PurrOSDocs

Authentication

Sign-in, sessions, two-factor authentication, password resets and personal API keys.

These endpoints are used by the web app and by people, never by integration keys. Most need a browser session; the sign-in, magic-link, invitation and password-reset endpoints are public.

See Authentication for how sign-in, 2FA, sessions and lockouts work, and Authentication & scopes for calling the API.

All paths are relative to /api/v1. Key is the scope an integration key needs, People the permission a signed-in person or personal key needs, and Feature the feature switch the endpoint belongs to. See how to read this reference.

  • GET/auth/api-keys

    Your personal API keys

    Keynot allowed
    Peopleself (session)
  • POST/auth/api-keys

    Create a personal API key

    Keynot allowed
    Peopleapi_keys.personal (session)
  • DELETE/auth/api-keys/{id}

    Revoke one of your personal API keys

    Keynot allowed
    Peopleself (session)
  • POST/auth/invitations:accept

    Accept an invitation and set a password

    Keypublic
    Peoplepublic
  • POST/auth/magic-link

    Email a single-use sign-in link

    Keypublic
    Peoplepublic
  • POST/auth/magic-link:redeem

    Sign in with a magic link

    Keypublic
    Peoplepublic
  • POST/auth/mfa/recovery-codes:regenerate

    Replace your recovery codes

    Keynot allowed
    Peopleself (session)
  • POST/auth/mfa/totp:confirm

    Turn on two-factor authentication with a first code

    Keynot allowed
    Peopleself (session)
  • POST/auth/mfa/totp:disable

    Turn off two-factor authentication

    Keynot allowed
    Peopleself (session)
  • POST/auth/mfa/totp:setup

    Start setting up an authenticator app

    Keynot allowed
    Peopleself (session)
  • POST/auth/password

    Change your password

    Keynot allowed
    Peopleself (session)
  • POST/auth/password-reset

    Email a password reset link

    Keypublic
    Peoplepublic
  • POST/auth/password-reset:complete

    Choose a new password with a reset link

    Keypublic
    Peoplepublic
  • GET/auth/session

    The signed-in person: role, permissions, assignments and enabled features

    Keynot allowed
    Peopleself
  • GET/auth/sessions

    Your active sessions and devices

    Keynot allowed
    Peopleself (session)
  • DELETE/auth/sessions/{id}

    Sign out one of your sessions

    Keynot allowed
    Peopleself (session)
  • POST/auth/sign-in

    Sign in with email and password

    Keypublic
    Peoplepublic
  • POST/auth/sign-in/mfa

    Finish signing in with an authenticator or recovery code

    Keynot allowed
    Peopleself (session)
  • POST/auth/sign-out

    Sign out this session

    Keynot allowed
    Peopleself (session)