Authentication
Base URL: https://global.miridia.io. Read Authentication and Conventions before you call these operations.
| Method | Path | Operation |
|---|---|---|
| POST | /api/auth/login | Login |
| POST | /api/auth/select-organization | Select organization |
| POST | /api/auth/new-token | New token |
| POST | /api/auth/logout | Logout |
| POST | /api/auth/reset-password | Reset password |
| POST | /api/auth/ott | Mint one time token |
| POST | /api/auth/ott/redeem | Redeem one time token |
| POST | /api/auth/complete-invitation/{businessId} | Complete invitation |
| GET | /api/auth/verify-by-token | Verify by token |
| GET | /api/auth/tokens | Get access tokens |
| POST | /api/auth/tokens | Create api token |
| DELETE | /api/auth/tokens/{id} | Revoke access token |
Login
POST/api/auth/login
Access. This operation needs no authentication.
Request body
Send JSON with the shape AuthenticateRequest.
| Field | Type | Required | Description |
|---|---|---|---|
email | string (email) | Yes | |
password | string | Yes |
Response
200. Returns a SingleResult envelope. The data field is LoginResponse.
curl -X POST "https://global.miridia.io/api/auth/login" \
-H "Content-Type: application/json" \
-d '{
"email": "name@example.com",
"password": "string"
}'{
"data": {
"requiresOrganizationSelection": true,
"session": {
"accessToken": "string",
"expiresAtUtc": "2026-09-29T08:00:00Z",
"organization": {},
"businessId": "3fa85f64-5717-4562-b3fc-2c963f66afa6"
},
"selectionToken": "string",
"selectionExpiresAtUtc": "2026-09-29T08:00:00Z",
"organizations": [
{}
]
},
"statusCode": 0,
"messages": [
"string"
]
}Select organization
POST/api/auth/select-organization
Requires the short-lived selection token LoginAsync returned for a multi-membership user.
Access. This operation needs no session token. It reads the selection token from the login response, as a bearer token.
Request body
Send JSON with the shape SelectOrganizationRequest.
| Field | Type | Required | Description |
|---|---|---|---|
organizationId | string (uuid) | Yes |
Response
200. Returns a SingleResult envelope. The data field is SessionResponse.
curl -X POST "https://global.miridia.io/api/auth/select-organization" \
-H "Content-Type: application/json" \
-d '{
"organizationId": "3fa85f64-5717-4562-b3fc-2c963f66afa6"
}'{
"data": {
"accessToken": "string",
"expiresAtUtc": "2026-09-29T08:00:00Z",
"organization": {
"id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"slug": "string",
"name": "string"
},
"businessId": "3fa85f64-5717-4562-b3fc-2c963f66afa6"
},
"statusCode": 0,
"messages": [
"string"
]
}New token
POST/api/auth/new-token
Refresh-token rotation. Reads the refresh cookie. No request body.
Access. This operation needs no session token. It reads the refresh cookie that login sets.
Response
200. Returns a SingleResult envelope. The data field is SessionResponse.
curl -X POST "https://global.miridia.io/api/auth/new-token"{
"data": {
"accessToken": "string",
"expiresAtUtc": "2026-09-29T08:00:00Z",
"organization": {
"id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"slug": "string",
"name": "string"
},
"businessId": "3fa85f64-5717-4562-b3fc-2c963f66afa6"
},
"statusCode": 0,
"messages": [
"string"
]
}Logout
POST/api/auth/logout
Access. Send a bearer token or an API key. Any signed-in member can call this operation.
Response
200. Returns a SingleResult envelope. The data field is boolean.
curl -X POST "https://global.miridia.io/api/auth/logout" \
-H "Authorization: Bearer $MIRIDIA_TOKEN"{
"data": true,
"statusCode": 0,
"messages": [
"string"
]
}Reset password
POST/api/auth/reset-password
Access. This operation needs no authentication.
Request body
Send JSON with the shape ResetPasswordRequest.
| Field | Type | Required | Description |
|---|---|---|---|
token | string | Yes | |
password | string | Yes |
Response
200. Returns a SingleResult envelope. The data field is boolean.
curl -X POST "https://global.miridia.io/api/auth/reset-password" \
-H "Content-Type: application/json" \
-d '{
"token": "string",
"password": "string"
}'{
"data": true,
"statusCode": 0,
"messages": [
"string"
]
}Mint one time token
POST/api/auth/ott
Mints a single-use SSO handoff token (60s TTL) for the current session.
Access. Send a bearer token or an API key. Any signed-in member can call this operation.
Request body
Send JSON with the shape MintOneTimeTokenRequest.
| Field | Type | Required | Description |
|---|---|---|---|
targetApp | string | Yes | |
businessId | string (uuid) | Yes | The business the handed-off session should land in. A Global-API-issued token carries no business-id claim, so the caller must supply this explicitly. |
Response
200. Returns a SingleResult envelope. The data field is OneTimeTokenResponse.
curl -X POST "https://global.miridia.io/api/auth/ott" \
-H "Authorization: Bearer $MIRIDIA_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"targetApp": "string",
"businessId": "3fa85f64-5717-4562-b3fc-2c963f66afa6"
}'{
"data": {
"token": "string",
"expiresAt": "2026-09-29T08:00:00Z"
},
"statusCode": 0,
"messages": [
"string"
]
}Redeem one time token
POST/api/auth/ott/redeem
Redeems a one-time token minted by mintOneTimeToken.
Access. This operation needs no authentication.
Request body
Send JSON with the shape RedeemOneTimeTokenRequest.
| Field | Type | Required | Description |
|---|---|---|---|
token | string | Yes |
Response
200. Returns a SingleResult envelope. The data field is SessionResponse.
curl -X POST "https://global.miridia.io/api/auth/ott/redeem" \
-H "Content-Type: application/json" \
-d '{
"token": "string"
}'{
"data": {
"accessToken": "string",
"expiresAtUtc": "2026-09-29T08:00:00Z",
"organization": {
"id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"slug": "string",
"name": "string"
},
"businessId": "3fa85f64-5717-4562-b3fc-2c963f66afa6"
},
"statusCode": 0,
"messages": [
"string"
]
}Complete invitation
POST/api/auth/complete-invitation/{businessId}
Global part only: sets the password and marks the user verified. The businessId route segment is kept for URL compatibility; org-side profile completion is a separate main-API call.
Access. This operation needs no authentication.
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
businessId | path | string (uuid) | Yes |
Request body
Send JSON with the shape CompleteInvitationRequest.
| Field | Type | Required | Description |
|---|---|---|---|
email | string (email) | Yes | |
password | string | Yes | |
acceptedTerms | boolean | No |
Response
200. Returns a SingleResult envelope. The data field is boolean.
curl -X POST "https://global.miridia.io/api/auth/complete-invitation/{businessId}" \
-H "Content-Type: application/json" \
-d '{
"email": "name@example.com",
"password": "string",
"acceptedTerms": true
}'{
"data": true,
"statusCode": 0,
"messages": [
"string"
]
}Verify by token
GET/api/auth/verify-by-token
Access. This operation needs no authentication.
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
token | query | string | No |
Response
200. The response has no body.
curl -X GET "https://global.miridia.io/api/auth/verify-by-token"Get access tokens
GET/api/auth/tokens
Access. Send a bearer token or an API key. Any signed-in member can call this operation.
Response
200. Returns a PagedResult envelope. Each item in data is AccessTokenResponse.
curl -X GET "https://global.miridia.io/api/auth/tokens" \
-H "Authorization: Bearer $MIRIDIA_TOKEN"{
"data": [
{
"id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"token": "string",
"expiryDate": "2026-09-29T08:00:00Z",
"title": "string",
"scopes": "string",
"dateCreated": "2026-09-29T08:00:00Z",
"lastUsedAt": "2026-09-29T08:00:00Z"
}
],
"count": 0,
"page": 0,
"pageSize": 0,
"totalCount": 0,
"statusCode": 0,
"messages": [
"string"
]
}Create api token
POST/api/auth/tokens
Requires the caller to be an owner of the token's organization.
Access. Send a bearer token or an API key. Any signed-in member can call this operation.
Request body
Send JSON with the shape CreateApiKeyRequest.
| Field | Type | Required | Description |
|---|---|---|---|
label | string | No | |
ttlMinutes | integer (int32) | No | |
businessId | string (uuid) | Yes | The business the key acts for (api_keys.business_id is NOT NULL). The Global API has no business context of its own, so the caller must supply it explicitly. |
scopes | string | No | Optional raw permission grant, { "ModuleName": bitmaskInt }, passed straight through to api_keys.scopes. There is no role-based derivation here: roles are org-side data the Global API cannot resolve. Null/absent = unrestricted key. |
Response
200. Returns a SingleResult envelope. The data field is AccessTokenResponse.
curl -X POST "https://global.miridia.io/api/auth/tokens" \
-H "Authorization: Bearer $MIRIDIA_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"label": "string",
"ttlMinutes": 0,
"businessId": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"scopes": "string"
}'{
"data": {
"id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
"token": "string",
"expiryDate": "2026-09-29T08:00:00Z",
"title": "string",
"scopes": "string",
"dateCreated": "2026-09-29T08:00:00Z",
"lastUsedAt": "2026-09-29T08:00:00Z"
},
"statusCode": 0,
"messages": [
"string"
]
}Revoke access token
DELETE/api/auth/tokens/{id}
Requires the caller to be an owner of the token's organization.
Access. Send a bearer token or an API key. Any signed-in member can call this operation.
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
id | path | string (uuid) | Yes |
Response
200. Returns a SingleResult envelope. The data field is boolean.
curl -X DELETE "https://global.miridia.io/api/auth/tokens/{id}" \
-H "Authorization: Bearer $MIRIDIA_TOKEN"{
"data": true,
"statusCode": 0,
"messages": [
"string"
]
}Models
The operations on this page use these object types. Select a type to see its fields.
AccessTokenResponse
| Field | Type | Description |
|---|---|---|
id | string (uuid) | |
token | string | |
expiryDate | string (date-time) | |
title | string | |
scopes | string | |
dateCreated | string (date-time) | |
lastUsedAt | string (date-time) |
LoginResponse
Exactly one of the two shapes is populated: a single membership yields session; more than one yields selectionToken + organizations, and the client must call POST /api/auth/select-organization next.
| Field | Type | Description |
|---|---|---|
requiresOrganizationSelection | boolean | |
session | SessionResponse | |
selectionToken | string | |
selectionExpiresAtUtc | string (date-time) | |
organizations | OrganizationSummary[] |
OneTimeTokenResponse
| Field | Type | Description |
|---|---|---|
token | string | |
expiresAt | string (date-time) |
OrganizationContext
| Field | Type | Description |
|---|---|---|
id | string (uuid) | |
slug | string | |
name | string |
OrganizationSummary
| Field | Type | Description |
|---|---|---|
id | string (uuid) | |
slug | string | |
name | string | |
isOwner | boolean |
SessionResponse
BusinessId is set only for a session that comes from a one-time token.
| Field | Type | Description |
|---|---|---|
accessToken | string | |
expiresAtUtc | string (date-time) | |
organization | OrganizationContext | |
businessId | string (uuid) |