Skip to content

Authentication

Ubikap gives you a Synchro Service user:

  • a userUuid (a UUIDv7);
  • a TOTP secret, to enroll in a TOTP library: it produces 8-digit codes, with SHA-512 and a 30-second period. The codes of the previous and next periods are also accepted, to absorb clock drift.

The user is granted access to the offices that use your software, and to the RPCs listed in your contract. A token is always issued for one office.

Call AuthenticationService.LogIn (REST: POST /services.authentication.v1.AuthenticationService/LogIn). It needs no token.

FieldDescription
officeScope.target.office.externalIdThe office’s id in your software, e.g. 12345. Ubikap stored it when the office was connected to your software.
userUuidYour Synchro Service user’s UUIDv7.
userCodeThe current 8-digit TOTP code.
{
"officeScope": { "target": { "office": { "externalId": "12345" } } },
"userUuid": "01920000-0000-7000-8000-000000000000",
"userCode": "12345678"
}

The response is { "token": "<jwt>" }.

Send the token on every other call:

  • gRPC: metadata authorization: Bearer <token>;
  • REST: header Authorization: Bearer <token>.

The token only gives access to the office it was issued for. To synchronize another office, log in again with that office’s externalId.

The token expires 30 minutes after it was issued, and there is no refresh RPC.

Log in again each time you start working with the service — a synchronization to post, a state to poll — rather than keeping a token around. Within a long run, a call that answers UNAUTHENTICATED (401) Your token has expired means it is time to call LogIn again, with a new TOTP code.

gRPC statusHTTPMessageCause
INVALID_ARGUMENT400Unable to parse input DTO: …A missing field, a userUuid that is not a UUIDv7, a userCode that is not 8 digits.
INVALID_ARGUMENT400No office with this external id '…' existsNo Ubikap office is connected under this externalId.
INVALID_ARGUMENT400User with id '…' not foundUnknown userUuid.
INVALID_ARGUMENT400Invalid OTP codeWrong or expired TOTP code.
PERMISSION_DENIED403Action CAN_GET_TOKEN_FOR_OFFICE_SCOPE refused …Your user has no access to this office.

On the other RPCs:

gRPC statusHTTPMessageCause
UNAUTHENTICATED401Missing Authorization headerNo authorization metadata or header.
UNAUTHENTICATED401Your token has expiredLog in again.
UNAUTHENTICATED401Unable to verify the signature of the token (token invalid)The token was altered, or comes from another service or environment.
INVALID_ARGUMENT400Invalid Authorization metadata format. Expected "Bearer <token>"The value is not exactly Bearer <token>.
PERMISSION_DENIED403Action CAN_USE_ENDPOINT refused …Your user is not allowed to call this RPC.