> ## Documentation Index
> Fetch the complete documentation index at: https://developers.aptranet.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Platform and browser sessions

> Understand the boundary between project API automation and organization, identity, and billing workflows.

The generated product reference covers project resources authenticated with an access key and secret. Organization administration, billing, and personal account security also use customer-facing browser endpoints, with session, CSRF, organization-role, and project-permission checks as applicable.

Use the Management Console for these workflows. Do not use a project API key as a substitute for a signed-in organization administrator or billing manager.

| Workflow | Endpoint family | Guide |
| - | - | - |
| Organization profile, membership, invitations | `/central/organizations` | [Organizations and projects](/platform/organizations-and-projects), [Members and permissions](/platform/members-and-permissions) |
| Project creation and settings | `/central/projects` | [Organizations and projects](/platform/organizations-and-projects) |
| Project member permissions | `/central/projects/member_permissions` | [Members and permissions](/platform/members-and-permissions) |
| Project API keys and secret rotation | `/central/developers/api_keys` | [API keys](/platform/api-keys) |
| Project quotas | `/central/quotas` | [Quotas](/platform/quotas) |
| Billing profile, plans, subscriptions, usage, invoices, payments | `/central/billing` | [Billing](/platform/billing) |
| Sign-in, password recovery, MFA, passkeys, sessions | `/auth` | [Account security](/platform/account-security) |

## Browser context

Browser requests include the session cookie. Mutations require the corresponding `X-CSRF-Token` and an approved origin. The console selects the organization with `Aptranet-Organization-ID` and passes `project` on project-scoped calls. The API validates membership and permissions before accessing resources.

Changing an organization or project changes the resource context. A resource ID from a previous selection does not grant access in the new context.

## Error handling

Treat session expiry as a sign-in requirement, not a reason to retry a mutation repeatedly. A `403` can indicate an organization role, project permission, or product entitlement problem. A `404` can mean the resource is unavailable in the current scope. Review [API errors](/api-reference/errors) and [troubleshooting](/operations/troubleshooting).

Never copy a browser cookie or CSRF token into a server automation job. Create a dedicated [project API key](/platform/api-keys) for supported product automation.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.