Authentication
The Comcent API authenticates every request with a session token: sign in with a user’s email and password, then send the token as a bearer token. This works the same on Comcent Cloud (https://app.comcent.io) and on a self-hosted instance (your own domain). Requests act as that user, with that user’s role in each organization.
Get a session token
Section titled “Get a session token”curl -X POST https://app.comcent.io/api/v2/auth/login \ -H "Content-Type: application/json" \ -d '{"email": "you@example.com", "password": "…"}'On a self-hosted instance, use your own domain instead of app.comcent.io.
The response contains token and user.
Send the token
Section titled “Send the token”Include the token in the Authorization header of every request:
curl https://app.comcent.io/api/v2/acme/queues \ -H "Authorization: Bearer <token>"Here acme is your organization’s subdomain.
Token lifetime
Section titled “Token lifetime”- Session tokens are valid for 30 days. Sign in again to get a new one.
- Resetting a user’s password invalidates every session token issued before the reset.
- On a self-hosted instance, tokens are signed with the instance’s
SIGNING_KEY; changing that key invalidates all sessions.
See the REST API overview for the available endpoints.
Need help?
Section titled “Need help?”If you run into authentication problems, open an issue on GitHub.