Download OpenAPI specification:
Self-hosted authentication service. This document is the contract: the Go server, the dashboard client and the SDK are generated from it, and every request is validated against it before reaching a handler.
Errors are RFC 9457 problem documents (application/problem+json)
with a stable machine-readable code.
| email required | string <email> <= 254 characters |
| password required | string <password> (Password) [ 12 .. 128 ] characters 12–128 characters, no composition rules (ARCHITECTURE §3.8, ASVS 4.0.3 2.1.1). |
| name | string <= 100 characters |
{- "email": "user@example.com",
- "password": "pa$$word_qwe",
- "name": "string"
}{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "email": "user@example.com",
- "email_verified": true,
- "name": "string",
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z"
}Always 202, whether or not the address has an account. The link opens {PUBLIC_URL}/account/reset-password, is single-use and expires in 30 minutes.
| email required | string <email> <= 254 characters |
{- "email": "user@example.com"
}{- "title": "string",
- "status": 100,
- "detail": "string",
- "instance": "string",
- "code": "malformed_request",
- "errors": [
- {
- "field": "string",
- "message": "string"
}
], - "request_id": "string"
}Consumes the token, sets the password, verifies the email address and ends every dashboard session of the account.
| token required | string (OneTimeToken) [ 1 .. 128 ] characters The |
| new_password required | string <password> (Password) [ 12 .. 128 ] characters 12–128 characters, no composition rules (ARCHITECTURE §3.8, ASVS 4.0.3 2.1.1). |
{- "token": "string",
- "new_password": "pa$$word_qwe"
}{- "title": "string",
- "status": 100,
- "detail": "string",
- "instance": "string",
- "code": "malformed_request",
- "errors": [
- {
- "field": "string",
- "message": "string"
}
], - "request_id": "string"
}Public, so an account blocked by AUTHBASE_REQUIRE_ACCOUNT_EMAIL_VERIFICATION can ask again. Always 202; verified, disabled or unknown addresses get no email. The link opens {PUBLIC_URL}/account/verify-email and expires in 24 hours.
| email required | string <email> <= 254 characters |
{- "email": "user@example.com"
}{- "title": "string",
- "status": 100,
- "detail": "string",
- "instance": "string",
- "code": "malformed_request",
- "errors": [
- {
- "field": "string",
- "message": "string"
}
], - "request_id": "string"
}| token required | string (OneTimeToken) [ 1 .. 128 ] characters The |
{- "token": "string"
}{- "title": "string",
- "status": 100,
- "detail": "string",
- "instance": "string",
- "code": "malformed_request",
- "errors": [
- {
- "field": "string",
- "message": "string"
}
], - "request_id": "string"
}| email required | string <email> <= 254 characters |
| password required | string <password> <= 128 characters |
{- "email": "user@example.com",
- "password": "pa$$word"
}{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "email": "user@example.com",
- "email_verified": true,
- "name": "string",
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z"
}{- "title": "string",
- "status": 100,
- "detail": "string",
- "instance": "string",
- "code": "malformed_request",
- "errors": [
- {
- "field": "string",
- "message": "string"
}
], - "request_id": "string"
}Changing the email requires current_password (ASVS 3.7.1) and clears email_verified. A wrong current password answers invalid_credentials.
| name | string <= 100 characters |
string <email> <= 254 characters | |
| current_password | string <password> <= 128 characters Required when |
{- "name": "string",
- "email": "user@example.com",
- "current_password": "pa$$word"
}{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "email": "user@example.com",
- "email_verified": true,
- "name": "string",
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z"
}Requires current_password (ASVS 3.7.1). Refused with account_owns_apps while the account owns apps (ADR-018).
| current_password required | string <password> <= 128 characters |
{- "current_password": "pa$$word"
}{- "title": "string",
- "status": 100,
- "detail": "string",
- "instance": "string",
- "code": "malformed_request",
- "errors": [
- {
- "field": "string",
- "message": "string"
}
], - "request_id": "string"
}Newest first; current marks the session making this request.
{- "data": [
- {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "created_at": "2019-08-24T14:15:22Z",
- "last_seen_at": "2019-08-24T14:15:22Z",
- "expires_at": "2019-08-24T14:15:22Z",
- "ip": "string",
- "user_agent": "string",
- "current": true
}
]
}Another account's session, or an unknown id, is 404. Revoking the current session also clears the cookie.
| sessionId required | string <uuid> |
{- "title": "string",
- "status": 100,
- "detail": "string",
- "instance": "string",
- "code": "malformed_request",
- "errors": [
- {
- "field": "string",
- "message": "string"
}
], - "request_id": "string"
}Requires the current password. Every other session of the account is revoked.
| current_password required | string <password> <= 128 characters |
| new_password required | string <password> (Password) [ 12 .. 128 ] characters 12–128 characters, no composition rules (ARCHITECTURE §3.8, ASVS 4.0.3 2.1.1). |
{- "current_password": "pa$$word",
- "new_password": "pa$$word_qwe"
}{- "title": "string",
- "status": 100,
- "detail": "string",
- "instance": "string",
- "code": "malformed_request",
- "errors": [
- {
- "field": "string",
- "message": "string"
}
], - "request_id": "string"
}Generates the app's first Ed25519 signing key. The slug is immutable (ADR-028).
| name required | string [ 1 .. 100 ] characters |
| slug required | string [ 1 .. 63 ] characters ^[a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?$ Lowercase letters, digits and hyphens. Immutable; appears in the issuer URL. |
object (AppSettings) |
{- "name": "string",
- "slug": "string",
- "settings": {
- "access_token_ttl_s": 900,
- "refresh_token_ttl_s": 2592000,
- "email_verification": "off",
- "api_key_rotation_grace_s": 86400,
- "password_reset_url": "string",
- "email_verification_url": "string",
- "security_notifications": true
}
}{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "slug": "string",
- "name": "string",
- "settings": {
- "access_token_ttl_s": 900,
- "refresh_token_ttl_s": 2592000,
- "email_verification": "off",
- "api_key_rotation_grace_s": 86400,
- "password_reset_url": "string",
- "email_verification_url": "string",
- "security_notifications": true
}, - "issuer": "string",
- "jwks_uri": "string",
- "discovery_uri": "string",
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z"
}{- "data": [
- {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "slug": "string",
- "name": "string",
- "settings": {
- "access_token_ttl_s": 900,
- "refresh_token_ttl_s": 2592000,
- "email_verification": "off",
- "api_key_rotation_grace_s": 86400,
- "password_reset_url": "string",
- "email_verification_url": "string",
- "security_notifications": true
}, - "issuer": "string",
- "jwks_uri": "string",
- "discovery_uri": "string",
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z"
}
]
}{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "slug": "string",
- "name": "string",
- "settings": {
- "access_token_ttl_s": 900,
- "refresh_token_ttl_s": 2592000,
- "email_verification": "off",
- "api_key_rotation_grace_s": 86400,
- "password_reset_url": "string",
- "email_verification_url": "string",
- "security_notifications": true
}, - "issuer": "string",
- "jwks_uri": "string",
- "discovery_uri": "string",
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z"
}Settings keys not present are left unchanged. The slug cannot change.
| appId required | string <uuid> |
| name | string [ 1 .. 100 ] characters |
object (AppSettings) |
{- "name": "string",
- "settings": {
- "access_token_ttl_s": 900,
- "refresh_token_ttl_s": 2592000,
- "email_verification": "off",
- "api_key_rotation_grace_s": 86400,
- "password_reset_url": "string",
- "email_verification_url": "string",
- "security_notifications": true
}
}{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "slug": "string",
- "name": "string",
- "settings": {
- "access_token_ttl_s": 900,
- "refresh_token_ttl_s": 2592000,
- "email_verification": "off",
- "api_key_rotation_grace_s": 86400,
- "password_reset_url": "string",
- "email_verification_url": "string",
- "security_notifications": true
}, - "issuer": "string",
- "jwks_uri": "string",
- "discovery_uri": "string",
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z"
}Final. confirm must equal the app's slug. Cascades to users, keys, tokens and the app's audit events (ADR-018).
| appId required | string <uuid> |
| confirm required | string Must equal the app's slug. |
{- "confirm": "string"
}{- "title": "string",
- "status": 100,
- "detail": "string",
- "instance": "string",
- "code": "malformed_request",
- "errors": [
- {
- "field": "string",
- "message": "string"
}
], - "request_id": "string"
}{- "data": [
- {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "name": "string",
- "prefix": "string",
- "status": "active",
- "created_at": "2019-08-24T14:15:22Z",
- "last_used_at": "2019-08-24T14:15:22Z",
- "expires_at": "2019-08-24T14:15:22Z",
- "revoked_at": "2019-08-24T14:15:22Z"
}
]
}The plaintext key is returned once, in this response only.
| appId required | string <uuid> |
| name required | string [ 1 .. 100 ] characters |
{- "name": "string"
}{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "name": "string",
- "prefix": "string",
- "status": "active",
- "created_at": "2019-08-24T14:15:22Z",
- "last_used_at": "2019-08-24T14:15:22Z",
- "expires_at": "2019-08-24T14:15:22Z",
- "revoked_at": "2019-08-24T14:15:22Z",
- "key": "string"
}Creates a new key and gives every other live key an expiry of
now + grace (default: the app's api_key_rotation_grace_s, 0 allowed).
Both keys work during the grace period.
| appId required | string <uuid> |
| name required | string [ 1 .. 100 ] characters |
| grace_seconds | integer [ 0 .. 604800 ] |
{- "name": "string",
- "grace_seconds": 0
}{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "name": "string",
- "prefix": "string",
- "status": "active",
- "created_at": "2019-08-24T14:15:22Z",
- "last_used_at": "2019-08-24T14:15:22Z",
- "expires_at": "2019-08-24T14:15:22Z",
- "revoked_at": "2019-08-24T14:15:22Z",
- "key": "string"
}| appId required | string <uuid> |
| keyId required | string <uuid> |
{- "title": "string",
- "status": 100,
- "detail": "string",
- "instance": "string",
- "code": "malformed_request",
- "errors": [
- {
- "field": "string",
- "message": "string"
}
], - "request_id": "string"
}{- "data": [
- {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "alg": "string",
- "status": "active",
- "created_at": "2019-08-24T14:15:22Z",
- "retire_after": "2019-08-24T14:15:22Z",
- "retired_at": "2019-08-24T14:15:22Z",
- "public_key": {
- "kty": "string",
- "crv": "string",
- "kid": "string",
- "x": "string",
- "alg": "string",
- "use": "string"
}
}
]
}Generates a new active key. The previous key stays published as
retiring until every token it could have signed has expired
(max access-token TTL + 5 min), then is retired automatically.
| appId required | string <uuid> |
{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "alg": "string",
- "status": "active",
- "created_at": "2019-08-24T14:15:22Z",
- "retire_after": "2019-08-24T14:15:22Z",
- "retired_at": "2019-08-24T14:15:22Z",
- "public_key": {
- "kty": "string",
- "crv": "string",
- "kid": "string",
- "x": "string",
- "alg": "string",
- "use": "string"
}
}Active and retiring public keys. Served with Cache-Control: public, max-age=300.
| slug required | string^[a-z0-9]([a-z0-9-]{0,61}[a-z0-9])?$ |
{- "keys": [
- {
- "kty": "string",
- "crv": "string",
- "kid": "string",
- "x": "string",
- "alg": "string",
- "use": "string"
}
]
}{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "slug": "string",
- "name": "string",
- "settings": {
- "access_token_ttl_s": 900,
- "refresh_token_ttl_s": 2592000,
- "email_verification": "off",
- "api_key_rotation_grace_s": 86400,
- "password_reset_url": "string",
- "email_verification_url": "string",
- "security_notifications": true
}, - "issuer": "string",
- "jwks_uri": "string",
- "discovery_uri": "string",
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z"
}| email required | string <email> <= 254 characters |
| password | string <password> (Password) [ 12 .. 128 ] characters 12–128 characters, no composition rules (ARCHITECTURE §3.8, ASVS 4.0.3 2.1.1). |
| username | string (Username) [ 3 .. 64 ] characters ^[A-Za-z0-9._-]+$ |
object (Metadata) Free-form JSON object, at most 16 KiB. Not included in access tokens. | |
| roles | Array of strings (Roles) <= 50 items unique [ items [ 1 .. 64 ] characters ^[A-Za-z0-9_:.-]+$ ] |
{- "email": "user@example.com",
- "password": "pa$$word_qwe",
- "username": "string",
- "metadata": { },
- "roles": [
- "string"
]
}{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "email": "user@example.com",
- "username": "string",
- "email_verified": true,
- "roles": [
- "string"
], - "metadata": { },
- "disabled": true,
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z",
- "last_login_at": "2019-08-24T14:15:22Z"
}| q | string <= 254 characters Case-insensitive prefix match on email or username. |
| role | string <= 64 characters Only users holding this role. |
| limit | integer [ 1 .. 200 ] Default: 50 |
| cursor | string <= 512 characters
|
{- "data": [
- {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "email": "user@example.com",
- "username": "string",
- "email_verified": true,
- "roles": [
- "string"
], - "metadata": { },
- "disabled": true,
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z",
- "last_login_at": "2019-08-24T14:15:22Z"
}
], - "next_cursor": "string"
}{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "email": "user@example.com",
- "username": "string",
- "email_verified": true,
- "roles": [
- "string"
], - "metadata": { },
- "disabled": true,
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z",
- "last_login_at": "2019-08-24T14:15:22Z"
}metadata replaces the whole object. username: null clears it.
| userId required | string <uuid> |
string <email> <= 254 characters | |
| username | string or null [ 3 .. 64 ] characters ^[A-Za-z0-9._-]+$ |
object (Metadata) Free-form JSON object, at most 16 KiB. Not included in access tokens. | |
| roles | Array of strings (Roles) <= 50 items unique [ items [ 1 .. 64 ] characters ^[A-Za-z0-9_:.-]+$ ] |
| disabled | boolean |
{- "email": "user@example.com",
- "username": "string",
- "metadata": { },
- "roles": [
- "string"
], - "disabled": true
}{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "email": "user@example.com",
- "username": "string",
- "email_verified": true,
- "roles": [
- "string"
], - "metadata": { },
- "disabled": true,
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z",
- "last_login_at": "2019-08-24T14:15:22Z"
}{- "title": "string",
- "status": 100,
- "detail": "string",
- "instance": "string",
- "code": "malformed_request",
- "errors": [
- {
- "field": "string",
- "message": "string"
}
], - "request_id": "string"
}No current password needed. Every refresh-token family of the user is revoked. Audited as user.password_admin_set.
| userId required | string <uuid> |
| password required | string <password> (Password) [ 12 .. 128 ] characters 12–128 characters, no composition rules (ARCHITECTURE §3.8, ASVS 4.0.3 2.1.1). |
{- "password": "pa$$word_qwe"
}{- "title": "string",
- "status": 100,
- "detail": "string",
- "instance": "string",
- "code": "malformed_request",
- "errors": [
- {
- "field": "string",
- "message": "string"
}
], - "request_id": "string"
}Every refresh-token family of the user is revoked.
| userId required | string <uuid> |
| current_password required | string <password> <= 128 characters |
| new_password required | string <password> (Password) [ 12 .. 128 ] characters 12–128 characters, no composition rules (ARCHITECTURE §3.8, ASVS 4.0.3 2.1.1). |
{- "current_password": "pa$$word",
- "new_password": "pa$$word_qwe"
}{- "title": "string",
- "status": 100,
- "detail": "string",
- "instance": "string",
- "code": "malformed_request",
- "errors": [
- {
- "field": "string",
- "message": "string"
}
], - "request_id": "string"
}Revokes every refresh-token family. Access tokens already issued expire naturally (ADR-009).
| userId required | string <uuid> |
{- "title": "string",
- "status": 100,
- "detail": "string",
- "instance": "string",
- "code": "malformed_request",
- "errors": [
- {
- "field": "string",
- "message": "string"
}
], - "request_id": "string"
}| appId required | string <uuid> |
| q | string <= 254 characters Case-insensitive prefix match on email or username. |
| role | string <= 64 characters Only users holding this role. |
| limit | integer [ 1 .. 200 ] Default: 50 |
| cursor | string <= 512 characters
|
{- "data": [
- {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "email": "user@example.com",
- "username": "string",
- "email_verified": true,
- "roles": [
- "string"
], - "metadata": { },
- "disabled": true,
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z",
- "last_login_at": "2019-08-24T14:15:22Z"
}
], - "next_cursor": "string"
}| appId required | string <uuid> |
| userId required | string <uuid> |
{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "email": "user@example.com",
- "username": "string",
- "email_verified": true,
- "roles": [
- "string"
], - "metadata": { },
- "disabled": true,
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z",
- "last_login_at": "2019-08-24T14:15:22Z"
}| appId required | string <uuid> |
| userId required | string <uuid> |
string <email> <= 254 characters | |
| username | string or null [ 3 .. 64 ] characters ^[A-Za-z0-9._-]+$ |
object (Metadata) Free-form JSON object, at most 16 KiB. Not included in access tokens. | |
| roles | Array of strings (Roles) <= 50 items unique [ items [ 1 .. 64 ] characters ^[A-Za-z0-9_:.-]+$ ] |
| disabled | boolean |
{- "email": "user@example.com",
- "username": "string",
- "metadata": { },
- "roles": [
- "string"
], - "disabled": true
}{- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "email": "user@example.com",
- "username": "string",
- "email_verified": true,
- "roles": [
- "string"
], - "metadata": { },
- "disabled": true,
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z",
- "last_login_at": "2019-08-24T14:15:22Z"
}| appId required | string <uuid> |
| userId required | string <uuid> |
{- "title": "string",
- "status": 100,
- "detail": "string",
- "instance": "string",
- "code": "malformed_request",
- "errors": [
- {
- "field": "string",
- "message": "string"
}
], - "request_id": "string"
}| appId required | string <uuid> |
| userId required | string <uuid> |
{- "title": "string",
- "status": 100,
- "detail": "string",
- "instance": "string",
- "code": "malformed_request",
- "errors": [
- {
- "field": "string",
- "message": "string"
}
], - "request_id": "string"
}Verifies the password and returns an access token (JWT, EdDSA) and a
refresh token. Unknown identifier and wrong password are
indistinguishable. Repeated failures lock the identifier
(429 account_locked, Retry-After).
| identifier required | string [ 1 .. 254 ] characters Email or username. |
| password required | string <password> [ 1 .. 128 ] characters |
| client_ip | string (ClientIp) <= 45 characters The end-user's IP as seen by your backend; used for rate limiting and audit. Defaults to the connection address. |
| user_agent | string (ClientUserAgent) <= 512 characters |
{- "identifier": "string",
- "password": "pa$$word",
- "client_ip": "string",
- "user_agent": "string"
}{- "access_token": "string",
- "token_type": "Bearer",
- "expires_in": 0,
- "refresh_token": "string",
- "refresh_expires_in": 0,
- "user": {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "email": "user@example.com",
- "username": "string",
- "email_verified": true,
- "roles": [
- "string"
], - "metadata": { },
- "disabled": true,
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z",
- "last_login_at": "2019-08-24T14:15:22Z"
}
}Every refresh returns a new refresh token; the presented one is
dead. Presenting an already-used token revokes its whole family
(theft detection, ADR-011) and answers refresh_token_reused.
| refresh_token required | string [ 1 .. 128 ] characters |
| client_ip | string (ClientIp) <= 45 characters The end-user's IP as seen by your backend; used for rate limiting and audit. Defaults to the connection address. |
| user_agent | string (ClientUserAgent) <= 512 characters |
{- "refresh_token": "string",
- "client_ip": "string",
- "user_agent": "string"
}{- "access_token": "string",
- "token_type": "Bearer",
- "expires_in": 0,
- "refresh_token": "string",
- "refresh_expires_in": 0,
- "user": {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "email": "user@example.com",
- "username": "string",
- "email_verified": true,
- "roles": [
- "string"
], - "metadata": { },
- "disabled": true,
- "created_at": "2019-08-24T14:15:22Z",
- "updated_at": "2019-08-24T14:15:22Z",
- "last_login_at": "2019-08-24T14:15:22Z"
}
}| refresh_token required | string [ 1 .. 128 ] characters |
{- "refresh_token": "string"
}{- "title": "string",
- "status": 100,
- "detail": "string",
- "instance": "string",
- "code": "malformed_request",
- "errors": [
- {
- "field": "string",
- "message": "string"
}
], - "request_id": "string"
}Always 202, whether or not the email belongs to a user of this app, so the response reveals nothing. The link goes to the app's password_reset_url or the hosted page, is single-use and expires in 30 minutes. Rate limited per end-user IP (client_ip).
| email required | string <email> <= 254 characters |
| client_ip | string (ClientIp) <= 45 characters The end-user's IP as seen by your backend; used for rate limiting and audit. Defaults to the connection address. |
{- "email": "user@example.com",
- "client_ip": "string"
}{- "title": "string",
- "status": 100,
- "detail": "string",
- "instance": "string",
- "code": "malformed_request",
- "errors": [
- {
- "field": "string",
- "message": "string"
}
], - "request_id": "string"
}Consumes the token, sets the password, verifies the email address (the link proved control of it) and revokes every refresh-token family of the user.
| token required | string (OneTimeToken) [ 1 .. 128 ] characters The |
| new_password required | string <password> (Password) [ 12 .. 128 ] characters 12–128 characters, no composition rules (ARCHITECTURE §3.8, ASVS 4.0.3 2.1.1). |
{- "token": "string",
- "new_password": "pa$$word_qwe"
}{- "title": "string",
- "status": 100,
- "detail": "string",
- "instance": "string",
- "code": "malformed_request",
- "errors": [
- {
- "field": "string",
- "message": "string"
}
], - "request_id": "string"
}Works whatever the app's email_verification mode (that mode governs the automatic email on sign-up and the login check). A user who is already verified, or disabled, gets no email; the answer is 202 either way. The link goes to the app's email_verification_url or the hosted page and expires in 24 hours. Rate limited per end-user IP (client_ip).
| user_id required | string <uuid> |
| client_ip | string (ClientIp) <= 45 characters The end-user's IP as seen by your backend; used for rate limiting and audit. Defaults to the connection address. |
{- "user_id": "a169451c-8525-4352-b8ca-070dd449a1a5",
- "client_ip": "string"
}{- "title": "string",
- "status": 100,
- "detail": "string",
- "instance": "string",
- "code": "malformed_request",
- "errors": [
- {
- "field": "string",
- "message": "string"
}
], - "request_id": "string"
}For your own verification page (email_verification_url); the hosted page does the same.
| token required | string (OneTimeToken) [ 1 .. 128 ] characters The |
{- "token": "string"
}{- "title": "string",
- "status": 100,
- "detail": "string",
- "instance": "string",
- "code": "malformed_request",
- "errors": [
- {
- "field": "string",
- "message": "string"
}
], - "request_id": "string"
}| appId required | string <uuid> |
| action | string <= 64 characters Exact action name, e.g. |
| actor_id | string <uuid> |
| limit | integer [ 1 .. 200 ] Default: 50 |
| cursor | string <= 512 characters
|
{- "data": [
- {
- "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
- "action": "string",
- "actor_type": "account",
- "actor_id": "04f37679-bfbf-4906-b749-01756515cecf",
- "target_type": "string",
- "target_id": "d3bcdc92-4191-401b-ad0c-42056c6efab9",
- "ip": "string",
- "metadata": { },
- "created_at": "2019-08-24T14:15:22Z"
}
], - "next_cursor": "string"
}