Authentication

Log in to the Innorix API and obtain an access token.

Every API call must be authenticated. This example logs in with your account credentials, receives an access token, and attaches it to all subsequent requests. It also shows how to refresh an expired token.

Steps

  1. Send your email and password to POST /api/auth/login.
  2. Read accessToken from the response.
  3. Send it as a Bearer token (with your workspace ID) on every request.
  4. Refresh the token when it expires, or log out to end the session.

Configuration

Set your credentials and IDs via environment variables or a .env file (INNORIX_BASE_URL, INNORIX_WORKSPACE_ID, INNORIX_EMAIL, INNORIX_PASSWORD, and the INNORIX_SOURCE_ID / INNORIX_TARGET_ID / path variables the example uses).

API

MethodEndpointDescription
POST/api/auth/loginLog in and receive an access token
GET/api/auth/meGet the current authenticated user
POST/api/auth/refresh-tokenRefresh an expired access token
GET/api/auth/logoutEnd the current session
python
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
""" 01 - Authentication =================== Log in, inspect the current user, and (optionally) refresh the token. This is the foundation every other example builds on. This file is self-contained: it embeds a minimal client so it can be read and run on its own. Fill in the configuration below (or set the matching INNORIX_* environment variables / .env file). Endpoints: POST /api/auth/login GET /api/auth/me GET /api/auth/get-token GET /api/auth/logout Run: python 01_auth.py """ from __future__ import annotations import os import json import logging import requests try: # optional .env support from dotenv import load_dotenv load_dotenv() except ImportError: pass # --------------------------------------------------------------------------- # # Configuration # --------------------------------------------------------------------------- # BASE_URL = os.getenv("INNORIX_BASE_URL", "https://app.innorix.com") WORKSPACE_ID = os.getenv("INNORIX_WORKSPACE_ID", "<WORKSPACE_ID>") EMAIL = os.getenv("INNORIX_EMAIL", "<YOUR_EMAIL>") PASSWORD = os.getenv("INNORIX_PASSWORD", "<YOUR_PASSWORD>") logging.basicConfig(level=logging.INFO, format="%(asctime)s [%(levelname)s] %(message)s", datefmt="%H:%M:%S") log = logging.getLogger("innorix") # --------------------------------------------------------------------------- # # Minimal client # --------------------------------------------------------------------------- # class ApiError(RuntimeError): """Raised when the API returns a non-2xx response.""" class InnorixClient: def __init__(self, base_url: str, workspace_id: str, timeout: float = 15.0): self.base_url = base_url.rstrip("/") self.workspace_id = workspace_id self.timeout = timeout self.session = requests.Session() def _request(self, method: str, path: str, **kwargs): kwargs.setdefault("timeout", self.timeout) res = self.session.request(method, f"{self.base_url}{path}", **kwargs) try: res.raise_for_status() except requests.HTTPError as exc: raise ApiError(f"{method} {path} -> {res.status_code}: {res.text[:500]}") from exc if not res.content: return None try: return res.json() except ValueError: return res.text def login(self, email: str, password: str) -> str: data = self._request("POST", "/api/auth/login", json={"email": email, "password": password}, timeout=10) token = data["data"]["user"]["accessToken"] self.session.headers.update({ "Authorization": f"Bearer {token}", "x-workspace-id": self.workspace_id, "Content-Type": "application/json", }) log.info("logged in") return token def refresh_token(self, refresh_token: str) -> str: data = self._request("POST", "/api/auth/refresh-token", headers={"X-Refresh-Token": refresh_token}, timeout=10) token = data["data"]["user"]["accessToken"] self.session.headers["Authorization"] = f"Bearer {token}" return token def get_token(self): return self._request("GET", "/api/auth/get-token", timeout=10) def me(self): return self._request("GET", "/api/auth/me", timeout=10) def logout(self): return self._request("GET", "/api/auth/logout", timeout=10) # --------------------------------------------------------------------------- # # Run # --------------------------------------------------------------------------- # def main() -> None: client = InnorixClient(BASE_URL, WORKSPACE_ID) client.login(EMAIL, PASSWORD) # Who am I? me = client.me() print(json.dumps(me, indent=2, ensure_ascii=False)) # When the access token expires you can either: # - client.refresh_token(<refresh_token>) (header X-Refresh-Token) # - client.get_token() (GET /api/auth/get-token) # token = client.refresh_token("<REFRESH_TOKEN>") # client.logout() # end the session when you are done if __name__ == "__main__": main()