Open Loyalty Authorization API

Authentication and token issuance.

OpenAPI Specification

open-loyalty-authorization-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: Open Loyalty REST Authorization API
  version: '1.0'
  description: API-first, headless loyalty and gamification platform. This document models a representative, grounded subset of the Open Loyalty REST API across members (customers), transactions, points transfers, reward campaigns, levels (tiers), and earning rules. Endpoints are scoped per store using a storeCode path segment. Open Loyalty is delivered as managed cloud SaaS on a per-tenant instance, so the server host below is a template - substitute your own Open Loyalty instance host. Requests and responses are JSON over HTTPS, authenticated with a JWT bearer token or a permanent API token.
  contact:
    name: Open Loyalty
    url: https://www.openloyalty.io
  license:
    name: Open Loyalty (Open Source Edition Apache-2.0 / Enterprise SaaS)
    url: https://github.com/OpenLoyalty
servers:
- url: https://{instance}.openloyalty.io/api
  description: Per-tenant Open Loyalty instance (substitute your own host).
  variables:
    instance:
      default: your-instance
      description: Your Open Loyalty tenant subdomain.
security:
- bearerAuth: []
- permanentToken: []
tags:
- name: Authorization
  description: Authentication and token issuance.
paths:
  /admin/login_check:
    post:
      operationId: adminLogin
      tags:
      - Authorization
      summary: Obtain a JWT for an admin user
      security: []
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                username:
                  type: string
                password:
                  type: string
              required:
              - username
              - password
      responses:
        '200':
          description: A signed JWT bearer token.
          content:
            application/json:
              schema:
                type: object
                properties:
                  token:
                    type: string
  /{storeCode}/customer/login_check:
    post:
      operationId: customerLogin
      tags:
      - Authorization
      summary: Obtain a JWT for a member (customer)
      security: []
      parameters:
      - $ref: '#/components/parameters/StoreCode'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                username:
                  type: string
                password:
                  type: string
      responses:
        '200':
          description: A signed JWT bearer token for the member.
components:
  parameters:
    StoreCode:
      name: storeCode
      in: path
      required: true
      description: The store the request is scoped to.
      schema:
        type: string
        default: DEFAULT
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: 'JWT obtained from POST /admin/login_check (admin) or POST /{storeCode}/customer/login_check (member), sent as Authorization: Bearer <token>.'
    permanentToken:
      type: apiKey
      in: header
      name: X-AUTH-TOKEN
      description: Permanent API token issued to an admin account.
externalDocs:
  description: Open Loyalty REST API reference
  url: https://docs.openloyalty.io/en/latest/api/