API?

Yes. Use the POST `/api/sessions` endpoint. The API returns structured JSON responses that agents can parse and act on directly.

### What are the rate limits for the Session Manager API?

Rate limits are not specified in the OpenAPI spec. Check the vendor documentation for current limits. Through Jentic, rate limiting is handled automatically with retry logic built into the execution layer.

### How do I create new session through Jentic?

Install the Jentic SDK with pip install jentic, authenticate through Jentic One, the self-hosted execution layer, then search for 'create new session'. Jentic returns the matching Session Manager API operation with its input schema. Load the schema and execute the call - credentials are injected automatically.

### How many endpoints does the Session Manager API have?

The Session Manager API exposes 4 endpoints covering session, segment operations.

### Can I limit what my agent is allowed to do with the Session Manager API?

Yes. Because you run Jentic One yourself, your own rules decide which Session Manager API operations and credentials the agent may use. You can allow only the read calls, such as GET `/api/sessions` to read the current session and GET `/api/segments` to read its segments, while withholding the writes like POST `/api/sessions` to create a session or PATCH `/api/sessions` to edit one. Since the API acts on the current session through the request body and cookies rather than a resource id in the path, scoping is controlled by which operations you enable and the credential you store.
