{ "$schema": "https://json-schema.org/draft/2020-12/schema", "$id": "https://velox.dev/schema/methods/session.pair.schema.json", "title": "session.pair", "description": "WebSocket transport only. Triggers a GUI or desktop-notification prompt showing a four-digit code; the user must approve before a token is issued. Failed attempts are rate-limited to 5/min followed by a 60 s lockout (-32014) so a token cannot be brute-forced by another local process. The daemon stores only a hash of the token.", "x-privileged": false, "x-transports": ["ws"], "x-deadlineMs": 120000, "x-errors": [-32003, -32014], "type": "object", "properties": { "params": { "type": "object", "additionalProperties": false, "required": ["clientName", "extensionId"], "properties": { "clientName": { "type": "string", "maxLength": 64 }, "extensionId": { "type": "string", "description": "The moz-extension origin UUID. Must match the Origin header verified on the WS upgrade." }, "code": { "type": ["string", "null"], "pattern": "^[0-9]{4}$", "description": "Set when the user typed the code into the extension's Options page instead of clicking Allow in the GUI." } } }, "result": { "type": "object", "additionalProperties": false, "required": ["token", "expiresAt"], "properties": { "token": { "type": "string", "minLength": 43, "description": "256 bits, base64url. Stored by the extension in browser.storage.local and sent on every later connect." }, "expiresAt": { "type": ["string", "null"], "format": "date-time", "description": "null means the token does not expire; it is revoked from Options -> Unpair." } } } } }