On this page
Authentication API
Generated Golden API operations for Authentication.
Golden 3.0.0 public API reference. Parameters, responses, and schemas for supported customer operations.
7 operations.
POST /api/security/auth
Authenticate user
Operation ID: authenticate
Authenticates a user using email and password or SSO token. Returns a JWT bearer token on success. Does not require authentication.
Security: None
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
Accept-Language | header | false | string | — |
Request body
| Media type | Required | Schema |
|---|---|---|
application/json | true | TzAuthRequestDto |
Responses
| Status | Description | Body |
|---|---|---|
200 | Successful authentication | application/json: TzAuthResponseDto |
401 | Unauthorized | /: map of any JSON value |
409 | Conflict | /: map of any JSON value |
POST /api/security/auth/logout
Log out of every device
Operation ID: logoutEverywhere
Revokes every refresh token belonging to the authenticated user, ending their sessions everywhere. Requires authentication. The access token already issued stays valid until it expires – it is stateless – so a short JWT lifetime is what bounds the window.
Security: bearerAuth
Responses
| Status | Description | Body |
|---|---|---|
200 | Every session was ended | — |
400 | The caller is an application token, which has no sessions | — |
401 | Unauthorized | /: map of any JSON value |
409 | Conflict | /: map of any JSON value |
POST /api/security/auth/refresh
Refresh authentication token
Operation ID: refreshToken
Exchanges a valid refresh token for a new JWT and refresh token pair. Does not require authentication.
Security: None
Request body
| Media type | Required | Schema |
|---|---|---|
application/json | true | TzRefreshRequestDto |
Responses
| Status | Description | Body |
|---|---|---|
200 | Tokens refreshed successfully | application/json: TzRefreshResponseDto |
401 | Invalid or expired refresh token | /: map of any JSON value |
409 | Conflict | /: map of any JSON value |
PUT /api/security/password/reset/{email}
Request password reset
Operation ID: requestPasswordReset
Requests a password reset for the specified email. Operation always succeeds (for security reasons, to avoid user enumeration). Does not require authentication.
Security: None
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
email | path | true | string | minLength: 1 |
Accept-Language | header | false | string | — |
Responses
| Status | Description | Body |
|---|---|---|
200 | Request processed | application/json: TzAuthResponseDto |
401 | Unauthorized | /: map of any JSON value |
409 | Conflict | /: map of any JSON value |
POST /api/security/password/update
Update password
Operation ID: updatePassword
Updates user password using a previously generated reset token. Does not require authentication.
Security: None
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
Accept-Language | header | false | string | — |
Request body
| Media type | Required | Schema |
|---|---|---|
application/json | true | TzPasswordUpdateRequestDto |
Responses
| Status | Description | Body |
|---|---|---|
200 | Password updated | application/json: TzUserResponseDto |
401 | Unauthorized | /: map of any JSON value |
409 | Conflict | /: map of any JSON value |
GET /api/security/sso/config
Get SSO configuration
Operation ID: getSsoConfig
Returns SSO provider configuration for frontend OAuth setup. Exposes only public information (client IDs, authorization endpoints, scopes). Does not require authentication.
Security: None
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
Accept-Language | header | false | string | — |
Responses
| Status | Description | Body |
|---|---|---|
200 | SSO configuration retrieved | application/json: TzSsoConfigResponseDto |
401 | Unauthorized | /: map of any JSON value |
409 | Conflict | /: map of any JSON value |
GET /api/security/whoami
Who am I?
Operation ID: whoami
Returns authentication context information. Does not require authentication.
Security: None
Parameters
| Name | In | Required | Type | Description |
|---|---|---|---|---|
Accept-Language | header | false | string | — |
Responses
| Status | Description | Body |
|---|---|---|
200 | Operation successful | application/json: TzAuthResponseDto |
401 | Unauthorized | /: map of any JSON value |
409 | Conflict | /: map of any JSON value |