Depa LogoDocsv1
API Reference

Authentication

Authenticate every request by sending a token as the raw value of the `Authorization` header, without a `Bearer` prefix.

Authorization: <token>

The token can be either of:

  • An API key, which Depa issues for server-to-server integrations. Use it as is.
  • A user token (JWT) from POST /sign_in, for actions taken on behalf of a person, such as four-eyes approvals. If the user has two-factor authentication enabled, add the current one-time code as otp_attempt when signing in.

User tokens expire, and stop working early if they're revoked or the user's password changes. A missing, invalid or expired token returns 401 with {"error": "You are not authenticated."}; sign in again to get a new one.

The user token is a standard JWT, so you can read its payload without calling the API. It includes user_uuid, main_account_uuid, your roles, the vaults you can access (use these IDs in the /vaults/{vault_id}/… endpoints) and exp, the expiry time in Unix seconds.

What a token can do depends on its user's roles: api_read allows reading and api_write allows changes. Calls outside those permissions return 403.

Sandbox and production are separate environments with separate credentials. Build and test against https://api.sandbox.depa.finance/v1.

Sign in

POST/sign_in

Exchanges a user's email and password for a JWT. Send it as the raw value of the Authorization header on every other request, without a Bearer prefix. This is the only endpoint that doesn't need a token.

If the user has two-factor authentication enabled, include the current code from their authenticator app in otp_attempt. After too many failed attempts the user is locked and sign-in returns 423; contact Depa support to unlock it.

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Credentials of a Depa user.

Response Body

application/json

application/json

application/json

curl -X POST "https://example.com/sign_in" \  -H "Content-Type: application/json" \  -d '{    "email": "developer@yourcompany.com",    "password": "your-password"  }'
{  "data": {    "token": "eyJhbGciOiJIUzI1NiJ9.eyJ1c2VyX3V1aWQiOiI3ZGU4OWQ2MiIsImV4cCI6MTc3NTQ4Nzk1M30.Qm9ndXNTaWduYXR1cmU"  }}
🍪 We do not track your behaviour or use any cookie on this site.