Auth API
Auth endpoints exposed by the Devotel CPaaS API Base path:/api/v1/auth
Endpoint count: 7
title: “The SAML SSO round-trip” description: “Walk the four SAML steps end to end — SP metadata, SP-initiated login, the IdP’s ACS POST to the callback, and optional single logout.”
The SAML SSO round-trip
These four operations are the service-provider side of SAML 2.0 SSO — the route an organization’s IdP administrators walk to wire Okta, Entra ID, or similar into Orbit’s sign-in. The page’s{orgSlug} path segment selects the SAML configuration; it is a URL-safe organization slug, not an API-key credential, and the operations are deliberately unauthenticated because they begin a session rather than require one.
Sequence the round-trip like this. (1) GET /auth/saml/{orgSlug}/metadata returns the service-provider XML the IdP admin imports to register Orbit: entity ID, ACS URL, and signing details. (2) GET /auth/saml/{orgSlug}/login?redirect=/settings/team issues the SP-initiated AuthnRequest and 302-redirects the browser to the IdP’s SSO URL; any redirect value is signed into RelayState and sweeps the post-auth destination back. (3) The IdP POSTs the signed SAMLResponse to /auth/saml/{orgSlug}/callback — the Assertion Consumer Service verifies signature, audience, and the replay window, provisions the user on first login, then 302-redirects to the dashboard sign-in ticket that mints the session cookie. (4) GET /auth/saml/{orgSlug}/logout?nameId=<subject> builds a LogoutRequest for the IdP’s SLO endpoint when single logout is configured; otherwise it answers 200 with a logged_out status, and the local ceremony destroys the session.
A worked check-in sequence in cURL:
cURL
Consume the staged impersonation cookie
GET /api/v1/auth/impersonate-cookie-consumeRevoke every API key after a password reset
GET /api/v1/auth/post-reset-revoke-api-keysRevoke all my API keys link in the email sent after a password reset. Validates the single-use token from the link, deactivates every API key the user created, drops them from the authentication cache so running services stop accepting them straight away, and burns the token. The link is valid for 24 hours and works once.
Record terms and privacy consent
POST /api/v1/auth/consentRequest a password-reset email
POST /api/v1/auth/forgot-passwordStage an impersonation token in a cookie
POST /api/v1/auth/impersonate-cookie-set204 No Content
Exchange an impersonation token for its grant
POST /api/v1/auth/impersonate-exchangeSet a new password with a reset token
POST /api/v1/auth/reset-password