Skip to main content

Overview

The Authentication module handles identity verification for all users and provides user lifecycle management within your tenant. Dashboard sessions authenticate with HttpOnly cookies (ratel_access_token, ratel_refresh_token) set by the login endpoint — tokens are never exposed in response bodies. Server-to-server integrations authenticate with an X-API-Key: rk_live_... header, using keys managed via /api/v1/auth/api-keys.

Common Workflows

New team member onboarding: A BANK_ADMIN creates a user account → The new user receives a welcome email → They log in and begin using the dashboard. Session refresh: When your access cookie expires (every 15 minutes), call the refresh endpoint to rotate the session cookies without prompting for credentials again.

Permissions

Endpoints


Login

Authenticate with email and password. On success the API sets two HttpOnly session cookies — ratel_access_token and ratel_refresh_token. Tokens are never returned in the response body. Request Body Example Request
Example Response -200 OK
The session cookies ratel_access_token (15 minutes) and ratel_refresh_token (7 days) are set as HttpOnly Set-Cookie headers. If the tenant’s MFA policy requires it, the response instead carries mfaRequired (or mfaSetupRequired) with a short-lived tempToken for POST /api/v1/auth/mfa/verify or POST /api/v1/auth/mfa/setup.
Example Response -401 Unauthorized

Refresh Token

Rotate the session cookies without re-entering credentials. The current ratel_refresh_token cookie is read automatically — no request body is required. Example Request
Example Response -200 OK
Refreshing rotates both cookies: a fresh ratel_access_token (valid for 15 minutes) and a new ratel_refresh_token (valid for 7 days).

Get My Profile

Retrieve the currently authenticated user’s details, including their tenant. Example Request
Example Response -200 OK

List Users

Retrieve all users within your tenant. Query Parameters Example Request
Example Response -200 OK

Create User

Add a new user to your tenant. The new user will receive a welcome email with login instructions. Request Body Example Request
Example Response -201 Created
Example Response -409 Conflict

Update User

Modify a user’s details or role. Path Parameters Request Body All fields are optional. Example Request
Example Response -200 OK

Deactivate User

Soft-delete a user by deactivating their account. Path Parameters Example Request
Example Response -200 OK
Deactivated users cannot log in but their audit history and case contributions are preserved for compliance.