
I'm using godot with the rest api to make requests to appwrite. This is my code to get account:
func get_account() -> bool:
print(" Get account started")
requesting = true
http_request.request_completed.connect(get_account_signal)
var link: String = endpoint + "/account"
var body: String = JSON.new().stringify({
})
var temp_headers: PackedStringArray = custom_headers.duplicate()
temp_headers.append("X-Appwrite-Session: " + session.get_string_from_utf8())
var error = http_request.request(link, temp_headers, HTTPClient.METHOD_GET, body)
await http_request.request_completed
requesting = false
if error != OK or response != 200 and response != 201: return false
return true
```
Custom headers includes the appwrite project id and content-type application/json
I have the third header, x appwrite session with my session string.
Printing the header string gives me this:
"X-Appwrite-Project: pale-tube", "Content-Type: application/json", "X-Appwrite-Session: {$id:679d22d032e6b859705a,$createdAt:2025-01-31T19:21:52.227+00:00,$updatedAt:2025-01-31T19:21:52.227+00:00,userId:679cfd9c7af6fb6bf717,expire:2026-01-31T19:21:52.208+00:00,provider:email,providerUid:omareeto2012@hotmail.com,providerAccessToken:,providerAccessTokenExpiry:,providerRefreshToken:,ip:REDACTED,osCode:AND,osName:Android,osVersion:,clientType:browser,clientCode:AN,clientName:Android Browser,clientVersion:,clientEngine:WebKit,clientEngineVersion:,deviceName:,deviceBrand:,deviceModel:,countryCode:jo,countryName:Jordan,current:true,factors:[password],secret:,mfaUpdatedAt:}"
which matches the values I am using.
Logging in with my rest api implementation succeeds, giving me a 201 response code and a valid session

I believe x-appwrite-session is not the session object, but your session secret.

it says that its only included when i made the request with an api key, does that mean i need to make a custom backend to not leak the key?

or can i make it give me the secret without forcing me to use an api key

I'm not familiar with godot, can you set cookies and include them in http requests?

If not, I believe you should be able to get the session token from the cookies in the response headers of your authentication request, then you can store that and use it on subsequent requests.

Have you looked at this? https://appwrite.io/docs/apis/rest#authentication
Recommended threads
- OAuth fails with Invalid Response or inv...
Im currently trying to use the Discord Oauth but i cant find a way to make it work. I followed the docs and set up the discord oauth application and enabled it...
- "Invalid relationship value. Must be eit...
In my app i am trying to update the documents in my databse from a form in my app, and i am getting this error Error updating event users: AppwriteException: I...
- reoccurring resource limit usage
Two days ago I had of the error (attached) when there’s virtually no usage this month for any of my appwrite apps Yesterday we cleared up and I wasn’t getting...
