Single-Use Auth Token
Use this endpoint to obtain a temporary login token after authenticating with your session ID (access token). This token allows for secure user logins in third-party or mobile apps without needing to store credentials.
Use this endpoint after obtaining an Access Token (Session ID) with the end user’s credentials. It returns a single-use login token that you can append to Magentrix’s login page URL to securely authenticate the user. The one-time token automatically logs the user in and cannot be reused.
curl POST 'https://{domain}/api/3.0/authtoken'
-H 'Authorization: Bearer {access_token}'
-H 'Content-Type: application/json'
-H 'Accept: application/json'
Note: The user's session will time out based on the Organization Settings in your Magentrix org. Once the session has expired (due to inactivity), the user gets logged out.
Delegated AuthToken
If you wish to log in as a user without using the user's credentials, you can use an administrator's Access Token (Session ID) instead and pass the target user's record ID in the body of the request. The system will authorize this action as long as the administrator's session ID is valid.
curl POST 'https://{domain}/api/3.0/delegatedauthtoken'
-H 'Authorization: Bearer {access_token}'
-H 'Content-Type: application/json'
-H 'Accept: application/json'
-d '{
"userId": "{userId}"
}'
Response
HTTP 200 OK
{
"token": "dasWERWERWSADAWQsdfdsf234asdasdw4asdasdF-DGFDGFDS23sfdfsw434sdfx_sda"
}Note: This token is safe to use as a URL parameter, and you do not need to do URL encoding. Also, this token is only valid for 1 minute, and the system won't accept it once it has expired.
Once you have this single-use token, you can forward the user to your org's login endpoint:
FORWARD 'https://{domain}/user/login?token={token}'After the user has successfully logged in, they will be forwarded to their appropriate login flow or landing pages.