Preparation

Create App

To add an application in System Settings -> Application Settings, select module permissions and generate client_id and client_secret.

Get Token

GET /open/auth/token

Query Params

Field Name Field Type Default Value
client_id string -
client_secret string -

This GET request uses query parameters and does not require a request body.

Response Body Params

{
  "code": 200,
  "data": {
    "token": "xxxxxx",
    "token_type": "Bearer",
    "expiration": 1237889999
  }
}

expiration is a Unix timestamp in seconds, not milliseconds or a remaining duration. Tokens currently last 30 days. Each application keeps up to 5 valid tokens; further requests reuse the fifth token and extend its expiration. Resetting the application secret invalidates existing tokens.

Making API Requests

Use the token obtained above to make API requests. The base path for all module interfaces is /open

Request Example

curl 'http://[host]:[port]/open/envs' \
  -H 'Accept: application/json' \
  -H 'Authorization: Bearer {token}'

Use the CLI

The remote CLI handles application login and token refresh:

ql login --url https://ql.example.com
ql auth status --scope envs --json
ql env list --json