Avnet /IOTCONNECT Authenticate API

Login with a solution-key header to obtain the JWT bearer token every other /IOTCONNECT module requires; refresh, verify and mobile-login methods. Part of Avnet's /IOTCONNECT IoT platform REST API (5 operations, API version 2); every request carries a JWT bearer token issued by the Authenticate API and the docs page serves the live Swagger 2.0 definition per module, environment and cloud platform (Azure or AWS).

Operations 5

GET /api/v2/Auth/basic-token Generate basic token
POST /api/v2/Auth/login Login
POST /api/v2/Auth/refresh-token Refresh access token
GET /api/v2/Auth/verify-token Verify access token
POST /api/v2/Auth/m-login Login from Mobile

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/avnet-iotconnect-authenticate-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

avnet-iotconnect-auth-openapi.yml Raw ↑
openapi: 3.0.0
info:
  title: /IOTCONNECT™ Authenticate API
  description: "Authenticate your Web API requests by providing a bearer token, which identifies a single user, application\
    \ relationship. We prefer tokens to be sent in the Authorization HTTP header of your outbound requests. However, you may\
    \ also pass tokens in all Web API calls as a parameter called token.\n<br /> Also, it will contain the API method list\
    \ for the Login and refresh the bearer token.. \n<br />\n<br /> Authorization &emsp;&nbsp;  &emsp;<b><i style=\"font-style:\
    \ italic !important;\">Bearer + access_token (Generated From api/v1.1/auth/login API)</i></b>\n<br /> Content-Type &emsp;&nbsp;&emsp;<b><i\
    \ style=\"font-style: italic !important;\">application/json</i></b></p>"
  version: '2.0'
  x-source: https://auth.iotconnect.io/api/v2/swagger-json
  x-harvested: '2026-09-18'
  x-original: openapi/_original/avnet-iotconnect-auth-azure-prod-swagger.json
  x-conversion: Swagger 2.0 -> OpenAPI 3.0.0 via swagger2openapi; operations, parameters, schemas and responses are as published
    — only servers[] and these x- provenance keys were added. No operationIds are published by the provider and none were
    invented.
  x-ownership: IoTConnect is Avnet's own IoT platform (docs.iotconnect.io is titled "Avnet /IOTCONNECT", carries "Copyright
    Avnet, Inc." and links github.com/avnet-iotconnect); the product lives on iotconnect.io rather than avnet.com.
servers:
- url: https://auth.iotconnect.io
  description: /IOTCONNECT production (Azure platform) — the host the docs page resolves for env=prod&pf=az; paths carry the
    /api/v2 prefix
paths:
  /api/v2/Auth/basic-token:
    get:
      tags:
      - Auth
      summary: Generate basic token
      description: <p>We are using the OAuth 2.0 protocol for authentication and authorization. Login API endpoint needs basic
        authentication to validate your request. This API endpoint will generate that basic authentication token, which you
        need for the Login API endpoint. This token informs the API that the bearer of the token has been authorized to access
        the Login API.</p>
      responses:
        '200':
          description: Indicates that basic token is created successfully and returns generated basic token
          content:
            '*/*':
              schema:
                $ref: '#/components/schemas/BasicTokenCreateResponse'
        '500':
          description: Indicates that the request could not be carried out because of some technical error on the server.
          content:
            '*/*':
              schema:
                $ref: '#/components/schemas/ConflictErrorModel'
  /api/v2/Auth/login:
    post:
      tags:
      - Auth
      summary: Login
      description: "<p>Before you can access private data using IoTConnect API, you must obtain an access token that grants\
        \ access to that API. A single access token can grant varying degrees of access to multiple IoTConnect APIs. Once\
        \ you get an access token, send it to IoTConnect API in an HTTP authorization header. Access tokens are valid only\
        \ for the set of operations and resources described in the scope of the token. Along with an access token, you will\
        \ also receive a refresh token. This refresh token allows you to get new access tokens.</p>\r\n<p>We are using the\
        \ OAuth 2.0 protocol for authentication and authorization. To begin, obtain a basic token from the basic token API\
        \ endpoint. Then, request an access token from the IoTConnect Authorization Server, extract a token from the response,\
        \ and send the token to the IoTConnect API that you want to access.</p>\r\n<p>During the access token request, you\
        \ need to pass your IoTConnect account username and password in body. While in Request Header, you need to submit\
        \ basic token and solution key.</p>"
      parameters:
      - name: solution-key
        in: header
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/LoginRequest'
      responses:
        '200':
          description: Indicates that access token is created successfully and returns generated access token along with refresh
            token
          content:
            '*/*':
              schema:
                $ref: '#/components/schemas/LoginResponse'
        '401':
          description: Indicates that authentication is failed because of the wrong username/password or the user is not authorized
            to access given solution.
          content:
            '*/*':
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '500':
          description: Indicates that the request could not be carried out because of some technical error on the server.
          content:
            '*/*':
              schema:
                $ref: '#/components/schemas/ConflictErrorModel'
  /api/v2/Auth/refresh-token:
    post:
      tags:
      - Auth
      summary: Refresh access token
      description: "<p>Access tokens have a limited lifespan. If you need access to the IoTConnect API beyond the lifespan\
        \ of a single access token, get a refresh token. A refresh token allows you to obtain new access tokens.</p>\r\n<p>During\
        \ the refresh token request, you need to send refresh_token, which you received in the login API endpoint response.</p>"
      responses:
        '200':
          description: Indicates that refresh token is created successfully and returns generated access token along with
            new refresh token
          content:
            '*/*':
              schema:
                $ref: '#/components/schemas/LoginResponse'
        '409':
          description: Indicates that supplied refresh token is not valid.
        '500':
          description: Indicates that the request could not be carried out because of some technical error on the server.
          content:
            '*/*':
              schema:
                $ref: '#/components/schemas/ConflictErrorModel'
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RefreshTokenRequest'
  /api/v2/Auth/verify-token:
    get:
      tags:
      - Auth
      summary: Verify access token
      description: <p>This API endpoint verifies the validity of your access token.</p>
      responses:
        '200':
          description: Indicates that access token is verified successfully
          content:
            '*/*':
              schema:
                $ref: '#/components/schemas/ArrayBaseResponse'
        '401':
          description: Indicates that authentication is failed because of the token is invalid or expired or missing.
        '500':
          description: Indicates that the request could not be carried out because of some technical error on the server.
          content:
            '*/*':
              schema:
                $ref: '#/components/schemas/ConflictErrorModel'
  /api/v2/Auth/m-login:
    post:
      tags:
      - Auth
      summary: Login from Mobile
      description: "<p>This Api endpoint will be used for mobile application login. Before your mobile device can access private\
        \ data using IoTConnect API, you must obtain an access token that grants access to that API. A single access token\
        \ can grant varying degrees of access to multiple IoTConnect APIs. Once you get an access token, send it to IoTConnect\
        \ API in an HTTP authorization header. Access tokens are valid only for the set of operations and resources described\
        \ in the scope of the token. Along with an access token, you will also receive a refresh token. This refresh token\
        \ allows you to get new access tokens.</p>\r\n<p>We are using the OAuth 2.0 protocol for authentication and authorization.\
        \ To begin, obtain a basic token from the basic token API endpoint. Then, request an access token from the IoTConnect\
        \ Authorization Server, extract a token from the response, and send the token to the IoTConnect API that you want\
        \ to access.</p>\r\n<p>During the access token request, you need to send username and password along with deviceType,\
        \ osName, osVersion, uuid and deviceToken in the request body. While in Request Header, you need to submit a basic\
        \ token and solution key.</p>"
      parameters:
      - name: solution-key
        in: header
        required: true
        schema:
          type: string
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/MobileLoginRequest'
      responses:
        '200':
          description: Indicates that access token is created successfully and returns generated access token along with refresh
            token
          content:
            '*/*':
              schema:
                $ref: '#/components/schemas/MobileLoginResponse'
        '401':
          description: Indicates that authentication is failed because of the wrong username/password or the user is not authorized
            to access given solution.
          content:
            '*/*':
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '500':
          description: Indicates that the request could not be carried out because of some technical error on the server.
          content:
            '*/*':
              schema:
                $ref: '#/components/schemas/ConflictErrorModel'
security:
- Bearer: []
tags:
- name: Auth
  description: Auth Api List
components:
  securitySchemes:
    Bearer:
      type: apiKey
      description: Please enter JWT with Bearer into field
      name: Authorization
      in: header
  schemas:
    ArrayBaseResponse:
      type: object
      properties:
        data:
          type: array
          items:
            type: object
            nullable: true
          nullable: true
        status:
          enum:
          - 100
          - 101
          - 102
          - 103
          - 200
          - 201
          - 202
          - 203
          - 204
          - 205
          - 206
          - 207
          - 208
          - 226
          - 300
          - 301
          - 302
          - 303
          - 304
          - 305
          - 306
          - 307
          - 308
          - 400
          - 401
          - 402
          - 403
          - 404
          - 405
          - 406
          - 407
          - 408
          - 409
          - 410
          - 411
          - 412
          - 413
          - 414
          - 415
          - 416
          - 417
          - 421
          - 422
          - 423
          - 424
          - 426
          - 428
          - 429
          - 431
          - 451
          - 500
          - 501
          - 502
          - 503
          - 504
          - 505
          - 506
          - 507
          - 508
          - 510
          - 511
          type: integer
          format: int32
        message:
          type: string
          nullable: true
        count:
          type: integer
          format: int64
          nullable: true
      additionalProperties: false
    BasicTokenCreateResponse:
      type: object
      properties:
        data:
          type: string
          nullable: true
        status:
          enum:
          - 100
          - 101
          - 102
          - 103
          - 200
          - 201
          - 202
          - 203
          - 204
          - 205
          - 206
          - 207
          - 208
          - 226
          - 300
          - 301
          - 302
          - 303
          - 304
          - 305
          - 306
          - 307
          - 308
          - 400
          - 401
          - 402
          - 403
          - 404
          - 405
          - 406
          - 407
          - 408
          - 409
          - 410
          - 411
          - 412
          - 413
          - 414
          - 415
          - 416
          - 417
          - 421
          - 422
          - 423
          - 424
          - 426
          - 428
          - 429
          - 431
          - 451
          - 500
          - 501
          - 502
          - 503
          - 504
          - 505
          - 506
          - 507
          - 508
          - 510
          - 511
          type: integer
          format: int32
        message:
          type: string
          nullable: true
        count:
          type: integer
          format: int64
          nullable: true
      additionalProperties: false
    ConflictErrorModel:
      type: object
      properties:
        status:
          type: integer
          format: int32
        message:
          type: string
          nullable: true
        error:
          type: array
          items:
            $ref: '#/components/schemas/ErrorModel'
          nullable: true
      additionalProperties: false
    ErrorModel:
      type: object
      properties:
        param:
          type: string
          nullable: true
        message:
          type: string
          nullable: true
      additionalProperties: false
    ErrorResponse:
      type: object
      properties:
        status:
          type: integer
          format: int32
        message:
          type: string
          nullable: true
        error:
          type: object
          nullable: true
        data:
          type: object
          nullable: true
        ie:
          type: object
          nullable: true
      additionalProperties: false
    LoginRequest:
      required:
      - password
      - username
      type: object
      properties:
        username:
          minLength: 1
          type: string
          description: Email id of company user, eg. demouser@gmail.com
        password:
          minLength: 1
          type: string
          description: User's login password
      additionalProperties: false
    LoginResponse:
      type: object
      properties:
        token_type:
          type: string
          description: Token type eg. "Bearer"
          nullable: true
        access_token:
          type: string
          description: Access token, used to communicate with IOTConnect APIs
          nullable: true
        expires_in:
          type: integer
          description: Access token expiry duration in seconds, eg. 1000
          format: int64
        refresh_token:
          type: string
          description: Refresh token, used to get new access token against current session without login request
          nullable: true
        status:
          enum:
          - 100
          - 101
          - 102
          - 103
          - 200
          - 201
          - 202
          - 203
          - 204
          - 205
          - 206
          - 207
          - 208
          - 226
          - 300
          - 301
          - 302
          - 303
          - 304
          - 305
          - 306
          - 307
          - 308
          - 400
          - 401
          - 402
          - 403
          - 404
          - 405
          - 406
          - 407
          - 408
          - 409
          - 410
          - 411
          - 412
          - 413
          - 414
          - 415
          - 416
          - 417
          - 421
          - 422
          - 423
          - 424
          - 426
          - 428
          - 429
          - 431
          - 451
          - 500
          - 501
          - 502
          - 503
          - 504
          - 505
          - 506
          - 507
          - 508
          - 510
          - 511
          type: integer
          description: Status code of request, eg.200
          format: int32
          readOnly: true
      additionalProperties: false
    MobileLoginRequest:
      required:
      - deviceToken
      - deviceType
      - osName
      - osVersion
      - password
      - username
      - uuid
      type: object
      properties:
        username:
          minLength: 1
          type: string
          description: User's login email id
        password:
          minLength: 1
          type: string
          description: User's login password
        deviceType:
          minLength: 1
          type: string
          description: Type of the device used for login
        osName:
          minLength: 1
          type: string
          description: Device os name
        osVersion:
          minLength: 1
          type: string
          description: Device os version
        deviceToken:
          minLength: 1
          type: string
          description: Device token
        uuid:
          minLength: 1
          type: string
      additionalProperties: false
    MobileLoginResponse:
      type: object
      properties:
        token_type:
          type: string
          description: Token type eg. "Bearer"
          nullable: true
        access_token:
          type: string
          description: Access token, used to communicate with IOTConnect APIs
          nullable: true
        expires_in:
          type: integer
          description: Access token expiry duration in seconds, eg. 1000
          format: int64
        refresh_token:
          type: string
          description: Refresh token, used to get new access token against current session without login request
          nullable: true
        status:
          enum:
          - 100
          - 101
          - 102
          - 103
          - 200
          - 201
          - 202
          - 203
          - 204
          - 205
          - 206
          - 207
          - 208
          - 226
          - 300
          - 301
          - 302
          - 303
          - 304
          - 305
          - 306
          - 307
          - 308
          - 400
          - 401
          - 402
          - 403
          - 404
          - 405
          - 406
          - 407
          - 408
          - 409
          - 410
          - 411
          - 412
          - 413
          - 414
          - 415
          - 416
          - 417
          - 421
          - 422
          - 423
          - 424
          - 426
          - 428
          - 429
          - 431
          - 451
          - 500
          - 501
          - 502
          - 503
          - 504
          - 505
          - 506
          - 507
          - 508
          - 510
          - 511
          type: integer
          description: Status code of request, eg.200
          format: int32
          readOnly: true
      additionalProperties: false
    RefreshTokenRequest:
      required:
      - refreshtoken
      type: object
      properties:
        refreshtoken:
          minLength: 1
          type: string
          description: Refresh token
      additionalProperties: false