1Fort Authentication API

One-time-password (OTP) authentication. **Access:** public; no authentication required.

OpenAPI Specification

1fort-authentication-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: 1Fort API Documentation Authentication API
  description: '# 1Fort API


    REST API for the 1Fort insurance platform. This document is the authoritative

    map of the API surface; endpoints are grouped in the sidebar by **app** and

    **version**, and large apps are split into per-resource sub-groups.


    ## Authentication


    Almost every endpoint requires a **JWT access token**. Send it in the

    `Authorization` header as either `Bearer <token>` or `JWT <token>`. Tokens may

    also be presented as an HTTP-only cookie. Endpoints documented with no security

    requirement are intentionally public (for example sign-in, OTP and storefront

    endpoints).


    ## Multi-tenancy


    Resources are scoped to a tenant. Nested routes carry the owning resource id in

    the path (for example `/v2/broker/{business_pk}/applications`); a token is only

    authorised for the businesses its user may access. Object-level permissions are

    enforced per endpoint.


    ## Versioning


    `v2` endpoints live under `/apis/v2/...` and are the current surface. `v1`

    endpoints remain documented for compatibility. Endpoints marked **deprecated**

    are scheduled for removal; prefer the documented replacement.

    '
  termsOfService: https://www.1fort.com/
  license:
    name: Privately owned
  version: v1
servers:
- url: https://api.1fort.com/apis/
security:
- Bearer: []
tags:
- name: Authentication
  x-displayName: OTP
  description: 'One-time-password (OTP) authentication.


    **Access:** public; no authentication required.'
paths:
  /otp:
    parameters: []
    post:
      operationId: otp_create
      summary: Request or Verify Email OTP
      description: '

        Handles both requesting an OTP and verifying it for login/signup.


        **Step 1: Request OTP**

        - Provide `email` and `action` (''signup'' or ''login'').

        - Sends an OTP to the email if validation passes.

        - Returns: `{"message": "OTP sent..."}`


        **Step 2: Verify OTP & Authenticate**

        - Provide `email` and `code` received via email.

        - Optionally provide `auth_type`: ''session'' (default) or ''jwt''.

        - Optionally provide `first_name`, `last_name`, `user_role` if signing up.

        - Verifies the code. If valid, creates user (if signup) and authenticates.

        - Returns (Session Auth): `{"user": {...}, "created": bool, "auth_type": "session"}` -> Browser receives `sessionid` and `csrftoken` cookies.

        - Returns (JWT Auth, if enabled): `{"user": {...}, "created": bool, "auth_type": "jwt", "access": "...", "refresh": "..."}`

        '
      responses:
        '201':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/OTPEmail'
        '400':
          description: Invalid input.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ValidationError'
        '500':
          description: Internal server error.
      tags:
      - Authentication
      security: []
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/OTPEmail'
        required: true
components:
  schemas:
    OTPEmail:
      required:
      - email
      type: object
      properties:
        email:
          title: Email address
          type: string
          format: email
          maxLength: 255
          minLength: 1
        code:
          title: Code
          type: string
          maxLength: 6
          minLength: 1
        refresh:
          title: Refresh
          type: string
          readOnly: true
          minLength: 1
        access:
          title: Access
          type: string
          readOnly: true
          minLength: 1
        created:
          title: Created
          type: boolean
          readOnly: true
        user:
          $ref: '#/components/schemas/UserList'
        action:
          title: Action
          type: string
          enum:
          - login
          - signup
        first_name:
          title: First name
          type: string
          minLength: 1
        last_name:
          title: Last name
          type: string
          minLength: 1
        auth_type:
          title: Auth type
          description: Choose 'session' (default) or 'jwt' for authentication method upon successful OTP verification.
          type: string
          enum:
          - session
          - jwt
          default: jwt
        access_expires_in_seconds:
          title: Access expires in seconds
          type: integer
          readOnly: true
    ValidationError:
      title: Validation Error
      type: object
      properties:
        non_field_errors:
          description: List of validation errors not related to any field
          type: array
          items:
            type: string
      additionalProperties:
        description: A list of error messages for each field that triggered a validation error
        type: array
        items:
          type: string
    UserList:
      type: object
      properties:
        id:
          title: ID
          type: integer
          readOnly: true
        email:
          title: Email address
          type: string
          format: email
          readOnly: true
          minLength: 1
        first_name:
          title: First name
          type: string
          maxLength: 150
        last_name:
          title: Last name
          type: string
          maxLength: 150
        title:
          title: Title
          type:
          - string
          - 'null'
          maxLength: 50
        role:
          title: Role
          description: Role is for determining the access level control of the user.
          type:
          - string
          - 'null'
          enum:
          - Owner
          - Admin
          - User
          - Broker
          - Underwriter
          readOnly: true
  securitySchemes:
    Bearer:
      type: apiKey
      name: Authorization
      in: header
      description: JWT access token. Send as `Bearer <token>` or `JWT <token>`.
    ApiKey:
      type: apiKey
      name: Authorization
      in: header
      description: API key. Send as `Api-Key <key>`.
x-tagGroups:
- name: Agent runtime (v2)
  tags:
  - agent_runtime (v2)
- name: Analytics
  tags:
  - analytics
- name: Application
  tags:
  - 'application: applications'
  - 'application: clients'
- name: Application (v2)
  tags:
  - 'application (v2): applications'
  - 'application (v2): coverages'
- name: Ascend
  tags:
  - ascend
- name: Ascend (v2)
  tags:
  - ascend (v2)
- name: Authentication
  tags:
  - Authentication
  - auth
- name: Billing (v2)
  tags:
  - billing (v2)
- name: Broker
  tags:
  - broker
  - broker-ams-integration
  - broker-google
  - broker-office365
  - broker-office365-individual
  - 'broker: ai-customization-types'
  - 'broker: ai-customizations'
  - 'broker: clients'
  - 'broker: email_preferences'
  - 'broker: proposal-preferences'
  - 'broker: take-rates'
  - 'broker: user-ai-customizations'
  - 'broker: users'
  - broker_groups
  - broker_settings
- name: Broker (v2)
  tags:
  - 'broker (v2): applications'
  - 'broker (v2): clients'
  - 'broker (v2): coverages'
  - 'broker (v2): email-templates'
  - 'broker (v2): quote-policies'
  - 'broker (v2): quotes'
  - 'broker (v2): storefront'
  - 'broker (v2): team-users'
- name: Business
  tags:
  - business
  - business-broker-users
  - business-user
  - business_admin
- name: Carrier
  tags:
  - carrier
- name: Checkout
  tags:
  - checkout
- name: Email AI
  tags:
  - email_ai
- name: Email AI (v2)
  tags:
  - 'email_ai (v2): attachments'
  - 'email_ai (v2): carriers'
  - 'email_ai (v2): coverage-types'
  - 'email_ai (v2): emails'
  - 'email_ai (v2): gmail'
  - 'email_ai (v2): office365'
  - 'email_ai (v2): profiles'
  - 'email_ai (v2): wholesalers'
- name: Email AI Agent
  tags:
  - Email AI Agent
  - Email AI Agent - Attachments
  - Email AI Agent - Businesses
  - Email AI Agent - Entities
  - Email AI Agent - Markets
  - Email AI Agent - Profiles
  - Email AI Agent - Reference Data
- name: Google workspace (v2)
  tags:
  - google_workspace (v2)
- name: Herald (v2)
  tags:
  - herald (v2)
- name: Indications (v2)
  tags:
  - indications (v2)
- name: Insurance (v2)
  tags:
  - insurance (v2)
- name: Invite
  tags:
  - invite
- name: Legal
  tags:
  - legal
- name: Market
  tags:
  - Markets
  - Markets - Business
- name: Market (v2)
  tags:
  - market (v2)
- name: Office365 (v2)
  tags:
  - office365 (v2)
- name: Premium finance (v2)
  tags:
  - premium_finance (v2)
- name: Quote
  tags:
  - 'quote: applications'
  - 'quote: clients'
  - 'quote: quotes'
- name: Quote (v2)
  tags:
  - 'quote (v2): application'
  - 'quote (v2): binders'
  - 'quote (v2): checkout'
  - 'quote (v2): cios'
  - 'quote (v2): coverages'
  - 'quote (v2): quote-policies'
  - 'quote (v2): quotes'
  - 'quote (v2): tasks'
  - quote_ai (v2)
- name: Reports
  tags:
  - reports
- name: Reward
  tags:
  - reward
- name: Risk manager
  tags:
  - risk_manager
- name: Sanity check AI
  tags:
  - sanity_check_ai
- name: Storefront (v2)
  tags:
  - storefront (v2)
- name: Stripe
  tags:
  - stripe
- name: Suggestion AI
  tags:
  - suggestion_ai
- name: Treasury (v2)
  tags:
  - treasury (v2)
- name: User
  tags:
  - user
  - 'user: default-access-role'