Skip to Content
New release 12 available 🎉
API ReferenceAuthentication

Authentication

POST/v1/auth/loginPOST /v1/auth/login

Code samples

# You can also use wget curl -X POST /v1/auth/login \ -H 'Content-Type: application/json-patch+json' \ -H 'Accept: text/plain'

POST /v1/auth/login

Login to the system.

Body parameter

{ "username": "string", "password": "string" }

Parameters

NameInTypeRequiredDescription
bodybodyManagement.LoginRequestfalseThe login request.

Example responses

200 Response

{"success":true,"code":0,"message":"string","token":"string","expiresIn":0}
{ "success": true, "code": 0, "message": "string", "token": "string", "expiresIn": 0 }

Responses

StatusMeaningDescriptionSchema
200OK OKManagement.LoginResponse

Authentication: none, the endpoint is anonymous.

GET/v1/auth/userGET /v1/auth/user

Code samples

# You can also use wget curl -X GET /v1/auth/user \ -H 'Accept: text/plain'

GET /v1/auth/user

Get loggedin user information.

Parameters

NameInTypeRequiredDescription
requestqueryManagement.GetLoggedInUserRequestfalseThe logged in user request.

Example responses

200 Response

{"success":true,"code":0,"message":"string","user":{"id":"string","userName":"string","email":"string","phoneNumber":"string","title":"string","firstName":"string","lastName":"string","department":"string","birthDate":"2019-08-24T14:15:22Z","createdAt":"2019-08-24T14:15:22Z","updatedAt":"2019-08-24T14:15:22Z","lastDismissMessages":"2019-08-24T14:15:22Z","lastLogIn":"2019-08-24T14:15:22Z","rank":0,"image":"string","address":"string","postalCode":"string","region":"string","city":"string","country":"string","countryCode":"string","mobile":"string","notes":"string","customerId":0,"roles":["string"],"apiKeys":[{"id":0,"name":"string","key":"string","clientSecret":"string","createdDate":"2019-08-24T14:15:22Z","expireDate":"2019-08-24T14:15:22Z","ownerId":"string","revoked":true,"permissions":0,"description":"string"}],"settings":[{"id":0,"category":"string","group":"string","name":"string","value":"string","type":"string","description":"string","readOnly":true,"userId":"string"}]}}
{ "success": true, "code": 0, "message": "string", "user": { "id": "string", "userName": "string", "email": "string", "phoneNumber": "string", "title": "string", "firstName": "string", "lastName": "string", "department": "string", "birthDate": "2019-08-24T14:15:22Z", "createdAt": "2019-08-24T14:15:22Z", "updatedAt": "2019-08-24T14:15:22Z", "lastDismissMessages": "2019-08-24T14:15:22Z", "lastLogIn": "2019-08-24T14:15:22Z", "rank": 0, "image": "string", "address": "string", "postalCode": "string", "region": "string", "city": "string", "country": "string", "countryCode": "string", "mobile": "string", "notes": "string", "customerId": 0, "roles": [ "string" ], "apiKeys": [ { "id": 0, "name": "string", "key": "string", "clientSecret": "string", "createdDate": "2019-08-24T14:15:22Z", "expireDate": "2019-08-24T14:15:22Z", "ownerId": "string", "revoked": true, "permissions": 0, "description": "string" } ], "settings": [ { "id": 0, "category": "string", "group": "string", "name": "string", "value": "string", "type": "string", "description": "string", "readOnly": true, "userId": "string" } ] } }

Responses

StatusMeaningDescriptionSchema
200OK OKManagement.GetLoggedInUserResponse

Authentication: Bearer token.

POST/v1/auth/userPOST /v1/auth/user

Code samples

# You can also use wget curl -X POST /v1/auth/user \ -H 'Content-Type: application/json-patch+json' \ -H 'Accept: text/plain'

POST /v1/auth/user

Update loggedin user information.

Body parameter

{ "user": { "id": "string", "userName": "string", "email": "string", "phoneNumber": "string", "title": "string", "firstName": "string", "lastName": "string", "department": "string", "birthDate": "2019-08-24T14:15:22Z", "createdAt": "2019-08-24T14:15:22Z", "updatedAt": "2019-08-24T14:15:22Z", "lastDismissMessages": "2019-08-24T14:15:22Z", "lastLogIn": "2019-08-24T14:15:22Z", "rank": 0, "image": "string", "address": "string", "postalCode": "string", "region": "string", "city": "string", "country": "string", "countryCode": "string", "mobile": "string", "notes": "string", "customerId": 0, "roles": [ "string" ], "apiKeys": [ { "id": 0, "name": "string", "key": "string", "clientSecret": "string", "createdDate": "2019-08-24T14:15:22Z", "expireDate": "2019-08-24T14:15:22Z", "ownerId": "string", "revoked": true, "permissions": 0, "description": "string" } ], "settings": [ { "id": 0, "category": "string", "group": "string", "name": "string", "value": "string", "type": "string", "description": "string", "readOnly": true, "userId": "string" } ] } }

Parameters

NameInTypeRequiredDescription
bodybodyManagement.UpdateUserSettingsRequestfalseThe logged in user information request.

Example responses

200 Response

{"success":true,"code":0,"message":"string","user":{"id":"string","userName":"string","email":"string","phoneNumber":"string","title":"string","firstName":"string","lastName":"string","department":"string","birthDate":"2019-08-24T14:15:22Z","createdAt":"2019-08-24T14:15:22Z","updatedAt":"2019-08-24T14:15:22Z","lastDismissMessages":"2019-08-24T14:15:22Z","lastLogIn":"2019-08-24T14:15:22Z","rank":0,"image":"string","address":"string","postalCode":"string","region":"string","city":"string","country":"string","countryCode":"string","mobile":"string","notes":"string","customerId":0,"roles":["string"],"apiKeys":[{"id":0,"name":"string","key":"string","clientSecret":"string","createdDate":"2019-08-24T14:15:22Z","expireDate":"2019-08-24T14:15:22Z","ownerId":"string","revoked":true,"permissions":0,"description":"string"}],"settings":[{"id":0,"category":"string","group":"string","name":"string","value":"string","type":"string","description":"string","readOnly":true,"userId":"string"}]}}
{ "success": true, "code": 0, "message": "string", "user": { "id": "string", "userName": "string", "email": "string", "phoneNumber": "string", "title": "string", "firstName": "string", "lastName": "string", "department": "string", "birthDate": "2019-08-24T14:15:22Z", "createdAt": "2019-08-24T14:15:22Z", "updatedAt": "2019-08-24T14:15:22Z", "lastDismissMessages": "2019-08-24T14:15:22Z", "lastLogIn": "2019-08-24T14:15:22Z", "rank": 0, "image": "string", "address": "string", "postalCode": "string", "region": "string", "city": "string", "country": "string", "countryCode": "string", "mobile": "string", "notes": "string", "customerId": 0, "roles": [ "string" ], "apiKeys": [ { "id": 0, "name": "string", "key": "string", "clientSecret": "string", "createdDate": "2019-08-24T14:15:22Z", "expireDate": "2019-08-24T14:15:22Z", "ownerId": "string", "revoked": true, "permissions": 0, "description": "string" } ], "settings": [ { "id": 0, "category": "string", "group": "string", "name": "string", "value": "string", "type": "string", "description": "string", "readOnly": true, "userId": "string" } ] } }

Responses

StatusMeaningDescriptionSchema
200OK OKManagement.UpdateUserSettingsResponse

Authentication: Bearer token.

GET/v1/auth/sessionGET /v1/auth/session

Code samples

# You can also use wget curl -X GET /v1/auth/session \ -H 'Accept: text/plain'

GET /v1/auth/session

Get the capabilities of the credential that made the call.

Answers a bearer token and an API key alike, which is why it names both schemes: the rest of this controller speaks to tokens only, and a client holding just an API key has no other way to learn what it may do.

It carries no Policy = "ApiKey" on purpose. That policy demands the Read permission on every GET, so a key permitted only to create would not be able to ask what it is permitted to do. This is the one endpoint that serves no data, so it authenticates without requiring a permission of its own.

It also, deliberately, does not answer with the caller’s API keys the way M:Babel.Licensing.Service.Controllers.V1.AuthController.GetLoggedInUser(Babel.Licensing.Service.Management.GetLoggedInUserRequest) does: the caller may have proved possession of a single key, and that must not hand back the secrets of every other key the same owner holds.

Example responses

200 Response

{"success":true,"code":0,"message":"string","user":"string","roles":["string"],"permissions":0,"keyName":"string"}
{ "success": true, "code": 0, "message": "string", "user": "string", "roles": [ "string" ], "permissions": 0, "keyName": "string" }

Responses

StatusMeaningDescriptionSchema
200OK OKManagement.GetSessionResponse

Authentication: Bearer token or API key (x-api-key).

POST/v1/auth/logoutPOST /v1/auth/logout

Code samples

# You can also use wget curl -X POST /v1/auth/logout \ -H 'Content-Type: application/json-patch+json' \ -H 'Accept: text/plain'

POST /v1/auth/logout

Logout from the system.

Body parameter

{}

Parameters

NameInTypeRequiredDescription
bodybodyManagement.LogoutRequestfalsenone

Example responses

200 Response

{"success":true,"code":0,"message":"string"}
{ "success": true, "code": 0, "message": "string" }

Responses

StatusMeaningDescriptionSchema
200OK OKManagement.LogoutResponse

Authentication: Bearer token.

Last updated on