Identity API

Sign-in, tokens, multi-factor authentication, Microsoft sign-in, tenants, users, subscriptions and billing.

Service
Identity service
Base path
https://your-identity-host/api/v1
Authentication
Bearer token from POST /api/v1/auth/login. Sign-in and registration routes are public.

The identity service issues the platform's access tokens and holds tenants, users, roles, environments and subscriptions. Every other API expects the token it issues, plus the TenantId, AppId and EnvironmentId headers for the context you are working in.

POST/api/v1/auth/login

Sign in with email or username and password

Returns an access token and a refresh token for the user. The tenant is chosen from the user's usable subscriptions. When the tenant requires multi-factor authentication and the user has it enabled, the response asks for the second step instead (POST /api/v1/auth/login/mfa).

Authentication
None (public)
Permissions
None

Request body

JSON
{
  "email": "you@yourcompany.example",
  "password": "your-password",
  "rememberMe": false
}

Response

  • 200 OK: an authentication result with the access token and refresh token, or a request for the multi-factor step.
  • Lifetimes follow the tenant's security settings (access tokens default to 60 minutes).

Error responses

  • Invalid credentials, a locked account, an unconfirmed email or an expired password return an error result explaining which.

Example request

curl -X POST "https://your-identity-host/api/v1/auth/login" \
  -H "Content-Type: application/json" \
  -d '{
  "email": "you@yourcompany.example",
  "password": "your-password",
  "rememberMe": false
}'
POST/api/v1/auth/login/otp

Sign in with a one-time code

Authentication
None (public)
Permissions
None
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.

POST/api/v1/auth/login/mfa

Complete the multi-factor sign-in step

Authentication
None (public)
Permissions
None
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.

POST/api/v1/auth/refresh

Exchange a refresh token for new tokens

Refresh tokens rotate: the old token is revoked when it is used, and the refresh is bound to a tenant the user belongs to.

Authentication
None (public)
Permissions
None
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.

POST/api/v1/auth/register-tenant

Register a new tenant and its first administrator

Creates the tenant, the administrator user and role, links them to the platform environment, and returns a token. A default subscription is created in the background.

Authentication
None (public)
Permissions
None
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.

POST/api/v1/auth/register

Register a user

Authentication
None (public)
Permissions
None
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.

POST/api/v1/auth/password/forgot

Send a password reset code

Sends a six-digit code. The response is the same whether or not the account exists, and a cooldown applies per account.

Authentication
None (public)
Permissions
None
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.

POST/api/v1/auth/password/forgot/confirm

Set a new password with the reset code

Authentication
None (public)
Permissions
None
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.

POST/api/v1/auth/password/change

Change your own password

Authentication
Bearer token and context headers
Permissions
The signed-in user
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.

POST/api/v1/auth/password/{userId}/reset

Reset a user's password as an administrator

Authentication
Bearer token and context headers
Permissions
Tenant administrator
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.

POST/api/v1/mfa/setup

Start setting up authenticator-app or email-code MFA

Authentication
Bearer token and context headers
Permissions
The signed-in user
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.

POST/api/v1/mfa/enable

Enable MFA after verifying a code

Authentication
Bearer token and context headers
Permissions
The signed-in user
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.

POST/api/v1/mfa/disable

Disable MFA

Authentication
Bearer token and context headers
Permissions
The signed-in user
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.

GET/api/v1/mfa/status

Get your MFA status

Authentication
Bearer token and context headers
Permissions
The signed-in user
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.

GET/api/v1/sso/microsoft/settings

Read the tenant's Microsoft sign-in settings

Authentication
Bearer token and context headers
Permissions
Tenant administrator
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.

POST/api/v1/sso/microsoft/connect

Connect a Microsoft organisation to the tenant

Authentication
Bearer token and context headers
Permissions
Tenant administrator
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.

POST/api/v1/sso/microsoft/sign-in/start

Start Sign in with Microsoft

Uses PKCE and a nonce. Only members of a connected Microsoft organisation who already belong to the tenant can sign in; accounts are not created automatically.

Authentication
None (public)
Permissions
None
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.

POST/api/v1/sso/microsoft/sign-in/exchange

Exchange the Microsoft result for platform tokens

Authentication
None (public)
Permissions
None
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.

GET/api/v1/sso/microsoft/sign-in/availability

Check whether Microsoft sign-in is available

Authentication
None (public)
Permissions
None
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.

GET/api/v1/tenants

List tenants

Authentication
Bearer token and context headers
Permissions
Platform or tenant administrator
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.

GET/api/v1/tenants/{id}

Get a tenant

Authentication
Bearer token and context headers
Permissions
Platform or tenant administrator
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.

GET/api/v1/tenants/validate/subdomain/{subdomain}

Check whether a subdomain is available

Authentication
Bearer token and context headers
Permissions
Authenticated caller
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.

PATCH/api/v1/tenants/{id}/status

Change a tenant's status

Authentication
Bearer token and context headers
Permissions
Platform administrator
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.

GET/api/v1/users

List users

Authentication
Bearer token and context headers
Permissions
Tenant administrator
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.

GET/api/v1/users/{id}

Get a user

Authentication
Bearer token and context headers
Permissions
Tenant administrator
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.

POST/api/v1/users/{id}/roles

Assign roles to a user

Authentication
Bearer token and context headers
Permissions
Tenant administrator
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.

POST/api/v1/userdetails

Get the signed-in user's profile

The user is taken from the token, not from the request.

Authentication
Bearer token and context headers
Permissions
The signed-in user
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.

POST/api/v1/billing/checkout

Start a checkout for a plan

Authentication
Bearer token and context headers
Permissions
Your role's access to the resource
Note

The current payment gateway is Razorpay.

POST/api/v1/billing/checkout/verify

Verify a completed checkout

Authentication
Bearer token and context headers
Permissions
Your role's access to the resource
GET/api/v1/billing/entitlements

Get the plan capabilities for the current context

Authentication
Bearer token and context headers
Permissions
Your role's access to the resource
POST/api/v1/billing/subscriptions/{id}/cancel

Cancel a subscription

Authentication
Bearer token and context headers
Permissions
Your role's access to the resource
POST/api/v1/billing/subscriptions/{id}/resume

Resume a cancelled subscription

Authentication
Bearer token and context headers
Permissions
Your role's access to the resource
POST/connect/token

Token endpoint (authorization code, refresh token, client credentials)

Standard OAuth 2.0 token endpoint for integrations. Introspection (/connect/introspect) and revocation (/connect/revoke) are also available.

Authentication
None (public)
Permissions
A registered client
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.

GET/connect/authorize

Authorization endpoint

Authentication
None (public)
Permissions
A registered client
Detailed schema in preparation

The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.