User authentication
User authentication creates a session token associated with a project, user, and user level. Send that token only to the Ordering API over HTTPS.
The current authentication operation is:
POST https://api.ordering.co/v400/en/{project}/auth
Replace {project} with the project code you are authorized to access. The operation can accept email or cellphone credentials, and the current contract also includes one-time-password and device-code fields. Use the request schema in Scalar as the authority for the selected login mode.
Session response
A successful response can include session data similar to this sanitized fragment:
{
"result": {
"session": {
"access_token": "[REDACTED]",
"token_type": "bearer",
"expires_in": 3600
}
}
}
The values are placeholders. Do not copy tokens from logs, screenshots, or documentation into an application.
Send the token
Operations protected by bearer authentication expect the Authorization header:
Authorization: Bearer YOUR_ACCESS_TOKEN
Treat the token as a credential. Keep it out of URLs, source control, analytics, and persistent browser storage unless your security design explicitly requires and protects that storage.
User-level restrictions remain operation-specific. Review the operation's security requirements and the Users model before making a request.
Legacy SDK example
The archived SDK material used a token setter similar to this:
ordering.setToken('<access-token>')
The archived SDK pages also document a differently named setAccessToken() method. Confirm the SDK package and version before relying on either method; the HTTP bearer header is the maintained contract.