> ## Documentation Index
> Fetch the complete documentation index at: https://chisa.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Create Session (with Login)

> This method allows an application to validate a request token by entering a username and password.

Not all applications have access to a web view so this can be used as a substitute.

Please note, the preferred method of validating a request token is to have a user authenticate the request via the TMDB website. You can read about that method here.

If you decide to use this method please use **HTTPS**.

This would replace step 3 from the How do I generate a session id? guide.



## OpenAPI

````yaml api-reference/openapi.json post /3/authentication/token/validate_with_login
openapi: 3.0.3
info:
  title: Themoviedb API
  description: >-
    Version 3 (stable) of The Movie Database (TMDB) API offers a concise list of
    available methods for movies, TV shows, actors, and images.
  version: 1.0.0
  contact: {}
servers:
  - url: https://api.themoviedb.org
  - url: https://api.themoviedb.org/3
security: []
tags:
  - name: Account
  - name: Authentication
    description: >-
      # How do I generate a session id?


      As outlined in the [getting started
      guide](https://developer.themoviedb.org/docs/getting-started), the basics
      to getting a user authenticated look like this:


      1. **Create a new request token**  

      2. **Get the user to authorize the request token**  

      3. **Create a new session id with the authorized request token**  


      Steps 1 and 3 should be fairly easy to understand, but let's walk through
      each to ensure clarity.


      ## Step 1: Create a request token


      The first step as a developer is to request a new token. This is a
      **temporary token** required to ask the user for permission to access
      their account. This token will automatically expire **after 60 minutes**
      if it's not used.


      ## Step 2: Ask the user for permission


      With a request token in hand, forward your user to the following URL:


      ```

      https://www.themoviedb.org/authenticate/{REQUEST_TOKEN}

      ```


      You can also pass this URL a `redirect_to` parameter, like so:


      ```

      https://www.themoviedb.org/authenticate/{REQUEST_TOKEN}?redirect_to=http://www.yourapp.com/approved

      ```


      Once the user has approved your request token, they will either be
      redirected to the URL you specified in the `redirect_to` parameter or to
      the `/authenticate/allow` path on TMDB. If they aren't redirected to a
      custom URL, the page will also include an `Authentication-Callback`
      header. This header contains the API call for step #3. You can either
      manually generate it or simply use the one we return.


      ## Step 3: Create a session ID


      By calling the **new session method** with the request token that has been
      approved by the user in Step 2, we will return a **new session_id**. This
      session can now be used to write user data. You should treat this key
      **like a password** and keep it secret.


      ## What about guest sessions?


      A **guest session** can be used to rate movies **without** requiring a
      registered TMDB user account. For more information about how to create a
      guest session, see
      [here](https://developer.themoviedb.org/docs/authentication).
  - name: Certification
  - name: Changes
  - name: Collections
  - name: Companies
  - name: Configuration
  - name: Credits
  - name: Discover
  - name: Find
  - name: Genres
  - name: Guest Session
  - name: Keywords
  - name: List
    description: >-
      ## v3 or v4 list? 😕


      You may have noticed that the a v4 version of our list API exists. While
      these v3 list methods continue to work, all of the new features you can
      see on our website are only available if you switch to the v4 lists.


      **What are some of the improvements in v4?**


      - You can import "unlimited" items in a single request
          
      - You can use mixed type (movie and TV) lists
          
      - You can use private lists
          
      - You can add and use comments per item
          
      - There are more sort options
          
      - They are faster
          
      - Check the v4 documentation for more information.
  - name: Movie Lists
  - name: Movies
  - name: Networks
  - name: People Lists
  - name: People
  - name: Reviews
  - name: Search
  - name: Trending
  - name: TV Series Lists
  - name: TV Series
  - name: TV Seasons
  - name: TV Episodes
  - name: TV Episode Groups
  - name: Watch Providers
paths:
  /3/authentication/token/validate_with_login:
    post:
      tags:
        - Authentication
      summary: Create Session (with Login)
      description: >-
        This method allows an application to validate a request token by
        entering a username and password.


        Not all applications have access to a web view so this can be used as a
        substitute.


        Please note, the preferred method of validating a request token is to
        have a user authenticate the request via the TMDB website. You can read
        about that method here.


        If you decide to use this method please use **HTTPS**.


        This would replace step 3 from the How do I generate a session id?
        guide.
      operationId: createSessionWithLogin
      requestBody:
        content:
          application/json:
            schema:
              type: object
              properties:
                password:
                  type: string
                  example: Alexander4
                request_token:
                  type: string
                  example: 65fa8d51d4cc82668dd72b231591cc824231193c
                username:
                  type: string
                  example: Chisa_
            examples:
              Create Session (with Login):
                value:
                  password: Alexander4
                  request_token: 65fa8d51d4cc82668dd72b231591cc824231193c
                  username: Chisa_
      responses:
        '200':
          description: Session (with Login)
          headers:
            Alt-Svc:
              schema:
                type: string
                example: h3=":443"; ma=86400
            Connection:
              schema:
                type: string
                example: keep-alive
            Content-Encoding:
              schema:
                type: string
                example: br
            Date:
              schema:
                type: string
                example: Fri, 03 Jan 2025 15:39:48 GMT
            Server:
              schema:
                type: string
                example: openresty
            Transfer-Encoding:
              schema:
                type: string
                example: chunked
            Vary:
              schema:
                type: string
                example: Origin
            Via:
              schema:
                type: string
                example: >-
                  1.1 a95a47d0ae281d5cb9d53eb5abd9a948.cloudfront.net
                  (CloudFront)
            X-Amz-Cf-Id:
              schema:
                type: string
                example: 9yf0ROBea7-hI4QCuzISBoRZJtHMCcsRFHD7LK-Fe0ZZu662sm1Ytg==
            X-Amz-Cf-Pop:
              schema:
                type: string
                example: LOS50-P2
            X-Cache:
              schema:
                type: string
                example: Miss from cloudfront
            cache-control:
              schema:
                type: string
                example: public, max-age=0
            etag:
              schema:
                type: string
                example: W/"7ea26fc51aa14c65fe4d53c74617021d"
            vary:
              schema:
                type: string
                example: accept-encoding
          content:
            application/json:
              schema:
                type: object
                properties:
                  expires_at:
                    type: string
                    example: 2025-01-03 16:37:35 UTC
                  request_token:
                    type: string
                    example: 65fa8d51d4cc82668dd72b231591cc824231193c
                  success:
                    type: boolean
                    example: true
              examples:
                Session (with Login):
                  value:
                    expires_at: 2025-01-03 16:37:35 UTC
                    request_token: 65fa8d51d4cc82668dd72b231591cc824231193c
                    success: true

````