Mojo UpDocs
API reference

Cloud sign in

Sign-in providers

GET/auth/v1/providers

Mojo Up AI Cloud only. The sign-in buttons to show: the identity providers configured on this deployment, and email.

Response Body

application/json

curl -X GET "https://example.com/auth/v1/providers"
{  "providers": [    {      "id": "google",      "label": "string"    }  ]}
GET/auth/v1/start

Mojo Up AI Cloud only. Sends the browser to the provider (Google, GitHub, Microsoft or Facebook). After the person signs in there, Cloud returns them to redirect_uri with a one-time code (valid for 60 seconds) and your state, or with error. Exchange the code at /auth/v1/token. Uses PKCE with S256. Redirect addresses are allow-listed per client.

Query Parameters

provider*string

Value in

  • "google"
  • "github"
  • "microsoft"
  • "facebook"
client*string

Value in

  • "console"
  • "mobile"
redirect_uri*string

Where to return. Must be registered for the client.

code_challenge*string

The PKCE challenge: base64url SHA-256 of your verifier.

code_challenge_method?"S256"
Default"S256"

Value in

  • "S256"
state?string

Returned to you unchanged.

Lengthlength <= 500

Response Body

application/json

curl -X GET "https://example.com/auth/v1/start?provider=google&client=console&redirect_uri=string&code_challenge=string"
Empty

Email a sign-in code

POST/auth/v1/email/start

Mojo Up AI Cloud only. Emails a six-digit code that works for 10 minutes. Always answers 202, so it never reveals whether an address has an account. At most five codes per address per hour.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

curl -X POST "https://example.com/auth/v1/email/start" \  -H "Content-Type: application/json" \  -d '{    "email": "user@example.com",    "client": "console",    "redirect_uri": "string",    "code_challenge": "stringstringstringstringstringstringstrings"  }'
{}

Check an emailed code

POST/auth/v1/email/verify

Mojo Up AI Cloud only. Exchanges the six digits for a one-time code to send to /auth/v1/token. A code allows five tries.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

curl -X POST "https://example.com/auth/v1/email/verify" \  -H "Content-Type: application/json" \  -d '{    "email": "user@example.com",    "code": "string"  }'
{  "code": "string",  "state": "string"}

Get or refresh tokens

POST/auth/v1/token

Mojo Up AI Cloud only. OAuth 2.1 shaped: exchange a one-time code (with your PKCE verifier) or a refresh token for an access token (15 minutes by default) and a refresh token (30 days by default). Refresh tokens rotate on every use; presenting an old one again ends the whole session. Accepts JSON or form-encoded bodies.

Request Body

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

curl -X POST "https://example.com/auth/v1/token" \  -H "Content-Type: application/json" \  -d '{    "grant_type": "authorization_code",    "code": "string",    "code_verifier": "stringstringstringstringstringstringstrings",    "redirect_uri": "string"  }'
{  "access_token": "string",  "refresh_token": "string",  "expires_in": -9007199254740991,  "token_type": "Bearer"}

Sign out

POST/auth/v1/logout

Mojo Up AI Cloud only. Ends the session the access token belongs to, with every token issued in it.

Authorization

cloudSession
AuthorizationBearer <token>

Mojo Up AI Cloud: a person's access token from /auth/v1/token. Name the organisation with the X-Aioe-Organisation header where a request acts for one.

In: header

Response Body

curl -X POST "https://example.com/auth/v1/logout"
Empty