Authentication
Sign-in, sessions, two-factor authentication, password resets and personal API keys.
These endpoints are used by the web app and by people, never by integration keys. Most need a browser session; the sign-in, magic-link, invitation and password-reset endpoints are public.
See Authentication for how sign-in, 2FA, sessions and lockouts work, and Authentication & scopes for calling the API.
All paths are relative to /api/v1. Key is the scope an integration key needs, People the permission a signed-in person or personal key needs, and Feature the feature switch the endpoint belongs to. See how to read this reference.
- GET
/auth/api-keysYour personal API keys
Keynot allowedPeopleself (session) - POST
/auth/api-keysCreate a personal API key
Keynot allowedPeopleapi_keys.personal(session) - DELETE
/auth/api-keys/{id}Revoke one of your personal API keys
Keynot allowedPeopleself (session) - POST
/auth/invitations:acceptAccept an invitation and set a password
KeypublicPeoplepublic - POST
/auth/magic-linkEmail a single-use sign-in link
KeypublicPeoplepublic - POST
/auth/magic-link:redeemSign in with a magic link
KeypublicPeoplepublic - POST
/auth/mfa/recovery-codes:regenerateReplace your recovery codes
Keynot allowedPeopleself (session) - POST
/auth/mfa/totp:confirmTurn on two-factor authentication with a first code
Keynot allowedPeopleself (session) - POST
/auth/mfa/totp:disableTurn off two-factor authentication
Keynot allowedPeopleself (session) - POST
/auth/mfa/totp:setupStart setting up an authenticator app
Keynot allowedPeopleself (session) - POST
/auth/passwordChange your password
Keynot allowedPeopleself (session) - POST
/auth/password-resetEmail a password reset link
KeypublicPeoplepublic - POST
/auth/password-reset:completeChoose a new password with a reset link
KeypublicPeoplepublic - GET
/auth/sessionThe signed-in person: role, permissions, assignments and enabled features
Keynot allowedPeopleself - GET
/auth/sessionsYour active sessions and devices
Keynot allowedPeopleself (session) - DELETE
/auth/sessions/{id}Sign out one of your sessions
Keynot allowedPeopleself (session) - POST
/auth/sign-inSign in with email and password
KeypublicPeoplepublic - POST
/auth/sign-in/mfaFinish signing in with an authenticator or recovery code
Keynot allowedPeopleself (session) - POST
/auth/sign-outSign out this session
Keynot allowedPeopleself (session)