Authentication
POST /api/auth/bootstrap
Create the first administrator
- Access: No authentication
- Body: email, password (12+ characters)
POST /api/auth/challenge
Finish sign-in with an authenticator code
- Access: No authentication
- Body: challenge, code
POST /api/auth/forgot
Email a password reset link (always answers ok)
- Access: No authentication
- Body: email
POST /api/auth/login
Sign in with a password (and authenticator code, or stepwise for a challenge)
- Access: No authentication
- Body: email, password, totp?, stepwise?
POST /api/auth/logout
Sign out
- Access: Signed-in user (browser session)
GET /api/auth/me
The signed-in user
- Access: Signed-in user (browser session); also reachable with an API token that has the
readscope
POST /api/auth/passkey/options
Start a passkey sign-in (second factor)
- Access: No authentication
- Body: challenge
POST /api/auth/passkey/verify
Finish a passkey sign-in
- Access: No authentication
- Body: challenge, response
GET /api/auth/passkeys
Your passkeys
- Access: Signed-in user (browser session)
DELETE /api/auth/passkeys/{id}
Remove a passkey
- Access: Signed-in user (browser session)
- Path parameters:
id
POST /api/auth/passkeys/options
Start registering a passkey
- Access: Signed-in user (browser session)
POST /api/auth/passkeys/verify
Finish registering a passkey
- Access: Signed-in user (browser session)
- Body: response, name?
POST /api/auth/password
Change your password and revoke other sessions
- Access: Signed-in user (browser session)
PUT /api/auth/preferences
Choose light, dark or system for yourself (null for the default)
- Access: Signed-in user (browser session)
- Body: mode
POST /api/auth/recover
Reset a password with a recovery code
- Access: No authentication
- Body: email, recoveryCode, password
GET /api/auth/sessions
Your signed-in devices
- Access: Signed-in user (browser session)
DELETE /api/auth/sessions/{id}
Sign a device out
- Access: Signed-in user (browser session)
- Path parameters:
id
POST /api/auth/sessions/revoke-others
Sign out everywhere else
- Access: Signed-in user (browser session)
GET /api/auth/status
Whether the first administrator still has to be created
- Access: No authentication
POST /api/auth/token/accept
Set a password from an invitation or reset link
- Access: No authentication
- Body: token, password
GET /api/tokens
API tokens
- Access: Administrator
POST /api/tokens
Create an API token (scopes: read, provision, suspend)
- Access: Administrator
- Body: name, scopes[], expiresAt?
DELETE /api/tokens/{id}
Revoke an API token
- Access: Administrator
- Path parameters:
id
