Authentication
Authenticate every request by sending a token as the raw value of the `Authorization` header, without a `Bearer` prefix.
Authorization: <token>The token can be either of:
- An API key, which Depa issues for server-to-server integrations. Use it as is.
- A user token (JWT) from
POST /sign_in, for actions taken on behalf of a person, such as four-eyes approvals. If the user has two-factor authentication enabled, add the current one-time code asotp_attemptwhen signing in.
User tokens expire, and stop working early if they're revoked or the user's password
changes. A missing, invalid or expired token returns 401 with
{"error": "You are not authenticated."}; sign in again to get a new one.
The user token is a standard JWT, so you can read its payload without calling the API. It
includes user_uuid, main_account_uuid, your roles, the vaults you can access (use
these IDs in the /vaults/{vault_id}/… endpoints) and exp, the expiry time in Unix
seconds.
What a token can do depends on its user's roles: api_read allows reading and
api_write allows changes. Calls outside those permissions return 403.
Sandbox and production are separate environments with separate credentials. Build and
test against https://api.sandbox.depa.finance/v1.
/sign_inExchanges a user's email and password for a JWT. Send it as the raw value of the
Authorization header on every other request, without a Bearer prefix. This is the only
endpoint that doesn't need a token.
If the user has two-factor authentication enabled, include the current code from their
authenticator app in otp_attempt. After too many failed attempts the user is locked and
sign-in returns 423; contact Depa support to unlock it.
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Credentials of a Depa user.
Response Body
application/json
application/json
application/json
curl -X POST "https://example.com/sign_in" \ -H "Content-Type: application/json" \ -d '{ "email": "developer@yourcompany.com", "password": "your-password" }'{ "data": { "token": "eyJhbGciOiJIUzI1NiJ9.eyJ1c2VyX3V1aWQiOiI3ZGU4OWQ2MiIsImV4cCI6MTc3NTQ4Nzk1M30.Qm9ndXNTaWduYXR1cmU" }}