Authentication
Admin login with Discord, the signed-in admin's profile, logout, and the session cleanup job.
Project-scoped login (/auth/authorize), backend-to-backend session API (/auth/token, /auth/validate, /auth/logout, /auth/token/refresh), and system-admin Discord OAuth (/auth/admin/*). Use /auth/authorize when you need to force a fresh Discord consent (step-up auth) or to stay on the pre-SSO flow.
Initiate system admin Discord OAuth2 login
/api/auth/admin/discordReturns a Discord authorization URL. The admin opens the URL, authenticates with Discord, and is redirected to the admin callback endpoint.
Authentication: None, this endpoint is public.
Responses
| Status | Description | Body |
|---|---|---|
200 | Discord authorization URL. | any |
Open in Swagger (opens in a new tab)
Log out of the admin dashboard
/api/auth/admin/logoutInvalidates the current admin session and clears the admin_session httpOnly cookie. Accepts the token via Authorization: Bearer or the admin_session cookie, same as other admin routes.
Authentication: Admin session token (Authorization: Bearer <token>)
Responses
| Status | Description | Body |
|---|---|---|
200 | Logout successful. | SuccessResponseDto |
401 | Missing, invalid, or expired session token. |
Open in Swagger (opens in a new tab)
Get current system admin profile
/api/auth/admin/meReturns the profile of the authenticated system admin based on their Bearer session token or the admin_session httpOnly cookie set after Discord OAuth2 login. Useful for verifying a token is still valid and retrieving up-to-date profile data.
Authentication: Admin session token (Authorization: Bearer <token>)
Responses
| Status | Description | Body |
|---|---|---|
200 | Authenticated admin profile. | AdminMeResponseDto |
401 | Missing, invalid, or expired session token. | |
403 | Valid session but the member lacks the configured admin role. |
Open in Swagger (opens in a new tab)
Cleanup expired sessions (maintenance)
/api/auth/cleanupRemoves expired sessions. Should be called by a scheduled job.
Authentication: None, this endpoint is public.
Responses
| Status | Description | Body |
|---|---|---|
200 | Cleanup completed. | SuccessResponseDto |
Open in Swagger (opens in a new tab)
Schemas
AdminMeResponseDto schema
| Field | Type | Required | Description |
|---|---|---|---|
avatar | string or null | no | Discord avatar hash or full CDN URL |
displayName | string or null | no | Discord guild nickname (rewritten on every sync) |
email | string or null | no | Email address from Discord (requires email OAuth scope) |
globalName | string or null | no | Discord global display name |
id | string | yes | Member ID (Discord snowflake) |
isSystemAdmin | boolean | yes | Whether the member has the system admin flag set |
preferredName | string or null | no | Admin-set display-name override (via PATCH /api/admin/profile); takes precedence over displayName in the UI when present |
sessionExpiresAt | string (date-time) | yes | ISO 8601 timestamp when the current session expires |
username | string | yes | Discord username |
SuccessResponseDto schema
| Field | Type | Required | Description |
|---|---|---|---|
success | boolean | yes | Operation success status |
Source: apps/api/openapi.json.