Skip to content

Introduction

The Public API is a gRPC server: clients generated from our .proto files call it with type-safe messages. For added flexibility, every RPC is also served by a REST gateway over plain HTTP and JSON.

The gRPC server implements server reflection, so tools such as grpcurl and Postman can list its methods and build example requests without the .proto files.

SurfaceWhat it is forHow you authenticate
Public API (gRPC + REST gateway)Server-to-server access to an office’s workspaces, registers and file uploads.A TOTP LogIn returns a Bearer token. See Public API authentication.
OIDC provider (“Sign in with Ubikap”)Lets a Ubikap member sign in to your application, and tells you which office they belong to (office_key).OAuth 2.0 authorization code flow with PKCE. See OIDC provider.

The two are independent: the Public API does not accept an OIDC access token, and a Public API token is not an OIDC token.