Keystone Developers
Open Keystone
API reference

Auth service

Auth

10 endpoints.

POST/api/v1/auth/forgot-password

Forgot Password

Parameters

NameInTypeDescription
X-Recaptcha-Tokenheaderstring | null
X-Recaptcha-Key-Typeheaderstring | null

Request bodyrequired

application/jsonForgotPasswordRequest
FieldTypeDescription
emailrequiredstring (email)

Responses

200Successful Response
application/jsonany
  • 422Validation Error

Error bodies: HTTPValidationError. See Errors.

POST/api/v1/auth/login

Login

OAuth2 compatible token login, get an access token for future requests.

Parameters

NameInTypeDescription
X-Recaptcha-Tokenheaderstring | null
X-Recaptcha-Key-Typeheaderstring | null

Request bodyrequired

application/x-www-form-urlencodedBody_login_api_v1_auth_login_post
FieldTypeDescription
grant_typestring | null
usernamerequiredstring
passwordrequiredstring (password)
scopestringdefault ""
client_idstring | null
client_secretstring | null

Responses

200Successful Response
application/jsonToken

Token, expanded above.

  • 422Validation Error

Error bodies: HTTPValidationError. See Errors.

POST/api/v1/auth/logout

Logout

Request bodyrequired

application/jsonLogoutRequest
FieldTypeDescription
refresh_tokenrequiredstring

Responses

200Successful Response
application/jsonany
  • 422Validation Error

Error bodies: HTTPValidationError. See Errors.

POST/api/v1/auth/refresh

Refresh Token

Rotate refresh token.

Request bodyrequired

application/jsonRefreshTokenRequest
FieldTypeDescription
refresh_tokenrequiredstring

Responses

200Successful Response
application/jsonToken
FieldTypeDescription
access_tokenrequiredstring
token_typerequiredstring
refresh_tokenrequiredstring
  • 422Validation Error

Error bodies: HTTPValidationError. See Errors.

POST/api/v1/auth/resend-verification

Resend Verification

Parameters

NameInTypeDescription
X-Recaptcha-Tokenheaderstring | null
X-Recaptcha-Key-Typeheaderstring | null

Request bodyrequired

application/jsonResendVerificationRequest
FieldTypeDescription
emailrequiredstring

Responses

200Successful Response
application/jsonany
  • 422Validation Error

Error bodies: HTTPValidationError. See Errors.

POST/api/v1/auth/reset-password

Reset Password

Parameters

NameInTypeDescription
X-Recaptcha-Tokenheaderstring | null
X-Recaptcha-Key-Typeheaderstring | null

Request bodyrequired

application/jsonResetPasswordRequest
FieldTypeDescription
tokenstring | null
emailstring (email) | null
otpstring | null
new_passwordrequiredstring

Responses

200Successful Response
application/jsonany
  • 422Validation Error

Error bodies: HTTPValidationError. See Errors.

POST/api/v1/auth/signup

Create User

Create new user (201), or resend the code to a pending one (200).

Parameters

NameInTypeDescription
X-Recaptcha-Tokenheaderstring | null
X-Recaptcha-Key-Typeheaderstring | null

Request bodyrequired

application/jsonUserCreate
FieldTypeDescription
emailrequiredstring (email)
first_namerequiredstring
last_namerequiredstring
is_activeboolean | nulldefault true
passwordrequiredstring
invite_idstring | null

Responses

201Successful Response
application/jsonUserResponse
FieldTypeDescription
emailrequiredstring (email)
first_namestring | null
last_namestring | null
is_activeboolean | nulldefault true
idrequiredstring (uuid)
role_idrequiredinteger
created_atrequiredstring (date-time)
updated_atrequiredstring (date-time)
avatar_urlstring | null
  • 422Validation Error

Error bodies: HTTPValidationError. See Errors.

POST/api/v1/auth/social

Social Login

Social Login (Google). Verifies ID Token, finds/creates user, issues JWTs.

Request bodyrequired

application/jsonSocialLoginRequest
FieldTypeDescription
providerrequiredstring
tokenrequiredstring

Responses

200Successful Response
application/jsonToken

Token, expanded above.

  • 422Validation Error

Error bodies: HTTPValidationError. See Errors.

GET/api/v1/auth/verify-email

Verify Email Token

Parameters

NameInTypeDescription
tokenrequiredquerystring

Responses

200Successful Response
application/jsonany
  • 422Validation Error

Error bodies: HTTPValidationError. See Errors.

POST/api/v1/auth/verify-email

Verify Email Otp

Verify by the emailed six-digit code and sign the user in. 409 ALREADY_VERIFIED for a verified account, 401 ACCOUNT_INACTIVE for an inactive one, 400 INVALID_OTP otherwise.

Parameters

NameInTypeDescription
X-Recaptcha-Tokenheaderstring | null
X-Recaptcha-Key-Typeheaderstring | null

Request bodyrequired

application/jsonVerifyEmailOtpRequest
FieldTypeDescription
emailrequiredstring (email)
otprequiredstring

Responses

200Successful Response
application/jsonToken

Token, expanded above.

  • 422Validation Error

Error bodies: HTTPValidationError. See Errors.