Authentication
Authentication
The PRIME API supports two authentication methods: JWT Bearer Tokens for user sessions and API Keys for programmatic access.
Authentication Methods
Bearer Token Authentication
After login, use the JWT access token in the Authorization header.
Header Format
JWT Structure
The access token is a JWT signed with HMAC-SHA256 containing:
Standard Claims:
Custom Claims:
Token Lifecycle
API Key Authentication
For programmatic access, use HMAC-SHA256 signed requests.
Header Format
Components
Signature Calculation
-
Build the hash input (single-space separated). Omit any empty field — do not leave a placeholder space for it:
For a request with no query string, content type, or body, the input ends at
<Path>with no trailing spaces. -
Hash the input:
-
Sign the hash. The API secret is a 64-character hex string; hex-decode it to a 32-byte key before signing (do not use its UTF-8 bytes):
Example (Python)
Time Window
Requests must be within 150 seconds of the server time. Requests outside this window are rejected.
MFA (Multi-Factor Authentication)
When MFA is enabled for a user, login requires a TOTP code provided in the challenge field of the login request.
Login Flow with MFA
-
Attempt Login Without TOTP - If MFA is enabled, returns error:
Response (401 Unauthorized):
-
Login With TOTP Code - Include the
challengefield: -
Receive Tokens - On success:
Recovery Codes
Recovery codes are generated during MFA setup and can be used as alternatives to TOTP codes when the authenticator device is unavailable. Use a recovery code in place of the TOTP code in the challenge field.
Related Endpoints
Token Refresh
Before the access token expires, use the refresh token to obtain a new access token.
Request
Response
Authentication Errors
Best Practices
- Store tokens securely - Never expose tokens in URLs or logs
- Refresh proactively - Refresh tokens before expiration
- Use API keys for automation - Don’t embed user credentials in scripts
- Rotate API keys regularly - Create new keys and revoke old ones
- IP whitelist API keys - Restrict to known IP addresses
- Minimum permissions - Request only necessary permissions