Skip to content
This page View Markdown Open in ChatGPT Open in Claude

Auth of an API user

Every non-public API needs the token of an API user : the application calling. It is the first of the two gates.

Header x-am-authorization: <token>
Get it POST /api/system-api/<user path>/token with { "u", "p", "expiresInSeconds"? }
Answer { "token", "refresh_token", "expires_in" }
In code g.req.auth.authAMUser : the API user, with its name and groups.
Get the token
{ "u": "default", "p": "12345", "expiresInSeconds": 259200 }
Who is calling
const apiUser = g.req.auth.authAMUser;
g.logger.log(apiUser.name, apiUser.groups);
  • expiresInSeconds is optional : jwtOptions.expiresIn of the configuration otherwise, 72 hours by default. Refresh with { "refresh_token" } while the refresh token is valid (refreshTokenValidForS after the token expired, 900 seconds by default).
  • The groups of the API user decide which APIs, tables and fields the application reaches. A person token, when the API asks for one, narrows it further.