On this page

Golden 3.0.0 public API reference. Parameters, responses, and schemas for supported customer operations.

7 operations.

POST /api/security/auth

Authenticate user

Operation ID: authenticate

Authenticates a user using email and password or SSO token. Returns a JWT bearer token on success. Does not require authentication.

Security: None

Parameters

NameInRequiredTypeDescription
Accept-Languageheaderfalsestring—

Request body

Media typeRequiredSchema
application/jsontrueTzAuthRequestDto

Responses

StatusDescriptionBody
200Successful authenticationapplication/json: TzAuthResponseDto
401Unauthorized/: map of any JSON value
409Conflict/: map of any JSON value

POST /api/security/auth/logout

Log out of every device

Operation ID: logoutEverywhere

Revokes every refresh token belonging to the authenticated user, ending their sessions everywhere. Requires authentication. The access token already issued stays valid until it expires – it is stateless – so a short JWT lifetime is what bounds the window.

Security: bearerAuth

Responses

StatusDescriptionBody
200Every session was ended—
400The caller is an application token, which has no sessions—
401Unauthorized/: map of any JSON value
409Conflict/: map of any JSON value

POST /api/security/auth/refresh

Refresh authentication token

Operation ID: refreshToken

Exchanges a valid refresh token for a new JWT and refresh token pair. Does not require authentication.

Security: None

Request body

Media typeRequiredSchema
application/jsontrueTzRefreshRequestDto

Responses

StatusDescriptionBody
200Tokens refreshed successfullyapplication/json: TzRefreshResponseDto
401Invalid or expired refresh token/: map of any JSON value
409Conflict/: map of any JSON value

PUT /api/security/password/reset/{email}

Request password reset

Operation ID: requestPasswordReset

Requests a password reset for the specified email. Operation always succeeds (for security reasons, to avoid user enumeration). Does not require authentication.

Security: None

Parameters

NameInRequiredTypeDescription
emailpathtruestringminLength: 1
Accept-Languageheaderfalsestring—

Responses

StatusDescriptionBody
200Request processedapplication/json: TzAuthResponseDto
401Unauthorized/: map of any JSON value
409Conflict/: map of any JSON value

POST /api/security/password/update

Update password

Operation ID: updatePassword

Updates user password using a previously generated reset token. Does not require authentication.

Security: None

Parameters

NameInRequiredTypeDescription
Accept-Languageheaderfalsestring—

Request body

Media typeRequiredSchema
application/jsontrueTzPasswordUpdateRequestDto

Responses

StatusDescriptionBody
200Password updatedapplication/json: TzUserResponseDto
401Unauthorized/: map of any JSON value
409Conflict/: map of any JSON value

GET /api/security/sso/config

Get SSO configuration

Operation ID: getSsoConfig

Returns SSO provider configuration for frontend OAuth setup. Exposes only public information (client IDs, authorization endpoints, scopes). Does not require authentication.

Security: None

Parameters

NameInRequiredTypeDescription
Accept-Languageheaderfalsestring—

Responses

StatusDescriptionBody
200SSO configuration retrievedapplication/json: TzSsoConfigResponseDto
401Unauthorized/: map of any JSON value
409Conflict/: map of any JSON value

GET /api/security/whoami

Who am I?

Operation ID: whoami

Returns authentication context information. Does not require authentication.

Security: None

Parameters

NameInRequiredTypeDescription
Accept-Languageheaderfalsestring—

Responses

StatusDescriptionBody
200Operation successfulapplication/json: TzAuthResponseDto
401Unauthorized/: map of any JSON value
409Conflict/: map of any JSON value
Golden 3.0.0 · Published 2026-10-04