> ## Documentation Index
> Fetch the complete documentation index at: https://docs.praxis-ai.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Issue a short-lived ticket for the caller's KasmVNC desktop

> Mints a single-use, 60-second JWT ticket the browser uses to open a
WebSocket to the in-band desktop proxy at
`/api/agents/workspace/vnc/<workspaceId>`. The endpoint enforces:

- Sec-Fetch-Site: same-origin only — cross-site invocation is rejected.
- Per-user rate limiting via `createWorkspaceTicketLimiter()` (keyed on `req.user._id`; IP only as fallback for unauthenticated requests).
- Ownership: the workspace must belong to the caller and be in `status: 'ready'`.

The returned `vncPassword` is the RFB-protocol password KasmVNC requires
during the WebSocket handshake (separate from the HTTP Basic auth the
proxy applies server-side). Both the ticket and the password are
short-lived; obtain a fresh pair for each desktop session.

This route is not super-only — it is mounted under
`/api/agents/workspace` ahead of the super gate that fronts the rest
of `/api/agents/*`.




## OpenAPI

````yaml /mdx/api-reference/runtime/runtime-api.json post /api/user/agents/workspace/ticket
openapi: 3.0.0
info:
  title: Pria Runtime API
  version: 2.0.1
  description: >-
    Pria API Documentation Praxis's developer platform is a core part of our
    mission to empower organizations to grow better. Our APIs are designed to
    enable teams of any shape or size to build robust integrations that help
    them customize and get the most value out of Pria. All Pria APIs are built
    using REST conventions and designed to have a predictable URL structure.
    <br/>  <br/>They use many standard HTTP features, including methods (POST,
    GET, PUT, DELETE) and error response codes.  <br/> <br/>All API calls are
    made under https://hiimpria.ai/api and all responses return standard JSON.
    In these docs, you'll find lists of all available endpoints for a given API,
    along with interactive code blocks for building requests. For walkthroughs
    of basic usage for these APIs, check out the API guides.
servers:
  - url: https://pria.praxislxp.com
    description: Pria API Server
security: []
tags:
  - name: Authentication
    description: User authentication, registration, and password management (/api/auth)
  - name: OAuth
    description: OAuth authentication providers - Google, GitHub, SSO (/api/auth/oauth)
  - name: User
    description: User profile management and account operations (/api/user)
  - name: User Institutions
    description: User institution memberships and switching (/api/user/institution)
  - name: User Tools
    description: Available tools for authenticated users (/api/user/tools)
  - name: Institutions
    description: Institution settings and configuration (/api/user/institution)
  - name: Conversation
    description: AI conversation and Q&A endpoints (/api/ai)
  - name: Realtime
    description: Real-time voice AI and WebRTC sessions (/api/ai/rt)
  - name: Assistant
    description: AI assistant configuration and management (/api/user/assistant)
  - name: History
    description: Conversation history and favorites (/api/user/history)
  - name: RAG
    description: >-
      Document upload, embedding, and retrieval-augmented generation
      (/api/user/files, /api/user/rag)
  - name: Setting
    description: Instance variables and settings management (/api/user/setting)
  - name: Branding
    description: Digital twin branding and customization (/api/agent/branding)
  - name: Agent
    description: Agent engagement and session management (/api/agent)
  - name: SDK Launch
    description: >-
      SDK launch token signing and verification for secure iframe embedding
      (/api/auth/sdk-sign, /api/auth/sdk-verify)
  - name: Testing
    description: Health checks, diagnostics, and test endpoints (/api/test)
  - name: Admin Accounts
    description: Account management for super admins (/api/admin/account)
  - name: Admin Institutions
    description: Institution management for admins (/api/admin/institution)
  - name: Admin Users
    description: User management for admins (/api/admin/user)
  - name: Admin Entitlements
    description: >-
      User-institution relationships and permissions
      (/api/admin/userInstitution)
  - name: Admin Sessions
    description: Session management for admins (/api/admin/session)
  - name: Admin Histories
    description: Conversation history management and analytics (/api/admin/history)
  - name: Admin Assistants
    description: AI assistant management for admins (/api/admin/assistant)
  - name: Admin Questions
    description: Institution question and prompt management (/api/admin/question)
  - name: Admin Tools
    description: Tool configuration management (/api/admin/tool)
  - name: Admin AI Models
    description: AI model configuration (/api/admin/aimodel)
  - name: Admin MCP Servers
    description: Model Context Protocol server management (/api/admin/mcpserver)
  - name: Admin Feedbacks
    description: User feedback management (/api/admin/feedback)
  - name: Admin Uploads
    description: Upload management (/api/admin/upload)
  - name: Admin Charts
    description: Analytics and visualization chart management (/api/admin/chart)
  - name: Audio Notes
    description: Capture and ingest spoken notes into the personal vault
  - name: Memory
    description: User-facing memory parameters (personal + shared instance memory).
  - name: My Data
    description: >-
      GDPR controls — personal-scope counts, async ZIP-by-email export, and
      scoped soft-delete. Every endpoint pins `user = req.user._id` AND
      `institution: null`; institution-scoped data is governed by the
      institution's own retention policy and never reached from here.
  - name: Questions
    description: >-
      User-facing read of the onboarding question bank used by the "create a
      digital twin" wizard.
  - name: Transcription
    description: >-
      One-shot speech-to-text for in-place dictation. Audio blob in, transcript
      out — no Upload / History / RAG embeddings are persisted. Use
      `/audio-notes` for anything durable.
paths:
  /api/user/agents/workspace/ticket:
    post:
      tags:
        - Agents
      summary: Issue a short-lived ticket for the caller's KasmVNC desktop
      description: >
        Mints a single-use, 60-second JWT ticket the browser uses to open a

        WebSocket to the in-band desktop proxy at

        `/api/agents/workspace/vnc/<workspaceId>`. The endpoint enforces:


        - Sec-Fetch-Site: same-origin only — cross-site invocation is rejected.

        - Per-user rate limiting via `createWorkspaceTicketLimiter()` (keyed on
        `req.user._id`; IP only as fallback for unauthenticated requests).

        - Ownership: the workspace must belong to the caller and be in `status:
        'ready'`.


        The returned `vncPassword` is the RFB-protocol password KasmVNC requires

        during the WebSocket handshake (separate from the HTTP Basic auth the

        proxy applies server-side). Both the ticket and the password are

        short-lived; obtain a fresh pair for each desktop session.


        This route is not super-only — it is mounted under

        `/api/agents/workspace` ahead of the super gate that fronts the rest

        of `/api/agents/*`.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AgentWorkspaceTicketRequest'
      responses:
        '200':
          description: Ticket issued.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AgentWorkspaceTicketResponse'
        '400':
          description: workspaceId missing or empty.
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    example: false
                  message:
                    type: string
                    example: workspaceId is required
        '403':
          description: Cross-site request blocked by Sec-Fetch-Site enforcement.
        '404':
          description: No ready workspace owned by the caller matches `workspaceId`.
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    example: false
                  message:
                    type: string
                    example: Workspace not ready
        '429':
          description: Rate limit exceeded — too many ticket requests for this IP.
        '500':
          description: Internal server error issuing the ticket.
      security:
        - apiKeyAuth: []
components:
  schemas:
    AgentWorkspaceTicketRequest:
      type: object
      required:
        - workspaceId
      properties:
        workspaceId:
          type: string
          description: |
            Caller's own workspace runtime id (matches
            `agent.workspace.runtime.workspaceId` returned by
            `GET /api/user/agents/workspace/me`). The endpoint only issues
            tickets for a workspace owned by `req.user._id` and in
            `status: 'ready'`.
          example: pria-ws-7a3f9
    AgentWorkspaceTicketResponse:
      type: object
      properties:
        success:
          type: boolean
          example: true
        workspaceId:
          type: string
          description: Echo of the validated workspace id.
        vncUrl:
          type: string
          description: |
            Fully-qualified WebSocket URL (ws:// or wss://, matching the
            current request scheme) that the browser opens to reach the
            KasmVNC desktop. Includes the single-use `ticket` query param.
          example: >-
            wss://pria.praxislxp.com/api/agents/workspace/vnc/pria-ws-7a3f9?ticket=eyJhbGciOi...
        vncPassword:
          type: string
          description: |
            RFB-protocol password required by KasmVNC during the WebSocket
            handshake. This is **in addition** to the HTTP Basic auth
            handled server-side by the proxy. The browser never persists it
            — single use per RFB handshake for the lifetime of the ticket.
        expiresInSec:
          type: integer
          description: Ticket TTL in seconds (currently fixed at 60).
          example: 60
  securitySchemes:
    apiKeyAuth:
      type: apiKey
      in: header
      name: x-access-token
      description: JWT token passed in x-access-token header

````