Introduction
The Public API is a gRPC server: clients generated from our .proto files call it with type-safe messages. For added flexibility, every RPC is also served by a REST gateway over plain HTTP and JSON.
The gRPC server implements server reflection, so tools such as grpcurl and Postman can list its methods and build example requests without the .proto files.
Two integration surfaces
Section titled “Two integration surfaces”| Surface | What it is for | How you authenticate |
|---|---|---|
| Public API (gRPC + REST gateway) | Server-to-server access to an office’s workspaces, registers and file uploads. | A TOTP LogIn returns a Bearer token. See Public API authentication. |
| OIDC provider (“Sign in with Ubikap”) | Lets a Ubikap member sign in to your application, and tells you which office they belong to (office_key). | OAuth 2.0 authorization code flow with PKCE. See OIDC provider. |
The two are independent: the Public API does not accept an OIDC access token, and a Public API token is not an OIDC token.
Where to go next
Section titled “Where to go next”- Getting Started: generate a client and make your first Public API call.
- gRPC: endpoint,
.protofiles, server reflection and status codes, with grpcurl and Postman examples. - Sign in with Ubikap: the complete OIDC sign-in, from the authorization URL to
office_key. - Upload a document: send a PDF through a presigned POST and attach it to a register.
- OIDC tokens and refresh: token lifetimes, refresh token rotation and what revokes a sign-in.