Authentication
WEDNESDAY production requests are authorized through the account session boundary used by the WEDNESDAY product. Durable ownership is derived server-side from that authorized session.
Account authority
For protected operations, the API resolves the account owner from the authorized server session rather than trusting a caller-supplied owner identifier. This keeps projects, conversations, files, search results, and durable chat state scoped to the authenticated account.
Browser requests
The production web application communicates with https://api.wednesdaychat.com using the WEDNESDAY session boundary. Cross-origin access is restricted to approved WEDNESDAY origins and explicitly allowed methods and headers.
Request headers
Some production flows use WEDNESDAY-specific headers for session continuity, CSRF protection, client identity, idempotency, or turn coordination. A header appearing in the service implementation does not by itself make it a public third-party authentication mechanism.
Third-party developer access
Authorization failures
Callers should treat authorization and session failures as terminal for the current credential context and re-establish a valid WEDNESDAY session through the supported product flow rather than retrying with fabricated identity data.