Skip to content

Public API authentication

Ubikap gives you a Public API user:

  • a userUuid (a UUIDv7);
  • a TOTP secret, to enroll in an authenticator application or a TOTP library: it produces 8-digit codes.

The user is granted access to one or more offices. A token is always issued for one office.

Call AuthenticationService.LogIn (REST: POST /services.authentication.v1.AuthenticationService/LogIn). It needs no token.

FieldDescription
officeScope.target.office.keyKey of the office to act on, e.g. OFC_1234.
userUuidYour Public API user’s UUIDv7.
userCodeThe current 8-digit TOTP code.
{
"officeScope": { "target": { "office": { "key": "OFC_1234" } } },
"userUuid": "01920000-0000-7000-8000-000000000000",
"userCode": "12345678"
}

The response is { "token": "<jwt>" }.

The proto also declares officeUserScope and partnershipScope, but no RPC accepts their tokens yet: use officeScope.

Send the token on every other call:

  • gRPC: metadata authorization: Bearer <token>;
  • REST: header Authorization: Bearer <token>.

The token only gives access to the office it was issued for. To work on another office, log in again with that office’s key.

The token expires 30 minutes after it was issued, and there is no refresh RPC.

Log in again each time you start working with the API, rather than keeping a token around. Within a long run, a call that answers UNAUTHENTICATED (401) means it is time to call LogIn again, with a new TOTP code.

StatusMessageCause
401Missing Authorization headerNo Authorization header or metadata.
400—The header is not exactly Bearer <token>.
400Invalid OTP codeWrong or expired TOTP code.
400User with id '…' not foundUnknown userUuid.
403—Your user has no access to the requested office.

The Public API token is unrelated to the OIDC provider: the Public API refuses OIDC access tokens, and the OIDC provider knows nothing about Public API users.