Skip to main content

Avalex API Authentication Overview

Every protected Avalex API endpoint requires valid credentials on each request. You include those credentials in the Authorization header — either as a JWT Bearer token or as Base64-encoded HTTP Basic Auth credentials. A set of public integration endpoints (such as license validation, BuiltByBit webhooks, and authentication endpoints) do not require staff credentials and can be called directly.

Authentication Methods


Public & Integration Endpoints

The following endpoints do not require staff authentication headers:
  • POST /auth/login — Authenticate and obtain a 7-day JWT token
  • POST /staff/login — Staff-specific login alias
  • POST /staff/register — Create a new staff account (requires a valid single-use registration key)
  • POST /licenses/validate — Validate a license key from client software
  • POST /builtbybit — BuiltByBit license issuance webhook (authenticated via payload secret)
The Master Admin account configured in application.conf (master-admin) always has full bypass access across every API endpoint regardless of role assignments.

Next Steps

JWT Authentication Guide

Obtain a token via POST /auth/login and pass it in the Authorization: Bearer header.

HTTP Basic Auth Guide

Encode username:password in Base64 for rapid script testing.