Authentication

Log in, refresh the token, or use a long-lived token

  1. Log in
  2. Call the API
  3. Refresh the token
  4. Long-lived tokens

Every call needs an access token in the Authorization header. A token is obtained by logging in, and kept fresh with the refresh token.

Log in

Log in with basic authentication, with the user’s name and password:

curl -X POST https://af.example.com/api/v2/auth/login -u admin:<password>

The response holds two tokens:

{ "accessToken": "eyJ...", "refreshToken": "eyJ..." }

Call the API

Send the access token as a bearer token with every call:

curl https://af.example.com/api/v2/job/42 -H "Authorization: Bearer <accessToken>"

Refresh the token

The access token expires (ACCESS_TOKEN_EXPIRATION, 30 minutes by default). Get a new one with the refresh token, without the password:

curl -X POST https://af.example.com/api/v2/token \
  -H "Content-Type: application/json" -d '{ "refreshToken": "<refreshToken>" }'

Long-lived tokens

A script that runs unattended can use a token that lasts longer. It needs the extendedTokenExpiration role option:

  • Create one under Profile > API token.
  • Or log in with expiryDays, for a token valid that many days:
curl -X POST https://af.example.com/api/v2/auth/login -u automation:<password> -d expiryDays=90

Copyright © 2023-2026 AnsibleForms. All rights reserved.

This site uses Just the Docs, a documentation theme for Jekyll.