Overview
The Authentication module handles identity verification for all users and provides user lifecycle management within your tenant. Dashboard sessions authenticate with HttpOnly cookies (ratel_access_token, ratel_refresh_token) set by the login endpoint — tokens are never exposed in response bodies. Server-to-server integrations authenticate with an X-API-Key: rk_live_... header, using keys managed via /api/v1/auth/api-keys.
Common Workflows
New team member onboarding: ABANK_ADMIN creates a user account → The new user receives a welcome email → They log in and begin using the dashboard.
Session refresh: When your access cookie expires (every 15 minutes), call the refresh endpoint to rotate the session cookies without prompting for credentials again.
Permissions
Endpoints
Login
Authenticate with email and password. On success the API sets two HttpOnly session cookies —ratel_access_token and ratel_refresh_token. Tokens are never returned in the response body.
Request Body
Example Request
The session cookies
ratel_access_token (15 minutes) and
ratel_refresh_token (7 days) are set as HttpOnly Set-Cookie headers. If
the tenant’s MFA policy requires it, the response instead carries
mfaRequired (or mfaSetupRequired) with a short-lived tempToken for
POST /api/v1/auth/mfa/verify or POST /api/v1/auth/mfa/setup.Refresh Token
Rotate the session cookies without re-entering credentials. The currentratel_refresh_token cookie is read automatically — no request body is required.
Example Request
Refreshing rotates both cookies: a fresh
ratel_access_token (valid for
15 minutes) and a new ratel_refresh_token (valid for 7 days).Get My Profile
Retrieve the currently authenticated user’s details, including their tenant. Example RequestList Users
Retrieve all users within your tenant. Query Parameters
Example Request
Create User
Add a new user to your tenant. The new user will receive a welcome email with login instructions. Request Body
Example Request
Update User
Modify a user’s details or role. Path Parameters
Request Body
All fields are optional.
Example Request
Deactivate User
Soft-delete a user by deactivating their account. Path Parameters
Example Request