Appearance
Authentication API
Base URL:
https://your-domain.com
Authentication endpoints for both admin/staff users and subscribers.
Modules
| Module | Description |
|---|---|
| 📁 User Authentication | Admin/Staff login, logout, token refresh |
| 📁 Subscriber Authentication | Subscriber login, logout, token refresh |
Quick Reference
User Authentication
| Method | Endpoint | Description |
|---|---|---|
| POST | /api/v1/users/login | Admin/Staff login (30-day token) |
| GET | /api/v1/users/profile | Get current user |
| POST | /api/v1/users/refresh-token | Refresh token |
| POST | /api/v1/users/logout | Logout (current token) |
| POST | /api/v1/users/logout-all | Logout all devices |
Subscriber Authentication
| Method | Endpoint | Description |
|---|---|---|
| POST | /api/v1/subscriber/login | Subscriber login (30-day token) |
| GET | /api/v1/subscriber/profile | Get profile |
| POST | /api/v1/subscriber/refresh-token | Refresh token |
| POST | /api/v1/subscriber/logout | Subscriber logout |
| POST | /api/v1/subscriber/logout-all | Logout all devices |
Token Usage
After successful login, include the token in all authenticated requests:
http
Authorization: Bearer your-auth-tokenToken Expiry
| Token | Lifetime | Renew with |
|---|---|---|
| User (Admin/Staff/Reseller) | 30 days (configurable) | POST /api/v1/users/refresh-token |
| Subscriber | 30 days (configurable) | POST /api/v1/subscriber/refresh-token |
Every login and refresh response includes expires_at (server time). Refresh shortly before that time.
API token rules — read before you integrate
- Lifetime: 30 days from login or refresh (server-configurable with
API_USER_TOKEN_DAYS). The exact moment is indata.expires_at(server time). - Refreshing rotates the token.
POST /api/v1/users/refresh-tokenreturns a new token and the old one stops working at once — overwrite what you stored. - A token is revoked before
expires_atwhen:- the user account is disabled (
status≠ 1), - the user's password is changed — by the user or by an admin — every token of that user is deleted,
- Logout / Logout All Devices is called.
- the user account is disabled (
- An expired or revoked token cannot be refreshed — the request gets
401 Unauthenticated.. Log in again; treat401as "get a new token", never as a bug. - Login is rate-limited to 5 attempts per minute per username + IP — cache the token, don't log in per request.
Subscriber tokens follow the same rules except the disabled/password checks: a subscriber whose package has expired can still log in to pay.
See the Quickstart for a client that handles refresh and re-login automatically.
