Avalex API Authentication Overview
Every protected Avalex API endpoint requires valid credentials on each request. You include those credentials in theAuthorization header — either as a JWT Bearer token or as Base64-encoded HTTP Basic Auth credentials.
A set of public integration endpoints (such as license validation, BuiltByBit webhooks, and authentication endpoints) do not require staff credentials and can be called directly.
Authentication Methods
Public & Integration Endpoints
The following endpoints do not require staff authentication headers:POST /auth/login— Authenticate and obtain a 7-day JWT tokenPOST /staff/login— Staff-specific login aliasPOST /staff/register— Create a new staff account (requires a valid single-use registration key)POST /licenses/validate— Validate a license key from client softwarePOST /builtbybit— BuiltByBit license issuance webhook (authenticated via payloadsecret)
The Master Admin account configured in
application.conf (master-admin) always has full bypass access across every API endpoint regardless of role assignments.Next Steps
JWT Authentication Guide
Obtain a token via
POST /auth/login and pass it in the Authorization: Bearer header.HTTP Basic Auth Guide
Encode
username:password in Base64 for rapid script testing.