Skip to main content

User authentication

User authentication creates a session token associated with a project, user, and user level. Send that token only to the Ordering API over HTTPS.

The current authentication operation is:

POST https://api.ordering.co/v400/en/{project}/auth

Replace {project} with the project code you are authorized to access. The operation can accept email or cellphone credentials, and the current contract also includes one-time-password and device-code fields. Use the request schema in Scalar as the authority for the selected login mode.

Session response​

A successful response can include session data similar to this sanitized fragment:

{
"result": {
"session": {
"access_token": "[REDACTED]",
"token_type": "bearer",
"expires_in": 3600
}
}
}

The values are placeholders. Do not copy tokens from logs, screenshots, or documentation into an application.

Send the token​

Operations protected by bearer authentication expect the Authorization header:

Authorization: Bearer YOUR_ACCESS_TOKEN

Treat the token as a credential. Keep it out of URLs, source control, analytics, and persistent browser storage unless your security design explicitly requires and protects that storage.

User-level restrictions remain operation-specific. Review the operation's security requirements and the Users model before making a request.

Legacy SDK example​

The archived SDK material used a token setter similar to this:

ordering.setToken('<access-token>')

The archived SDK pages also document a differently named setAccessToken() method. Confirm the SDK package and version before relying on either method; the HTTP bearer header is the maintained contract.