Authentication Flow
Login, token management, and session lifecycle
Authentication
This guide covers the complete authentication flow for accessing the PRIME API.
Overview
The platform supports two authentication methods:
- JWT Bearer Tokens - For user sessions (web/mobile clients)
- API Keys - For programmatic access (see API Key Creation)
Prerequisites
- Valid user credentials (username/password)
- TOTP authenticator configured (if 2FA is enabled)
Step 1: Login
Authenticate with username and password.
Endpoint: POST /api/rest/v1/users/authentication/login
Request
Request Fields
Response (200 OK)
Response Fields
Step 2: Login with 2FA
If 2FA is enabled, include the TOTP code in the challenge field.
Request
The response is the same as a successful login without 2FA.
Step 3: Using the Access Token
Include the access token in the Authorization header for all subsequent API requests.
Step 4: Refreshing Tokens
Before the access token expires, use the refresh token to obtain a new one.
Endpoint: POST /api/rest/v1/users/authentication/refresh
Request
Request Fields
Response (200 OK)
Step 5: Logout
Invalidate the current session or all sessions.
Endpoint: POST /api/rest/v1/users/authentication/logout
Request (Logout specific session)
Request (Logout all sessions)
Request Fields
Response (200 OK)
Empty response on success.
Error Scenarios
Related
- API Key Creation - Create API keys for programmatic access
- Getting Started: Authentication - Detailed auth documentation