Skip to main content

Auth API

Auth endpoints exposed by the Devotel CPaaS API Base path: /api/v1/auth Endpoint count: 7

title: “The SAML SSO round-trip” description: “Walk the four SAML steps end to end — SP metadata, SP-initiated login, the IdP’s ACS POST to the callback, and optional single logout.”

The SAML SSO round-trip

These four operations are the service-provider side of SAML 2.0 SSO — the route an organization’s IdP administrators walk to wire Okta, Entra ID, or similar into Orbit’s sign-in. The page’s {orgSlug} path segment selects the SAML configuration; it is a URL-safe organization slug, not an API-key credential, and the operations are deliberately unauthenticated because they begin a session rather than require one. Sequence the round-trip like this. (1) GET /auth/saml/{orgSlug}/metadata returns the service-provider XML the IdP admin imports to register Orbit: entity ID, ACS URL, and signing details. (2) GET /auth/saml/{orgSlug}/login?redirect=/settings/team issues the SP-initiated AuthnRequest and 302-redirects the browser to the IdP’s SSO URL; any redirect value is signed into RelayState and sweeps the post-auth destination back. (3) The IdP POSTs the signed SAMLResponse to /auth/saml/{orgSlug}/callback — the Assertion Consumer Service verifies signature, audience, and the replay window, provisions the user on first login, then 302-redirects to the dashboard sign-in ticket that mints the session cookie. (4) GET /auth/saml/{orgSlug}/logout?nameId=<subject> builds a LogoutRequest for the IdP’s SLO endpoint when single logout is configured; otherwise it answers 200 with a logged_out status, and the local ceremony destroys the session. A worked check-in sequence in cURL:
cURL
The first event and the first callback are both redirect-only flows — do not call them from your application; point users at them or let the IdP drive the callback.
GET /api/v1/auth/impersonate-cookie-consume
Second half of the impersonation handoff. Reads the token from the cookie staged by the previous call, enforces one-time use, confirms the impersonation session has not been ended, clears the cookie and redirects the browser into the impersonated dashboard. The operator’s browser opens this URL directly, so the success path is a redirect rather than a JSON body, and a second visit to the same link is rejected.

Revoke every API key after a password reset

GET /api/v1/auth/post-reset-revoke-api-keys
Backs the Revoke all my API keys link in the email sent after a password reset. Validates the single-use token from the link, deactivates every API key the user created, drops them from the authentication cache so running services stop accepting them straight away, and burns the token. The link is valid for 24 hours and works once.

POST /api/v1/auth/consent
Stores the signed-in user’s acceptance of the Terms of Service and Privacy Policy: the document versions they were shown, the moment they accepted, and the locale, IP address and user agent captured at that moment. Call it once from the signup or invite-acceptance flow as soon as the session exists. Posting again for the same user updates the existing record in place, so re-acceptance after a policy update is safe.

Request a password-reset email

POST /api/v1/auth/forgot-password
Starts a self-service password reset. When the address belongs to an account, Orbit emails a single-use reset link that expires after one hour; when it does not, no email is sent. The response is 200 either way, so the endpoint cannot be used to discover which addresses are registered. Requests are rate limited per IP address and per email address.

POST /api/v1/auth/impersonate-cookie-set
First half of the impersonation handoff. Verifies the token and stores it in a five-minute, httpOnly, Secure, SameSite=Strict cookie so the operator’s browser can carry it to the consume step without the token ever appearing in a URL, a proxy log or a referrer header. Returns no body — send the browser to the consume endpoint next.
Response: 204 No Content

Exchange an impersonation token for its grant

POST /api/v1/auth/impersonate-exchange
Verifies a short-lived impersonation token issued by the operator console and returns the grant it carries: which operator is acting, which organization they are entering, the reason recorded, and when the grant expires. The dashboard uses it to open a support session. Expired, ended, replayed and forged tokens are all rejected with the same 401, so the response cannot be used to probe which tokens exist. Every exchange is audit-logged.

Set a new password with a reset token

POST /api/v1/auth/reset-password
Completes a password reset. Validates the single-use token from the emailed link and checks the new password against the complexity policy, then updates the credential, signs the account out of every other active session, and sends a follow-up email offering one-click revocation of the account’s API keys. The token is burned on success, so a reset link never works twice.