Authentication
Log in to the Innorix API and obtain an access token.
Every API call must be authenticated. This example logs in with your account credentials, receives an access token, and attaches it to all subsequent requests. It also shows how to refresh an expired token.
Steps
- Send your email and password to
POST /api/auth/login. - Read
accessTokenfrom the response. - Send it as a
Bearertoken (with your workspace ID) on every request. - Refresh the token when it expires, or log out to end the session.
Configuration
Set your credentials and IDs via environment variables or a .env file (INNORIX_BASE_URL, INNORIX_WORKSPACE_ID, INNORIX_EMAIL, INNORIX_PASSWORD, and the INNORIX_SOURCE_ID / INNORIX_TARGET_ID / path variables the example uses).
API
| Method | Endpoint | Description |
|---|---|---|
| POST | /api/auth/login | Log in and receive an access token |
| GET | /api/auth/me | Get the current authenticated user |
| POST | /api/auth/refresh-token | Refresh an expired access token |
| GET | /api/auth/logout | End the current session |
python
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
"""
01 - Authentication
===================
Log in, inspect the current user, and (optionally) refresh the token.
This is the foundation every other example builds on.
This file is self-contained: it embeds a minimal client so it can be read and
run on its own. Fill in the configuration below (or set the matching
INNORIX_* environment variables / .env file).
Endpoints:
POST /api/auth/login
GET /api/auth/me
GET /api/auth/get-token
GET /api/auth/logout
Run:
python 01_auth.py
"""
from __future__ import annotations
import os
import json
import logging
import requests
try: # optional .env support
from dotenv import load_dotenv
load_dotenv()
except ImportError:
pass
# --------------------------------------------------------------------------- #
# Configuration
# --------------------------------------------------------------------------- #
BASE_URL = os.getenv("INNORIX_BASE_URL", "https://app.innorix.com")
WORKSPACE_ID = os.getenv("INNORIX_WORKSPACE_ID", "<WORKSPACE_ID>")
EMAIL = os.getenv("INNORIX_EMAIL", "<YOUR_EMAIL>")
PASSWORD = os.getenv("INNORIX_PASSWORD", "<YOUR_PASSWORD>")
logging.basicConfig(level=logging.INFO,
format="%(asctime)s [%(levelname)s] %(message)s",
datefmt="%H:%M:%S")
log = logging.getLogger("innorix")
# --------------------------------------------------------------------------- #
# Minimal client
# --------------------------------------------------------------------------- #
class ApiError(RuntimeError):
"""Raised when the API returns a non-2xx response."""
class InnorixClient:
def __init__(self, base_url: str, workspace_id: str, timeout: float = 15.0):
self.base_url = base_url.rstrip("/")
self.workspace_id = workspace_id
self.timeout = timeout
self.session = requests.Session()
def _request(self, method: str, path: str, **kwargs):
kwargs.setdefault("timeout", self.timeout)
res = self.session.request(method, f"{self.base_url}{path}", **kwargs)
try:
res.raise_for_status()
except requests.HTTPError as exc:
raise ApiError(f"{method} {path} -> {res.status_code}: {res.text[:500]}") from exc
if not res.content:
return None
try:
return res.json()
except ValueError:
return res.text
def login(self, email: str, password: str) -> str:
data = self._request("POST", "/api/auth/login",
json={"email": email, "password": password}, timeout=10)
token = data["data"]["user"]["accessToken"]
self.session.headers.update({
"Authorization": f"Bearer {token}",
"x-workspace-id": self.workspace_id,
"Content-Type": "application/json",
})
log.info("logged in")
return token
def refresh_token(self, refresh_token: str) -> str:
data = self._request("POST", "/api/auth/refresh-token",
headers={"X-Refresh-Token": refresh_token}, timeout=10)
token = data["data"]["user"]["accessToken"]
self.session.headers["Authorization"] = f"Bearer {token}"
return token
def get_token(self):
return self._request("GET", "/api/auth/get-token", timeout=10)
def me(self):
return self._request("GET", "/api/auth/me", timeout=10)
def logout(self):
return self._request("GET", "/api/auth/logout", timeout=10)
# --------------------------------------------------------------------------- #
# Run
# --------------------------------------------------------------------------- #
def main() -> None:
client = InnorixClient(BASE_URL, WORKSPACE_ID)
client.login(EMAIL, PASSWORD)
# Who am I?
me = client.me()
print(json.dumps(me, indent=2, ensure_ascii=False))
# When the access token expires you can either:
# - client.refresh_token(<refresh_token>) (header X-Refresh-Token)
# - client.get_token() (GET /api/auth/get-token)
# token = client.refresh_token("<REFRESH_TOKEN>")
# client.logout() # end the session when you are done
if __name__ == "__main__":
main()