Authentication
Every RiskAdvisor API request, except login, requires a bearer token for a user who belongs to a team. Create a personal access token in the dashboard, or exchange an email and password for a token.
Send the token on each request:
Authorization header
curl https://app.riskadvisor.insure/api/user \
-H "Authorization: Bearer {token}" \
-H "Accept: application/json"
Keep the token secret. If it is exposed, revoke it from API tokens and create a new one.
Dashboard tokens
The recommended way to authenticate is a personal access token from Settings » API tokens. Use that token as the bearer value above. Requests run as that user, against that user's current team and the other teams they belong to.
Login
POST /api/login checks an email and password and returns a token.
The user must have the RiskAdvisor API feature enabled. Otherwise the response is 403.
Required attributes
- Name
email- Type
- string
- Description
The account email address.
- Name
password- Type
- string
- Description
The account password.
Request
curl https://app.riskadvisor.insure/api/login \
-H "Accept: application/json" \
-H "Content-Type: application/json" \
-d '{"email":"[email protected]","password":"secret"}'
Response
{
"token": "1|plainTextToken"
}
A wrong email or password returns 401:
401
{
"message": "The provided credentials are incorrect."
}
A valid user without API access returns 403:
403
{
"message": "You are not allowed to access the RiskAdvisor API."
}
Current team
Authenticated routes use the auth:sanctum and has-team middleware. The user must belong to a team. If they do not, a JSON request returns 422 with the message No active team found. When current_team_id is empty, the API selects the user's first team before handling the request.