Most business endpoints require Authorization: Bearer <token>. API bearer authentication is separate from the website's sign-in cookie.
1. Send credentials in JSON
POST /api/Authenication/login
Content-Type: application/json
{
"username": "YOUR_API_USERNAME",
"password": "YOUR_API_PASSWORD"
}
This route allows anonymous access. username and password are required. trustedDeviceToken and ipAddress are optional request fields. New integrations must use POST with a JSON body; legacy GET login is deprecated and its availability depends on the environment.
Read requiresTwoFactor, token and expiresUTC from the returned user object. Do not treat the user ID or a website cookie as an API token.
2. Complete two-factor verification when requested
When requiresTwoFactor is true, obtain the verification code through the account's configured channel and submit:
POST /api/Authenication/validate-two-factor
Content-Type: application/json
{
"username": "YOUR_API_USERNAME",
"code": "CODE_FROM_YOUR_ACCOUNT"
}
This route also allows anonymous access. username and code are required; ipAddress is optional. Use the token from the completed sign-in response. If no token is returned, stop and resolve the sign-in failure before making business requests.
3. Use and renew the bearer token
POST /api/Authenication/refresh-token
Authorization: Bearer <token>
Refresh has no request body and requires an accepted bearer token. A successful response contains a JSON string token, not an object with a token property. Renew before expiry; if authentication rejects the token, sign in again. Do not assume refresh can recover an already expired token.
Store tokens securely and never include passwords or tokens in query strings, application logs or shared examples.
Authentication exceptions
The documented anonymous routes are login, two-factor verification, the webhook handler and test receiver, and the early-repayment read. Receiver/test routes are not an integration authentication mechanism. All other guides assume bearer authentication; resource access still depends on the account's permissions.
Continue with your first request or application setup.
| Method | Route | Inputs | Swagger success |
|---|---|---|---|
POST | /api/Authenication/login | body: body — LoginRequest | 200: FullApplicationUser |
POST | /api/Authenication/validate-two-factor | body: body — TwoFactorLoginRequest | 200: FullApplicationUser |
POST | /api/Authenication/refresh-token | None | 200: string |