All endpoints
The seven paths the public gateway routes to authsvc, in one list.
Tokens and login
Token issuance, staff sign-in and the public verification keys.
Exchange a tenant API key for a short-lived user token
Mints a short-lived scoped RS256 JWT that acts as one end user of the calling tenant.
Sign a portal staff member in
Authenticates a portal staff member against their Argon2id password hash and returns a staff session JWT.
Fetch the public signing keys
Serves the JSON Web Key Set for every ACTIVE signing key, so that any token this service has issued and not yet expired can be verified even across a rotation.
API keys
Tenant API key lifecycle, for platform operators.
List a tenant's API keys
Lists every key that can act in the tenant, active and revoked, oldest first, and never their secrets — incident response needs to see what exists before deciding what dies.
Issue a tenant API key
Creates an API key for a tenant and returns its token.
Revoke a tenant API key
Ends a key immediately, so revoking a leaked credential does not require shell access to the pod.
Staff sessions
Portal staff session administration, for platform operators.