/v1/auth
Identity and tokens — anonymous signup, service-account minting, whoami, and revoke.
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
curl -X POST "https://example.com/v1/auth/signup" \ -H "Content-Type: application/json" \ -d '{}'{ "token": "string", "jti": "string", "expires_at": "2019-08-24T14:15:22Z", "user_id": "string", "scope": "string", "tier": "string"}Authorization
bearer PASETO v4 public token (or deployment gate key). Auth-disabled dev instances accept any caller.
In: header
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/v1/auth/tokens" \ -H "Content-Type: application/json" \ -d '{ "subject": "string" }'{ "token": "string", "jti": "string", "expires_at": "2019-08-24T14:15:22Z"}Authorization
bearer PASETO v4 public token (or deployment gate key). Auth-disabled dev instances accept any caller.
In: header
Response Body
application/json
application/json
curl -X GET "https://example.com/v1/auth/whoami"{ "caller": "string", "tenant_id": "string", "deployment_preset": "string", "token": { "jti": "string", "iss": "string", "exp": 0 }, "effective_capabilities": [ "string" ]}Authorization
bearer PASETO v4 public token (or deployment gate key). Auth-disabled dev instances accept any caller.
In: header
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
curl -X POST "https://example.com/v1/auth/revoke" \ -H "Content-Type: application/json" \ -d '{ "jti": "string" }'CortexDB uses PASETO v4 public tokens. Every authenticated request carries
Authorization: Bearer <token> and X-Cortex-Actor (which must match the token's sub).
Endpoints
POST /v1/auth/signup {}— anonymous free-tier token (7-day TTL). Returns{ token, jti, user_id, scope, tier, expires_at }(jtiis what/v1/auth/revoketakes).POST /v1/auth/tokens— mint a service-account token (requires theauth.mintcapability;ttl_secondsis clamped to a 60 s minimum; a 7-day TTL was honoured on v0.9.13 and v0.10.1). Body:{ subject, scope?, ttl_seconds?, caps?, scopes? }.scopeonly says where yourauth.mintis checked (omit it for a deployment-wide check). It does not confine the minted token.capsnarrows the token's capabilities;capabilitiesis still accepted as an alias.scopesconfines capabilities to subtrees, each entry<capability>:<scope-path>[/*], for examplescope.read:org:acme/team:b/*. Entries are validated at mint: a bare path is422 INVALID_BODY.- The CLI sends
scopeswithcortexdb auth tokens --confine CAP:PREFIX(cortexdb-cli 0.6.0); its--scopeis the check location.
GET /v1/auth/whoami→{ caller, tenant_id, deployment_preset, token: { jti, iss, exp }, effective_capabilities }.POST /v1/auth/revoke { jti, reason }→204.
Signup/tokens return 503 on a keyed server unless the minter is enabled
On a server with a key configured (or an auto-generated one) and the v1 minter disabled, POST /v1/auth/signup and
POST /v1/auth/tokens return 503 NOT_CONFIGURED ("self-serve signup requires the v1 minter").
Enable minting with CORTEX_V1_MINTER_ENABLE=1, or have your IdP mint PASETO tokens that CortexDB
verifies. Under CORTEX_INSECURE_NO_AUTH=1 signup is served without the minter flag.
deployment_preset is dev_local on a keyed self-host, auth_disabled under
CORTEX_INSECURE_NO_AUTH=1 (vs cloud_shared_saas on the cloud).
Token enforcement (v0.9.10+)
A self-hosted server started with no CORTEX_API_KEY on a network bind generates a key and
enforces it: a request with only X-Cortex-Actor and no Authorization gets 401 MISSING_TOKEN, and a
minted token sent with a different actor gets 401 ACTOR_MISMATCH. Only
CORTEX_INSECURE_NO_AUTH=1 serves requests without a token. Before v0.9.10 an actor-only request was
accepted on the default dev_local preset. Error codes
follow the server's uppercase convention (MISSING_TOKEN, TOKEN_EXPIRED, ACTOR_MISMATCH,
POLICY_DENIED). See Authorization.