Identity API
Sign-in, tokens, multi-factor authentication, Microsoft sign-in, tenants, users, subscriptions and billing.
- Service
- Identity service
- Base path
https://your-identity-host/api/v1- Authentication
- Bearer token from
POST /api/v1/auth/login. Sign-in and registration routes are public.
The identity service issues the platform's access tokens and holds tenants, users, roles, environments and subscriptions. Every other API expects the token it issues, plus the TenantId, AppId and EnvironmentId headers for the context you are working in.
/api/v1/auth/loginSign in with email or username and password
Returns an access token and a refresh token for the user. The tenant is chosen from the user's usable subscriptions. When the tenant requires multi-factor authentication and the user has it enabled, the response asks for the second step instead (POST /api/v1/auth/login/mfa).
Request body
{
"email": "you@yourcompany.example",
"password": "your-password",
"rememberMe": false
}Response
- 200 OK: an authentication result with the access token and refresh token, or a request for the multi-factor step.
- Lifetimes follow the tenant's security settings (access tokens default to 60 minutes).
Error responses
- Invalid credentials, a locked account, an unconfirmed email or an expired password return an error result explaining which.
Example request
curl -X POST "https://your-identity-host/api/v1/auth/login" \
-H "Content-Type: application/json" \
-d '{
"email": "you@yourcompany.example",
"password": "your-password",
"rememberMe": false
}'const res = await fetch("https://your-identity-host/api/v1/auth/login", {
method: "POST",
headers: {
"Content-Type": "application/json",
},
body: JSON.stringify({
"email": "you@yourcompany.example",
"password": "your-password",
"rememberMe": false
}),
});
const result = await res.json();using var http = new HttpClient();
var request = new HttpRequestMessage(HttpMethod.Post, "https://your-identity-host/api/v1/auth/login");
request.Content = JsonContent.Create(body); // body: the JSON shown in the cURL tab
var response = await http.SendAsync(request);Sends the request from your browser to your own environment. Nothing is stored by this page. Your environment must allow requests from this site.
/api/v1/auth/login/otpSign in with a one-time code
The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.
/api/v1/auth/login/mfaComplete the multi-factor sign-in step
The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.
/api/v1/auth/refreshExchange a refresh token for new tokens
Refresh tokens rotate: the old token is revoked when it is used, and the refresh is bound to a tenant the user belongs to.
The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.
/api/v1/auth/register-tenantRegister a new tenant and its first administrator
Creates the tenant, the administrator user and role, links them to the platform environment, and returns a token. A default subscription is created in the background.
The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.
/api/v1/auth/registerRegister a user
The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.
/api/v1/auth/password/forgotSend a password reset code
Sends a six-digit code. The response is the same whether or not the account exists, and a cooldown applies per account.
The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.
/api/v1/auth/password/forgot/confirmSet a new password with the reset code
The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.
/api/v1/auth/password/changeChange your own password
The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.
/api/v1/auth/password/{userId}/resetReset a user's password as an administrator
The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.
/api/v1/mfa/setupStart setting up authenticator-app or email-code MFA
The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.
/api/v1/mfa/enableEnable MFA after verifying a code
The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.
/api/v1/mfa/disableDisable MFA
The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.
/api/v1/mfa/statusGet your MFA status
The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.
/api/v1/sso/microsoft/settingsRead the tenant's Microsoft sign-in settings
The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.
/api/v1/sso/microsoft/connectConnect a Microsoft organisation to the tenant
The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.
/api/v1/sso/microsoft/sign-in/startStart Sign in with Microsoft
Uses PKCE and a nonce. Only members of a connected Microsoft organisation who already belong to the tenant can sign in; accounts are not created automatically.
The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.
/api/v1/sso/microsoft/sign-in/exchangeExchange the Microsoft result for platform tokens
The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.
/api/v1/sso/microsoft/sign-in/availabilityCheck whether Microsoft sign-in is available
The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.
/api/v1/tenantsList tenants
The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.
/api/v1/tenants/{id}Get a tenant
The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.
/api/v1/tenants/validate/subdomain/{subdomain}Check whether a subdomain is available
The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.
/api/v1/tenants/{id}/statusChange a tenant's status
The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.
/api/v1/usersList users
The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.
/api/v1/users/{id}Get a user
The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.
/api/v1/users/{id}/rolesAssign roles to a user
The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.
/api/v1/userdetailsGet the signed-in user's profile
The user is taken from the token, not from the request.
The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.
/api/v1/billing/checkoutStart a checkout for a plan
The current payment gateway is Razorpay.
/api/v1/billing/checkout/verifyVerify a completed checkout
/api/v1/billing/entitlementsGet the plan capabilities for the current context
/api/v1/billing/subscriptions/{id}/cancelCancel a subscription
/api/v1/billing/subscriptions/{id}/resumeResume a cancelled subscription
/connect/tokenToken endpoint (authorization code, refresh token, client credentials)
Standard OAuth 2.0 token endpoint for integrations. Introspection (/connect/introspect) and revocation (/connect/revoke) are also available.
The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.
/connect/authorizeAuthorization endpoint
The route is part of the service today. Its request and response schema will be published here; until then, use the OpenAPI document on your environment.