Skip to content

Authentication

The Comcent API authenticates every request with a session token: sign in with a user’s email and password, then send the token as a bearer token. This works the same on Comcent Cloud (https://app.comcent.io) and on a self-hosted instance (your own domain). Requests act as that user, with that user’s role in each organization.

Terminal window
curl -X POST https://app.comcent.io/api/v2/auth/login \
-H "Content-Type: application/json" \
-d '{"email": "you@example.com", "password": "…"}'

On a self-hosted instance, use your own domain instead of app.comcent.io.

The response contains token and user.

Include the token in the Authorization header of every request:

Terminal window
curl https://app.comcent.io/api/v2/acme/queues \
-H "Authorization: Bearer <token>"

Here acme is your organization’s subdomain.

  • Session tokens are valid for 30 days. Sign in again to get a new one.
  • Resetting a user’s password invalidates every session token issued before the reset.
  • On a self-hosted instance, tokens are signed with the instance’s SIGNING_KEY; changing that key invalidates all sessions.

See the REST API overview for the available endpoints.

If you run into authentication problems, open an issue on GitHub.