Authentication

Every RiskAdvisor API request, except login, requires a bearer token for a user who belongs to a team. Create a personal access token in the dashboard, or exchange an email and password for a token.

Send the token on each request:

Authorization header

curl https://app.riskadvisor.insure/api/user \
  -H "Authorization: Bearer {token}" \
  -H "Accept: application/json"

Keep the token secret. If it is exposed, revoke it from API tokens and create a new one.

Dashboard tokens

The recommended way to authenticate is a personal access token from Settings » API tokens. Use that token as the bearer value above. Requests run as that user, against that user's current team and the other teams they belong to.

Login

POST /api/login checks an email and password and returns a token.

The user must have the RiskAdvisor API feature enabled. Otherwise the response is 403.

Required attributes

  • Name
    email
    Type
    string
    Description

    The account email address.

  • Name
    password
    Type
    string
    Description

    The account password.

Request

POST
/api/login
curl https://app.riskadvisor.insure/api/login \
  -H "Accept: application/json" \
  -H "Content-Type: application/json" \
  -d '{"email":"[email protected]","password":"secret"}'

Response

{
  "token": "1|plainTextToken"
}

A wrong email or password returns 401:

401

{
  "message": "The provided credentials are incorrect."
}

A valid user without API access returns 403:

403

{
  "message": "You are not allowed to access the RiskAdvisor API."
}

Current team

Authenticated routes use the auth:sanctum and has-team middleware. The user must belong to a team. If they do not, a JSON request returns 422 with the message No active team found. When current_team_id is empty, the API selects the user's first team before handling the request.