Browser context
Browser requests include the session cookie. Mutations require the correspondingX-CSRF-Token and an approved origin. The console selects the organization with Aptranet-Organization-ID and passes project on project-scoped calls. The API validates membership and permissions before accessing resources.
Changing an organization or project changes the resource context. A resource ID from a previous selection does not grant access in the new context.
Error handling
Treat session expiry as a sign-in requirement, not a reason to retry a mutation repeatedly. A403 can indicate an organization role, project permission, or product entitlement problem. A 404 can mean the resource is unavailable in the current scope. Review API errors and troubleshooting.
Never copy a browser cookie or CSRF token into a server automation job. Create a dedicated project API key for supported product automation.