APIs and SDKs
Authentication and API keys
Requests are authenticated with a token in the Authorization header: a user session token from an auth table, a superuser token, or a Project API key for trusted server code.
Authenticate a user
Sign in against an auth table with an identity (email or username, depending on the table configuration) and a password. The response carries the user record and a token.
curl -X POST $PROJECT_URL/api/v1/collections/users/auth-with-password \
-H "Content-Type: application/json" \
-d '{"identity":"[email protected]","password":"a-strong-password"}'{
"token": "eyJhbGciOiJIUzI1NiIs...",
"record": {
"id": "b7s0x1c9k2m4q8f",
"collectionId": "users_table_id",
"collectionName": "users",
"email": "[email protected]",
"verified": true,
"created": "2026-01-14 08:12:03.221Z",
"updated": "2026-02-02 11:40:55.004Z"
}
}Send the token
Attach the token to every authenticated request. The SDKs do this for you once a sign-in succeeds, and they keep the session in their auth store.
curl $PROJECT_URL/api/v1/collections/posts/records \
-H "Authorization: eyJhbGciOiJIUzI1NiIs..."Available sign-in methods
| Method | Endpoint | Notes |
|---|---|---|
List methods | GET /api/v1/collections/{table}/auth-methods | What the table has enabled |
Password | POST /api/v1/collections/{table}/auth-with-password | Identity fields are configurable per table |
OAuth2 | POST /api/v1/collections/{table}/auth-with-oauth2 | Provider, code, verifier, redirect URL |
One-time password | POST /api/v1/collections/{table}/request-otp then /auth-with-otp | Email-delivered code |
Refresh | POST /api/v1/collections/{table}/auth-refresh | Extends an existing session |
Impersonate | POST /api/v1/collections/{table}/impersonate/{id} | Superuser only |
When multi-factor authentication is enabled, the first step returns an mfaId that must be sent with the second factor.
Email flows
- POST /api/v1/collections/{table}/request-verification and /confirm-verification
- POST /api/v1/collections/{table}/request-password-reset and /confirm-password-reset
- POST /api/v1/collections/{table}/request-email-change and /confirm-email-change
Project API keys
Create scoped API keys in the Project console for servers, automation, and CI. A key is shown once at creation, is sent in the same Authorization header, and can be revoked without touching user sessions.
- Give each key the smallest set of tables and actions it needs.
- Name each key after the system that uses it.
- Rotate a key immediately if it appears in a log, a repository, or a browser bundle.
Superuser sessions and API keys must stay on the server. Browser and mobile applications should only ever hold a user session token.
Fix it yourself. The link below opens this file in GitHub's editor and forks the repository for you if you need one, and your change becomes a pull request without leaving the browser.