Skip to content

Authentication

Client Credentials authentication is implemented for system-to-system integration.

Implemented model

  • Single integration client configured through environment variables
  • POST /api/v1/auth/token with HTTP Basic credentials
  • JWT access tokens signed with HS256
  • Default access token lifetime: 60 minutes
  • No refresh tokens and no scopes in this version
  • Bearer middleware protects inbound work-order routes when AUTH_ENABLED=true

See the API guide: Authentication.

Transport

  • Production must use HTTPS / TLS
  • Local development may use HTTP on trusted networks
  • Controlled HTTP is allowed only on trusted local networks