External Rel ID & Rel Str

Generate a set of login tokens

POST/users/{extRelationId}/authenticationTokens

Generate a set of single-use tokens that sign the user into the client area. Requires a commercial licence.

Request

Authorization
Provide your bearer token in the Authorization header when making requests to protected resources.
Example: Authorization: Bearer ********************
Path Params#
extRelationIdstring#required

A valid external relational ID as shown in VirtFusion.

Example: 1
Query Params#
relStrboolean#

When true, the path value is matched against the user's relation string instead of the external relation ID.

Default: false
Body Paramsapplication/json#

return_url is where the user is sent after logging out.

object
return_urlstring#

Optional URL the user is returned to after the token login.

Example
{
    "return_url": "https://billing.example.com/clientarea"
}

Request Code Samples

curl --location --request POST 'https://cp.domain.com/api/v1/users/1/authenticationTokens' \
--header 'Authorization: Bearer <token>' \
--header 'Accept: application/json' \
--header 'Content-Type: application/json' \
--data-raw '{
    "return_url": "https://billing.example.com/clientarea"
}'
wget --quiet --output-document=- \
  --method=POST \
  --header='Authorization: Bearer <token>' \
  --header='Accept: application/json' \
  --header='Content-Type: application/json' \
  --body-data='{
    "return_url": "https://billing.example.com/clientarea"
}' \
  'https://cp.domain.com/api/v1/users/1/authenticationTokens'
http POST 'https://cp.domain.com/api/v1/users/1/authenticationTokens' \
  'Authorization: Bearer <token>' \
  'Accept: application/json' \
  'Content-Type: application/json' <<< '{
    "return_url": "https://billing.example.com/clientarea"
}'
const response = await fetch("https://cp.domain.com/api/v1/users/1/authenticationTokens", {
    method: "POST",
    headers: {
        "Authorization": "Bearer <token>",
        "Accept": "application/json",
        "Content-Type": "application/json",
    },
    body: JSON.stringify({
        "return_url": "https://billing.example.com/clientarea"
    }),
});

const data = await response.json();
console.log(response.status, data);
import axios from "axios";

const response = await axios({
    method: "post",
    url: "https://cp.domain.com/api/v1/users/1/authenticationTokens",
    headers: {
        "Authorization": "Bearer <token>",
        "Accept": "application/json",
        "Content-Type": "application/json",
    },
    data: {
        "return_url": "https://billing.example.com/clientarea"
    },
});

console.log(response.status, response.data);
const https = require("https");

const payload = JSON.stringify({
    "return_url": "https://billing.example.com/clientarea"
});

const req = https.request({
    hostname: "cp.domain.com",
    path: "/api/v1/users/1/authenticationTokens",
    method: "POST",
    headers: {
        "Authorization": "Bearer <token>",
        "Accept": "application/json",
        "Content-Type": "application/json",
        "Content-Length": Buffer.byteLength(payload),
    },
}, (res) => {
    let data = "";
    res.on("data", (chunk) => (data += chunk));
    res.on("end", () => console.log(res.statusCode, JSON.parse(data)));
});

req.on("error", (err) => console.error(err));
req.write(payload);
req.end();
import requests

url = "https://cp.domain.com/api/v1/users/1/authenticationTokens"
headers = {
    "Authorization": "Bearer <token>",
    "Accept": "application/json",
    "Content-Type": "application/json",
}
payload = {
    "return_url": "https://billing.example.com/clientarea",
}

response = requests.request("POST", url, headers=headers, json=payload)

print(response.status_code)
print(response.json())
import http.client
import json

conn = http.client.HTTPSConnection("cp.domain.com")
headers = {
    "Authorization": "Bearer <token>",
    "Accept": "application/json",
    "Content-Type": "application/json",
}
payload = json.dumps({
    "return_url": "https://billing.example.com/clientarea",
})

conn.request("POST", "/api/v1/users/1/authenticationTokens", payload, headers)
response = conn.getresponse()

print(response.status)
print(json.loads(response.read()))
<?php

$curl = curl_init();

curl_setopt_array($curl, array(
    CURLOPT_URL => 'https://cp.domain.com/api/v1/users/1/authenticationTokens',
    CURLOPT_RETURNTRANSFER => true,
    CURLOPT_ENCODING => '',
    CURLOPT_MAXREDIRS => 10,
    CURLOPT_TIMEOUT => 0,
    CURLOPT_FOLLOWLOCATION => true,
    CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
    CURLOPT_CUSTOMREQUEST => 'POST',
    CURLOPT_POSTFIELDS => json_encode([
        'return_url' => 'https://billing.example.com/clientarea',
    ]),
    CURLOPT_HTTPHEADER => array(
        'Authorization: Bearer <token>',
        'Accept: application/json',
        'Content-Type: application/json'
    ),
));

$response = curl_exec($curl);
curl_close($curl);

echo $response;
<?php

require 'vendor/autoload.php';

use GuzzleHttp\Client;

$client = new Client();

$response = $client->request('POST', 'https://cp.domain.com/api/v1/users/1/authenticationTokens', [
    'headers' => [
        'Authorization' => 'Bearer <token>',
        'Accept' => 'application/json',
    ],
    'json' => [
        'return_url' => 'https://billing.example.com/clientarea',
    ],
]);

echo $response->getStatusCode() . "\n";
echo $response->getBody();
package main

import (
    "fmt"
    "io"
    "net/http"
    "strings"
)

func main() {
    url := "https://cp.domain.com/api/v1/users/1/authenticationTokens"
    payload := strings.NewReader(`{
    "return_url": "https://billing.example.com/clientarea"
}`)
    req, _ := http.NewRequest("POST", url, payload)
    req.Header.Add("Authorization", "Bearer <token>")
    req.Header.Add("Accept", "application/json")
    req.Header.Add("Content-Type", "application/json")

    res, err := http.DefaultClient.Do(req)
    if err != nil {
        panic(err)
    }
    defer res.Body.Close()

    body, _ := io.ReadAll(res.Body)
    fmt.Println(res.StatusCode, string(body))
}
import java.net.URI;
import java.net.http.HttpClient;
import java.net.http.HttpRequest;
import java.net.http.HttpResponse;

public class Main {
    public static void main(String[] args) throws Exception {
        HttpClient client = HttpClient.newHttpClient();

        HttpRequest request = HttpRequest.newBuilder()
            .uri(URI.create("https://cp.domain.com/api/v1/users/1/authenticationTokens"))
            .header("Authorization", "Bearer <token>")
            .header("Accept", "application/json")
            .header("Content-Type", "application/json")
            .method("POST", HttpRequest.BodyPublishers.ofString("{\"return_url\":\"https://billing.example.com/clientarea\"}"))
            .build();

        HttpResponse<String> response = client.send(request, HttpResponse.BodyHandlers.ofString());
        System.out.println(response.statusCode());
        System.out.println(response.body());
    }
}
import okhttp3.*;

public class Main {
    public static void main(String[] args) throws Exception {
        OkHttpClient client = new OkHttpClient();

        MediaType json = MediaType.get("application/json");
        RequestBody body = RequestBody.create("{\"return_url\":\"https://billing.example.com/clientarea\"}", json);

        Request request = new Request.Builder()
            .url("https://cp.domain.com/api/v1/users/1/authenticationTokens")
            .method("POST", body)
            .addHeader("Authorization", "Bearer <token>")
            .addHeader("Accept", "application/json")
            .build();

        try (Response response = client.newCall(request).execute()) {
            System.out.println(response.code());
            System.out.println(response.body().string());
        }
    }
}
using System.Net.Http;
using System.Net.Http.Headers;
using System.Text;

var client = new HttpClient();
var request = new HttpRequestMessage(new HttpMethod("POST"), "https://cp.domain.com/api/v1/users/1/authenticationTokens");
request.Headers.Authorization = new AuthenticationHeaderValue("Bearer", "<token>");
request.Headers.Accept.Add(new MediaTypeWithQualityHeaderValue("application/json"));
request.Content = new StringContent("{\"return_url\":\"https://billing.example.com/clientarea\"}", Encoding.UTF8, "application/json");

var response = await client.SendAsync(request);
Console.WriteLine((int)response.StatusCode);
Console.WriteLine(await response.Content.ReadAsStringAsync());
require "net/http"
require "json"

uri = URI("https://cp.domain.com/api/v1/users/1/authenticationTokens")
request = Net::HTTP::Post.new(uri)
request["Authorization"] = "Bearer <token>"
request["Accept"] = "application/json"
request["Content-Type"] = "application/json"
request.body = "{\"return_url\":\"https://billing.example.com/clientarea\"}"

response = Net::HTTP.start(uri.host, uri.port, use_ssl: true) do |http|
  http.request(request)
end

puts response.code
puts JSON.pretty_generate(JSON.parse(response.body))
import Foundation

var request = URLRequest(url: URL(string: "https://cp.domain.com/api/v1/users/1/authenticationTokens")!)
request.httpMethod = "POST"
request.setValue("Bearer <token>", forHTTPHeaderField: "Authorization")
request.setValue("application/json", forHTTPHeaderField: "Accept")
request.setValue("application/json", forHTTPHeaderField: "Content-Type")
request.httpBody = "{\"return_url\":\"https://billing.example.com/clientarea\"}".data(using: .utf8)

let task = URLSession.shared.dataTask(with: request) { data, response, error in
    guard let data = data, error == nil else { print(error ?? "request failed"); return }
    print((response as! HTTPURLResponse).statusCode)
    print(String(data: data, encoding: .utf8) ?? "")
}
task.resume()
// Cargo.toml: reqwest = { version = "0.12", features = ["blocking", "json"] }, serde_json = "1"
use reqwest::blocking::Client;

fn main() -> Result<(), Box<dyn std::error::Error>> {
    let client = Client::new();
    let response = client
        .request(reqwest::Method::POST, "https://cp.domain.com/api/v1/users/1/authenticationTokens")
        .bearer_auth("<token>")
        .header("Accept", "application/json")
        .header("Content-Type", "application/json")
        .body(r#"{
    "return_url": "https://billing.example.com/clientarea"
}"#)
        .send()?;

    println!("{}", response.status());
    let json: serde_json::Value = response.json()?;
    println!("{}", serde_json::to_string_pretty(&json)?);
    Ok(())
}
// Cargo.toml: reqwest = { version = "0.12", features = ["json"] }, tokio = { version = "1", features = ["full"] }, serde_json = "1"
use reqwest::Client;

#[tokio::main]
async fn main() -> Result<(), Box<dyn std::error::Error>> {
    let client = Client::new();
    let response = client
        .request(reqwest::Method::POST, "https://cp.domain.com/api/v1/users/1/authenticationTokens")
        .bearer_auth("<token>")
        .header("Accept", "application/json")
        .header("Content-Type", "application/json")
        .body(r#"{
    "return_url": "https://billing.example.com/clientarea"
}"#)
        .send()
        .await?;

    println!("{}", response.status());
    let json: serde_json::Value = response.json().await?;
    println!("{}", serde_json::to_string_pretty(&json)?);
    Ok(())
}
import okhttp3.MediaType.Companion.toMediaType
import okhttp3.OkHttpClient
import okhttp3.Request
import okhttp3.RequestBody.Companion.toRequestBody

fun main() {
    val client = OkHttpClient()
    val body = """{
    "return_url": "https://billing.example.com/clientarea"
}""".toRequestBody("application/json".toMediaType())
    val request = Request.Builder()
        .url("https://cp.domain.com/api/v1/users/1/authenticationTokens")
        .method("POST", body)
        .addHeader("Authorization", "Bearer <token>")
        .addHeader("Accept", "application/json")
        .build()

    client.newCall(request).execute().use { response ->
        println(response.code)
        println(response.body?.string())
    }
}
// pubspec.yaml: http: ^1.2.0
import 'dart:convert';
import 'package:http/http.dart' as http;

Future<void> main() async {
  final request = http.Request('POST', Uri.parse('https://cp.domain.com/api/v1/users/1/authenticationTokens'));
  request.headers['Authorization'] = 'Bearer <token>';
  request.headers['Accept'] = 'application/json';
  request.headers['Content-Type'] = 'application/json';
  request.body = r'''{
    "return_url": "https://billing.example.com/clientarea"
}''';

  final response = await http.Response.fromStream(await request.send());
  print(response.statusCode);
  print(const JsonEncoder.withIndent('  ').convert(jsonDecode(response.body)));
}
#include <stdio.h>
#include <curl/curl.h>

int main(void) {
    CURL *curl = curl_easy_init();
    if (!curl) return 1;

    struct curl_slist *headers = NULL;
    headers = curl_slist_append(headers, "Authorization: Bearer <token>");
    headers = curl_slist_append(headers, "Accept: application/json");
    headers = curl_slist_append(headers, "Content-Type: application/json");

    curl_easy_setopt(curl, CURLOPT_URL, "https://cp.domain.com/api/v1/users/1/authenticationTokens");
    curl_easy_setopt(curl, CURLOPT_CUSTOMREQUEST, "POST");
    curl_easy_setopt(curl, CURLOPT_HTTPHEADER, headers);
    curl_easy_setopt(curl, CURLOPT_POSTFIELDS, "{\"return_url\":\"https://billing.example.com/clientarea\"}");

    CURLcode result = curl_easy_perform(curl);
    if (result != CURLE_OK) fprintf(stderr, "%s\n", curl_easy_strerror(result));

    curl_slist_free_all(headers);
    curl_easy_cleanup(curl);
    return result == CURLE_OK ? 0 : 1;
}
$headers = @{
    Authorization = "Bearer <token>"
    Accept        = "application/json"
}

$body = @'
{
    "return_url": "https://billing.example.com/clientarea"
}
'@

$response = Invoke-RestMethod -Uri "https://cp.domain.com/api/v1/users/1/authenticationTokens" -Method POST -Headers $headers -ContentType "application/json" -Body $body
$response | ConvertTo-Json -Depth 10
POST /api/v1/users/1/authenticationTokens HTTP/1.1
Host: cp.domain.com
Authorization: Bearer <token>
Accept: application/json
Content-Type: application/json
Content-Length: 62

{
    "return_url": "https://billing.example.com/clientarea"
}

Responses

200

OK.

#
application/json
object
dataobject#
fields
authenticationobject#
fields
tokensobject#
fields
1string#
2string#
endpointstring#
endpoint_completestring#
expiryobject#
fields
ttlinteger#
expiresstring <date-time>#
Example
{
    "data": {
        "authentication": {
            "tokens": {
                "1": "zYpEXpWEeXR4LfogW3xIomIJS5YW8woOjo18h9st6Sh23ReeTEeQNI1RSQWXYv1AImtQzFm0CLrn6Ve8VtIP3MfDnoRWHxQ334UU",
                "2": "RGzuQDFt0KsWgPozaTZDpuXy3aSsbj6VHWbz4JrhGoj0ZOvaGHUcXM6WGeGuNgfTUPLcy0SYMNJWmI1idC8uR88ZSs00XRnEtbG9"
            },
            "endpoint": "/token_authenticate",
            "endpoint_complete": "/token_authenticate/?1=zYpEXpWEeXR4LfogW3xIomIJS5YW8woOjo18h9st6Sh23ReeTEeQNI1RSQWXYv1AImtQzFm0CLrn6Ve8VtIP3MfDnoRWHxQ334UU&2=RGzuQDFt0KsWgPozaTZDpuXy3aSsbj6VHWbz4JrhGoj0ZOvaGHUcXM6WGeGuNgfTUPLcy0SYMNJWmI1idC8uR88ZSs00XRnEtbG9",
            "expiry": {
                "ttl": 60,
                "expires": "2025-01-20T12:49:52.170943Z"
            }
        }
    }
}
401

The bearer token is missing, invalid, or expired. The response has no body.

#
No response body.
403

The API token does not have the permission this endpoint requires.

#
application/json
msgstring#
Example
{
    "msg": "the API token does not have the necessary permissions"
}
404

The user was not found.

#
application/json
msgstring#
Example
{
    "msg": "user not found"
}
422

Authentication tokens require a commercial licence.

#
application/json
errorsarray[string]#
Example
{
    "errors": [
        "This method is unavailable in a non commercial license"
    ]
}
429

Too many requests. Either the token's requests per minute are used up (see the `X-RateL…

#
application/json

Too many requests. Either the token's requests per minute are used up (see the X-RateLimit-* headers) or the calling address has failed authentication 10 times in a minute (the body then includes retry_after_seconds). Retry-After gives the seconds to wait.

object
errorsarray[string]#
retry_after_secondsinteger#

Seconds to wait before retrying. Present on the failed-authentication limit only.

Response headers
Retry-Afterinteger

Seconds to wait before retrying.

X-RateLimit-Limitinteger

The token's requests per minute (token limit only).

X-RateLimit-Remaininginteger

Requests left in the current minute (token limit only).

X-RateLimit-Resetinteger

Unix timestamp at which the minute resets (token limit only).

Examples
{
    "errors": [
        "Too Many Requests"
    ]
}
{
    "errors": [
        "Too many authentication attempts. Try again later."
    ],
    "retry_after_seconds": 42
}