Skip to content

Authentication API ​

Base URL: https://your-domain.com

Authentication endpoints for both admin/staff users and subscribers.


Modules ​

ModuleDescription
📁 User AuthenticationAdmin/Staff login, logout, token refresh
📁 Subscriber AuthenticationSubscriber login, logout, token refresh

Quick Reference ​

User Authentication ​

MethodEndpointDescription
POST/api/v1/users/loginAdmin/Staff login (30-day token)
GET/api/v1/users/profileGet current user
POST/api/v1/users/refresh-tokenRefresh token
POST/api/v1/users/logoutLogout (current token)
POST/api/v1/users/logout-allLogout all devices

Subscriber Authentication ​

MethodEndpointDescription
POST/api/v1/subscriber/loginSubscriber login (30-day token)
GET/api/v1/subscriber/profileGet profile
POST/api/v1/subscriber/refresh-tokenRefresh token
POST/api/v1/subscriber/logoutSubscriber logout
POST/api/v1/subscriber/logout-allLogout all devices

Token Usage ​

After successful login, include the token in all authenticated requests:

http
Authorization: Bearer your-auth-token

Token Expiry ​

TokenLifetimeRenew with
User (Admin/Staff/Reseller)30 days (configurable)POST /api/v1/users/refresh-token
Subscriber30 days (configurable)POST /api/v1/subscriber/refresh-token

Every login and refresh response includes expires_at (server time). Refresh shortly before that time.

API token rules — read before you integrate

  • Lifetime: 30 days from login or refresh (server-configurable with API_USER_TOKEN_DAYS). The exact moment is in data.expires_at (server time).
  • Refreshing rotates the token. POST /api/v1/users/refresh-token returns a new token and the old one stops working at once — overwrite what you stored.
  • A token is revoked before expires_at when:
    • the user account is disabled (status ≠ 1),
    • the user's password is changed — by the user or by an admin — every token of that user is deleted,
    • Logout / Logout All Devices is called.
  • An expired or revoked token cannot be refreshed — the request gets 401 Unauthenticated.. Log in again; treat 401 as "get a new token", never as a bug.
  • Login is rate-limited to 5 attempts per minute per username + IP — cache the token, don't log in per request.

Subscriber tokens follow the same rules except the disabled/password checks: a subscriber whose package has expired can still log in to pay.

See the Quickstart for a client that handles refresh and re-login automatically.

www.onezeroart.com