Skip to content

Authentication ​

POST /api/auth/bootstrap ​

Create the first administrator

  • Access: No authentication
  • Body: email, password (12+ characters)

POST /api/auth/challenge ​

Finish sign-in with an authenticator code

  • Access: No authentication
  • Body: challenge, code

POST /api/auth/forgot ​

Email a password reset link (always answers ok)

  • Access: No authentication
  • Body: email

POST /api/auth/login ​

Sign in with a password (and authenticator code, or stepwise for a challenge)

  • Access: No authentication
  • Body: email, password, totp?, stepwise?

POST /api/auth/logout ​

Sign out

  • Access: Signed-in user (browser session)

GET /api/auth/me ​

The signed-in user

  • Access: Signed-in user (browser session); also reachable with an API token that has the read scope

POST /api/auth/passkey/options ​

Start a passkey sign-in (second factor)

  • Access: No authentication
  • Body: challenge

POST /api/auth/passkey/verify ​

Finish a passkey sign-in

  • Access: No authentication
  • Body: challenge, response

GET /api/auth/passkeys ​

Your passkeys

  • Access: Signed-in user (browser session)

DELETE /api/auth/passkeys/{id} ​

Remove a passkey

  • Access: Signed-in user (browser session)
  • Path parameters: id

POST /api/auth/passkeys/options ​

Start registering a passkey

  • Access: Signed-in user (browser session)

POST /api/auth/passkeys/verify ​

Finish registering a passkey

  • Access: Signed-in user (browser session)
  • Body: response, name?

POST /api/auth/password ​

Change your password and revoke other sessions

  • Access: Signed-in user (browser session)

PUT /api/auth/preferences ​

Choose light, dark or system for yourself (null for the default)

  • Access: Signed-in user (browser session)
  • Body: mode

POST /api/auth/recover ​

Reset a password with a recovery code

  • Access: No authentication
  • Body: email, recoveryCode, password

GET /api/auth/sessions ​

Your signed-in devices

  • Access: Signed-in user (browser session)

DELETE /api/auth/sessions/{id} ​

Sign a device out

  • Access: Signed-in user (browser session)
  • Path parameters: id

POST /api/auth/sessions/revoke-others ​

Sign out everywhere else

  • Access: Signed-in user (browser session)

GET /api/auth/status ​

Whether the first administrator still has to be created

  • Access: No authentication

POST /api/auth/token/accept ​

Set a password from an invitation or reset link

  • Access: No authentication
  • Body: token, password

GET /api/tokens ​

API tokens

  • Access: Administrator

POST /api/tokens ​

Create an API token (scopes: read, provision, suspend)

  • Access: Administrator
  • Body: name, scopes[], expiresAt?

DELETE /api/tokens/{id} ​

Revoke an API token

  • Access: Administrator
  • Path parameters: id

Released under the AGPL-3.0-only license.