Auth#
Sign-in, session validation, one-time sign-in tokens, password resets and two-factor authentication. Every endpoint in this folder is public: none requires an Authorization token.Concepts#
Business users are client-side users that belong to a business. They sign in with email and password, or with a one-time sign-in (OTS) token sent by email.
KIO users are internal employees. They sign in with Google (token in Log in) or with Apple. Session token: every successful sign-in returns a JWT in token and the user's permission slugs in permissions. Send the token in the Authorization header (Bearer <token> or the raw token) on authenticated endpoints. It is valid for 30 days, except tokens issued with an OTS token, which are valid for 24 hours.
Two-factor authentication (2FA) applies only to business users signing in with a password, unless 2FA is disabled for the user (two_factor_auth_unavailable):On the first sign-in, a grace period starts (TWO_FA_GRACE_DAYS, default 30 days). While it lasts, Log in returns the session directly. Every confirmed 2FA code or OTS sign-in starts a new grace period.
Codes can be requested once every OTS_TWO_FA_COOLDOWN_SECONDS (default 120 s), up to OTS_TWO_FA_DAILY_LIMIT (default 8) per day.
One-time sign-in (OTS) tokens: a passwordless sign-in for business users. Tokens are 6 characters, expire after 5 minutes, can be requested once every 2 minutes, and are limited to 6 requests or sign-ins per user per day.
Password resets: the reset email carries a token valid for 24 hours. New passwords need at least 8 characters with an uppercase letter, a lowercase letter, a digit and a special character, and expire after 90 days.
Endpoints#
Signs in a business user with email and password (with 2FA), or a KIO user with Google.POST /v1/auth/apple-loginSigns in a KIO user with Sign in with Apple.POST /v1/auth/confirm-login-2faFinishes a password sign-in with the emailed 2FA code.POST /v1/auth/enable-two-factor-authActivates 2FA for a business user and starts a new grace period.GET /v1/auth/validate-tokenChecks a session token and returns its owner.POST /v1/auth/generate-ots-tokenEmails an OTS token to a business user.POST /v1/auth/validate-ots-tokenExchanges an OTS token for a 24-hour session.POST /v1/auth/forgot-password-requestEmails a password reset link to a business user.GET /v1/auth/reset-password-request/{token}Validates a reset token and returns its user.POST /v1/auth/reset-passwordSets a new password with a reset token.POST /v1/auth/business-register-requestPlaceholder; echoes the request body.Source#
Router: routes/v1/auth.js
Controller: controllers/auth.js
Services: services/jwt.js, services/auth-apple.js, services/mailing.js
Models: models/business_user.js, models/business_user_access_token.js, models/user.js
Email templates: generate-token, ots-token-limit, resetPassword
Modified at 2026-10-05 19:51:57