Skip to content

Session cookie auth

{ type: "session", cookie } sends a raw Cookie header. Use it when you already have a browser session (e.g. scraped PHPSESSID=... from an authenticated web login) and need the same identity on API calls.

Prefer API tokens or OAuth for new apps. Session cookies are brittle, user-specific, and easy to misuse.

Shape

ts
import { WynnClient } from "@wynnjs/api";

const client = new WynnClient({
  auth: {
    type: "session",
    // Full Cookie header value — not just the session id name
    cookie: process.env.WYNN_SESSION_COOKIE!,
  },
});

The client sets:

http
Cookie: <your cookie string>

Include the full header value you would send from the browser (PHPSESSID=… and any other required cookies, joined with ; if needed).

What works

MethodSession auth
player.whoAmI()Yes — any WynnAuth
Other public modulesYes (same as token) for higher RPM when accepted
oauth.me()No — needs { type: "oauth", accessToken }
ts
const { data } = await client.player.whoAmI();
const me = Object.values(data)[0];
console.log(me?.username);

Failure modes

SymptomLikely cause
InvalidTokenError / MalformedTokenErrorWrong auth type or mangled cookie
Forbidden / CSRFErrorSession expired, missing CSRF context, or endpoint expects token/OAuth
Works in browser, fails hereCookie incomplete (missing flags / companion cookies) or bound to another origin

Rules of thumb

  • Never commit session cookies
  • Rotate / invalidate when a user logs out
  • Do not share one session across many servers — treat it like a password
  • If you control the integration, switch to a developer API token or OAuth

Unofficial TypeScript tooling for the Wynncraft API