Skip to content
Odinex Cloud
API reference

Auth

GET
/auth/csrf

Call once before the first POST from a fresh browser (any response sets the cookie when it is missing).

Response Body

Cookie set

curl -X GET "https://example.com/auth/csrf"
Empty
GET
/auth/providers

Response Body

Providers

application/json
  1. response
providers*array<>
curl -X GET "https://example.com/auth/providers"
{  "providers": [    "google"  ]}

Create an account

POST
/auth/signup

Request Body

application/json
  1. body
email*string
Formatemail
Lengthlength <= 254
password*string
Length10 <= length <= 128
name*string
Length1 <= length <= 100

Response Body

Account created and signed in; a verification email was sent.

application/json
  1. response
user*
organizations*array<>
mfa_required*boolean

True while the session still needs a second factor; other endpoints return 401 mfa_required.

curl -X POST "https://example.com/auth/signup" \  -H "Content-Type: application/json" \  -d '{    "email": "[email protected]",    "password": "stringstri",    "name": "string"  }'
{  "user": {    "id": 0,    "email": "string",    "name": "string",    "locale": "string",    "email_verified": true,    "mfa_enabled": true,    "has_password": true,    "created": "2019-08-24T14:15:22Z"  },  "organizations": [    {      "id": 0,      "name": "string",      "kind": "personal",      "role": "owner",      "status": "active"    }  ],  "mfa_required": true}
POST
/auth/login

Request Body

application/json
  1. body
email*string
Formatemail
password*string

Response Body

Signed in. If mfa_required is true, call /auth/mfa/totp next.

application/json
  1. response
user*
organizations*array<>
mfa_required*boolean

True while the session still needs a second factor; other endpoints return 401 mfa_required.

curl -X POST "https://example.com/auth/login" \  -H "Content-Type: application/json" \  -d '{    "email": "[email protected]",    "password": "string"  }'
{  "user": {    "id": 0,    "email": "string",    "name": "string",    "locale": "string",    "email_verified": true,    "mfa_enabled": true,    "has_password": true,    "created": "2019-08-24T14:15:22Z"  },  "organizations": [    {      "id": 0,      "name": "string",      "kind": "personal",      "role": "owner",      "status": "active"    }  ],  "mfa_required": true}
POST
/auth/mfa/totp

Authorization

cookieAuth
cookieodx_session<token>

Request Body

application/json
  1. body
code*string

6-digit TOTP code or a recovery code

Response Body

Session is now fully authenticated.

application/json
  1. response
user*
organizations*array<>
mfa_required*boolean

True while the session still needs a second factor; other endpoints return 401 mfa_required.

curl -X POST "https://example.com/auth/mfa/totp" \  -H "Content-Type: application/json" \  -d '{    "code": "string"  }'
{  "user": {    "id": 0,    "email": "string",    "name": "string",    "locale": "string",    "email_verified": true,    "mfa_enabled": true,    "has_password": true,    "created": "2019-08-24T14:15:22Z"  },  "organizations": [    {      "id": 0,      "name": "string",      "kind": "personal",      "role": "owner",      "status": "active"    }  ],  "mfa_required": true}
POST
/auth/logout

Authorization

cookieAuth
cookieodx_session<token>

Response Body

Signed out

curl -X POST "https://example.com/auth/logout"
Empty
POST
/auth/verify-email

Request Body

application/json
  1. body
token*string

Response Body

Email verified

curl -X POST "https://example.com/auth/verify-email" \  -H "Content-Type: application/json" \  -d '{    "token": "string"  }'
Empty
POST
/auth/verify-email/resend

Authorization

cookieAuth
cookieodx_session<token>

Response Body

Sent (rate limited)

curl -X POST "https://example.com/auth/verify-email/resend"
Empty
POST
/auth/password/forgot

Always returns 204, whether or not the address exists.

Request Body

application/json
  1. body
email*string
Formatemail

Response Body

Accepted

curl -X POST "https://example.com/auth/password/forgot" \  -H "Content-Type: application/json" \  -d '{    "email": "[email protected]"  }'
Empty
POST
/auth/password/reset

Revokes all existing sessions of the user.

Request Body

application/json
  1. body
token*string
password*string
Length10 <= length <= 128

Response Body

Password changed

curl -X POST "https://example.com/auth/password/reset" \  -H "Content-Type: application/json" \  -d '{    "token": "string",    "password": "stringstri"  }'
Empty
GET
/auth/oauth/{provider}/start

Path Parameters

provider*string
Value in"google""github"

Response Body

Redirect to the provider

curl -X GET "https://example.com/auth/oauth/google/start"
Empty
GET
/auth/oauth/{provider}/callback

Path Parameters

provider*string
Value in"google""github"

Query Parameters

code?string
state?string
error?string

Response Body

Redirect to the console

curl -X GET "https://example.com/auth/oauth/google/callback"
Empty