> ## Documentation Index
> Fetch the complete documentation index at: https://docs.orbit.devotel.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Join a live co-browse session

> Mints an orbit-media data-channel join token for the operator so they can view (and, when the visitor granted control, guide) the customer's live browser session. The effective control grant is the AND of the agent's requested `control` and the visitor's stored consent — an observe-only session can never be escalated to guided control. Flips the session to 'active' and stamps the agent + start time. 404 when no joinable session exists (the visitor must initiate from the widget first). 503 when the media plane is not configured.



## OpenAPI

````yaml /openapi.yaml post /api/v1/cobrowse/{conversationId}/join
openapi: 3.1.0
info:
  title: Devotel CPaaS API
  description: Orbit by Devotel — Communications Platform as a Service API
  version: 1.0.0
  contact:
    name: Devotel
    url: https://devotel.io
    email: support@devotel.io
  license:
    name: Proprietary
servers:
  - url: https://api.orbit.devotel.io
    description: Production
security:
  - Bearer: []
  - ApiKey: []
tags:
  - name: Messages
    description: >-
      Send and manage messages across all channels (SMS, WhatsApp, RCS, Email,
      Viber, etc.)
  - name: Fax
    description: >-
      List and track fax (MMS/T.38) transmissions on Telnyx-backed fax numbers
      (sending flows through the Messaging API)
  - name: Agents
    description: AI agent creation, configuration, and execution
  - name: Voice
    description: Voice calls, IVR, conferencing, and SIP trunking
  - name: OnCall
    description: On-call rotations and escalation policy planning for incident alerting
  - name: Webhooks
    description: Webhook endpoint management and delivery logs
  - name: Numbers
    description: Phone number search, provisioning, and configuration
  - name: Brand Identity
    description: >-
      Unified cross-channel brand trust posture (10DLC, toll-free, WhatsApp,
      RCS, branded calling, number KYC)
  - name: Contacts
    description: Contact management, segmentation, and lifecycle tracking
  - name: Campaigns
    description: Marketing campaign orchestration and analytics
  - name: Flows
    description: Automation flow builder and execution engine
  - name: Templates
    description: Message template management and approval workflows
  - name: Settings
    description: Organization, channel, and user preference settings
  - name: Verify
    description: OTP generation and verification across channels
  - name: Push
    description: Push notification delivery via FCM and APNs
  - name: Integrations
    description: Third-party service connections and OAuth management
  - name: CDP
    description: >-
      Customer Data Platform — activation surface (CRM object sync, streaming
      destinations, ad-audience activation)
  - name: Files
    description: >-
      Server-to-server media upload, listing, retrieval, and deletion
      (signed-URL backed)
  - name: Commerce
    description: >-
      Omnichannel conversational-commerce — persistent cart + checkout state
      machine, channel-agnostic hosted pay-by-link, native WhatsApp checkout,
      and AP2-style agent payment mandates.
  - name: Sync
    description: >-
      Real-time shared-state primitive (Twilio Sync parity) — Documents, Maps,
      Lists, and ephemeral Streams, with change events relayed over the
      /api/v1/ws/sync WebSocket gateway
paths:
  /api/v1/cobrowse/{conversationId}/join:
    post:
      tags:
        - Cobrowse
      summary: Join a live co-browse session
      description: >-
        Mints an orbit-media data-channel join token for the operator so they
        can view (and, when the visitor granted control, guide) the customer's
        live browser session. The effective control grant is the AND of the
        agent's requested `control` and the visitor's stored consent — an
        observe-only session can never be escalated to guided control. Flips the
        session to 'active' and stamps the agent + start time. 404 when no
        joinable session exists (the visitor must initiate from the widget
        first). 503 when the media plane is not configured.
      parameters:
        - schema:
            type: string
          in: path
          name: conversationId
          required: true
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                control:
                  type: boolean
                  description: >-
                    Request guided control (highlight / scroll / form-fill).
                    Effective only when the visitor consented; otherwise the
                    agent joins observe-only.
      responses:
        '200':
          description: Default Response
components:
  securitySchemes:
    Bearer:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: Dashboard JWT token from Clerk
    ApiKey:
      type: apiKey
      name: X-API-Key
      in: header
      description: Server-to-server API key (dv_live_sk_*)

````