Miridia
Portal
Global API

Authentication

The global-side auth routes

Base URL: https://global.miridia.io. Read Authentication and Conventions before you call these operations.

MethodPathOperation
POST/api/auth/loginLogin
POST/api/auth/select-organizationSelect organization
POST/api/auth/new-tokenNew token
POST/api/auth/logoutLogout
POST/api/auth/reset-passwordReset password
POST/api/auth/ottMint one time token
POST/api/auth/ott/redeemRedeem one time token
POST/api/auth/complete-invitation/{businessId}Complete invitation
GET/api/auth/verify-by-tokenVerify by token
GET/api/auth/tokensGet access tokens
POST/api/auth/tokensCreate api token
DELETE/api/auth/tokens/{id}Revoke access token

Login

POST/api/auth/login

Access. This operation needs no authentication.

Request body

Send JSON with the shape AuthenticateRequest.

FieldTypeRequiredDescription
emailstring (email)Yes
passwordstringYes

Response

200. Returns a SingleResult envelope. The data field is LoginResponse.

Request
curl -X POST "https://global.miridia.io/api/auth/login" \
  -H "Content-Type: application/json" \
  -d '{
  "email": "name@example.com",
  "password": "string"
}'
Response
{
  "data": {
    "requiresOrganizationSelection": true,
    "session": {
      "accessToken": "string",
      "expiresAtUtc": "2026-09-29T08:00:00Z",
      "organization": {},
      "businessId": "3fa85f64-5717-4562-b3fc-2c963f66afa6"
    },
    "selectionToken": "string",
    "selectionExpiresAtUtc": "2026-09-29T08:00:00Z",
    "organizations": [
      {}
    ]
  },
  "statusCode": 0,
  "messages": [
    "string"
  ]
}

Select organization

POST/api/auth/select-organization

Requires the short-lived selection token LoginAsync returned for a multi-membership user.

Access. This operation needs no session token. It reads the selection token from the login response, as a bearer token.

Request body

Send JSON with the shape SelectOrganizationRequest.

FieldTypeRequiredDescription
organizationIdstring (uuid)Yes

Response

200. Returns a SingleResult envelope. The data field is SessionResponse.

Request
curl -X POST "https://global.miridia.io/api/auth/select-organization" \
  -H "Content-Type: application/json" \
  -d '{
  "organizationId": "3fa85f64-5717-4562-b3fc-2c963f66afa6"
}'
Response
{
  "data": {
    "accessToken": "string",
    "expiresAtUtc": "2026-09-29T08:00:00Z",
    "organization": {
      "id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
      "slug": "string",
      "name": "string"
    },
    "businessId": "3fa85f64-5717-4562-b3fc-2c963f66afa6"
  },
  "statusCode": 0,
  "messages": [
    "string"
  ]
}

New token

POST/api/auth/new-token

Refresh-token rotation. Reads the refresh cookie. No request body.

Access. This operation needs no session token. It reads the refresh cookie that login sets.

Response

200. Returns a SingleResult envelope. The data field is SessionResponse.

Request
curl -X POST "https://global.miridia.io/api/auth/new-token"
Response
{
  "data": {
    "accessToken": "string",
    "expiresAtUtc": "2026-09-29T08:00:00Z",
    "organization": {
      "id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
      "slug": "string",
      "name": "string"
    },
    "businessId": "3fa85f64-5717-4562-b3fc-2c963f66afa6"
  },
  "statusCode": 0,
  "messages": [
    "string"
  ]
}

Logout

POST/api/auth/logout

Access. Send a bearer token or an API key. Any signed-in member can call this operation.

Response

200. Returns a SingleResult envelope. The data field is boolean.

Request
curl -X POST "https://global.miridia.io/api/auth/logout" \
  -H "Authorization: Bearer $MIRIDIA_TOKEN"
Response
{
  "data": true,
  "statusCode": 0,
  "messages": [
    "string"
  ]
}

Reset password

POST/api/auth/reset-password

Access. This operation needs no authentication.

Request body

Send JSON with the shape ResetPasswordRequest.

FieldTypeRequiredDescription
tokenstringYes
passwordstringYes

Response

200. Returns a SingleResult envelope. The data field is boolean.

Request
curl -X POST "https://global.miridia.io/api/auth/reset-password" \
  -H "Content-Type: application/json" \
  -d '{
  "token": "string",
  "password": "string"
}'
Response
{
  "data": true,
  "statusCode": 0,
  "messages": [
    "string"
  ]
}

Mint one time token

POST/api/auth/ott

Mints a single-use SSO handoff token (60s TTL) for the current session.

Access. Send a bearer token or an API key. Any signed-in member can call this operation.

Request body

Send JSON with the shape MintOneTimeTokenRequest.

FieldTypeRequiredDescription
targetAppstringYes
businessIdstring (uuid)YesThe business the handed-off session should land in. A Global-API-issued token carries no business-id claim, so the caller must supply this explicitly.

Response

200. Returns a SingleResult envelope. The data field is OneTimeTokenResponse.

Request
curl -X POST "https://global.miridia.io/api/auth/ott" \
  -H "Authorization: Bearer $MIRIDIA_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
  "targetApp": "string",
  "businessId": "3fa85f64-5717-4562-b3fc-2c963f66afa6"
}'
Response
{
  "data": {
    "token": "string",
    "expiresAt": "2026-09-29T08:00:00Z"
  },
  "statusCode": 0,
  "messages": [
    "string"
  ]
}

Redeem one time token

POST/api/auth/ott/redeem

Redeems a one-time token minted by mintOneTimeToken.

Access. This operation needs no authentication.

Request body

Send JSON with the shape RedeemOneTimeTokenRequest.

FieldTypeRequiredDescription
tokenstringYes

Response

200. Returns a SingleResult envelope. The data field is SessionResponse.

Request
curl -X POST "https://global.miridia.io/api/auth/ott/redeem" \
  -H "Content-Type: application/json" \
  -d '{
  "token": "string"
}'
Response
{
  "data": {
    "accessToken": "string",
    "expiresAtUtc": "2026-09-29T08:00:00Z",
    "organization": {
      "id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
      "slug": "string",
      "name": "string"
    },
    "businessId": "3fa85f64-5717-4562-b3fc-2c963f66afa6"
  },
  "statusCode": 0,
  "messages": [
    "string"
  ]
}

Complete invitation

POST/api/auth/complete-invitation/{businessId}

Global part only: sets the password and marks the user verified. The businessId route segment is kept for URL compatibility; org-side profile completion is a separate main-API call.

Access. This operation needs no authentication.

Parameters

NameInTypeRequiredDescription
businessIdpathstring (uuid)Yes

Request body

Send JSON with the shape CompleteInvitationRequest.

FieldTypeRequiredDescription
emailstring (email)Yes
passwordstringYes
acceptedTermsbooleanNo

Response

200. Returns a SingleResult envelope. The data field is boolean.

Request
curl -X POST "https://global.miridia.io/api/auth/complete-invitation/{businessId}" \
  -H "Content-Type: application/json" \
  -d '{
  "email": "name@example.com",
  "password": "string",
  "acceptedTerms": true
}'
Response
{
  "data": true,
  "statusCode": 0,
  "messages": [
    "string"
  ]
}

Verify by token

GET/api/auth/verify-by-token

Access. This operation needs no authentication.

Parameters

NameInTypeRequiredDescription
tokenquerystringNo

Response

200. The response has no body.

Request
curl -X GET "https://global.miridia.io/api/auth/verify-by-token"

Get access tokens

GET/api/auth/tokens

Access. Send a bearer token or an API key. Any signed-in member can call this operation.

Response

200. Returns a PagedResult envelope. Each item in data is AccessTokenResponse.

Request
curl -X GET "https://global.miridia.io/api/auth/tokens" \
  -H "Authorization: Bearer $MIRIDIA_TOKEN"
Response
{
  "data": [
    {
      "id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
      "token": "string",
      "expiryDate": "2026-09-29T08:00:00Z",
      "title": "string",
      "scopes": "string",
      "dateCreated": "2026-09-29T08:00:00Z",
      "lastUsedAt": "2026-09-29T08:00:00Z"
    }
  ],
  "count": 0,
  "page": 0,
  "pageSize": 0,
  "totalCount": 0,
  "statusCode": 0,
  "messages": [
    "string"
  ]
}

Create api token

POST/api/auth/tokens

Requires the caller to be an owner of the token's organization.

Access. Send a bearer token or an API key. Any signed-in member can call this operation.

Request body

Send JSON with the shape CreateApiKeyRequest.

FieldTypeRequiredDescription
labelstringNo
ttlMinutesinteger (int32)No
businessIdstring (uuid)YesThe business the key acts for (api_keys.business_id is NOT NULL). The Global API has no business context of its own, so the caller must supply it explicitly.
scopesstringNoOptional raw permission grant, { "ModuleName": bitmaskInt }, passed straight through to api_keys.scopes. There is no role-based derivation here: roles are org-side data the Global API cannot resolve. Null/absent = unrestricted key.

Response

200. Returns a SingleResult envelope. The data field is AccessTokenResponse.

Request
curl -X POST "https://global.miridia.io/api/auth/tokens" \
  -H "Authorization: Bearer $MIRIDIA_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
  "label": "string",
  "ttlMinutes": 0,
  "businessId": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
  "scopes": "string"
}'
Response
{
  "data": {
    "id": "3fa85f64-5717-4562-b3fc-2c963f66afa6",
    "token": "string",
    "expiryDate": "2026-09-29T08:00:00Z",
    "title": "string",
    "scopes": "string",
    "dateCreated": "2026-09-29T08:00:00Z",
    "lastUsedAt": "2026-09-29T08:00:00Z"
  },
  "statusCode": 0,
  "messages": [
    "string"
  ]
}

Revoke access token

DELETE/api/auth/tokens/{id}

Requires the caller to be an owner of the token's organization.

Access. Send a bearer token or an API key. Any signed-in member can call this operation.

Parameters

NameInTypeRequiredDescription
idpathstring (uuid)Yes

Response

200. Returns a SingleResult envelope. The data field is boolean.

Request
curl -X DELETE "https://global.miridia.io/api/auth/tokens/{id}" \
  -H "Authorization: Bearer $MIRIDIA_TOKEN"
Response
{
  "data": true,
  "statusCode": 0,
  "messages": [
    "string"
  ]
}

Models

The operations on this page use these object types. Select a type to see its fields.

AccessTokenResponse
FieldTypeDescription
idstring (uuid)
tokenstring
expiryDatestring (date-time)
titlestring
scopesstring
dateCreatedstring (date-time)
lastUsedAtstring (date-time)
LoginResponse

Exactly one of the two shapes is populated: a single membership yields session; more than one yields selectionToken + organizations, and the client must call POST /api/auth/select-organization next.

FieldTypeDescription
requiresOrganizationSelectionboolean
sessionSessionResponse
selectionTokenstring
selectionExpiresAtUtcstring (date-time)
organizationsOrganizationSummary[]
OneTimeTokenResponse
FieldTypeDescription
tokenstring
expiresAtstring (date-time)
OrganizationContext
FieldTypeDescription
idstring (uuid)
slugstring
namestring
OrganizationSummary
FieldTypeDescription
idstring (uuid)
slugstring
namestring
isOwnerboolean
SessionResponse

BusinessId is set only for a session that comes from a one-time token.

FieldTypeDescription
accessTokenstring
expiresAtUtcstring (date-time)
organizationOrganizationContext
businessIdstring (uuid)