Skip to main content

Authentication

Admin login with Discord, the signed-in admin's profile, logout, and the session cleanup job.

Project-scoped login (/auth/authorize), backend-to-backend session API (/auth/token, /auth/validate, /auth/logout, /auth/token/refresh), and system-admin Discord OAuth (/auth/admin/*). Use /auth/authorize when you need to force a fresh Discord consent (step-up auth) or to stay on the pre-SSO flow.

Initiate system admin Discord OAuth2 login

GET/api/auth/admin/discord

Returns a Discord authorization URL. The admin opens the URL, authenticates with Discord, and is redirected to the admin callback endpoint.

Authentication: None, this endpoint is public.

Responses

StatusDescriptionBody
200Discord authorization URL.any

Open in Swagger (opens in a new tab)

Log out of the admin dashboard

POST/api/auth/admin/logout

Invalidates the current admin session and clears the admin_session httpOnly cookie. Accepts the token via Authorization: Bearer or the admin_session cookie, same as other admin routes.

Authentication: Admin session token (Authorization: Bearer <token>)

Responses

StatusDescriptionBody
200Logout successful.SuccessResponseDto
401Missing, invalid, or expired session token.

Open in Swagger (opens in a new tab)

Get current system admin profile

GET/api/auth/admin/me

Returns the profile of the authenticated system admin based on their Bearer session token or the admin_session httpOnly cookie set after Discord OAuth2 login. Useful for verifying a token is still valid and retrieving up-to-date profile data.

Authentication: Admin session token (Authorization: Bearer <token>)

Responses

StatusDescriptionBody
200Authenticated admin profile.AdminMeResponseDto
401Missing, invalid, or expired session token.
403Valid session but the member lacks the configured admin role.

Open in Swagger (opens in a new tab)

Cleanup expired sessions (maintenance)

POST/api/auth/cleanup

Removes expired sessions. Should be called by a scheduled job.

Authentication: None, this endpoint is public.

Responses

StatusDescriptionBody
200Cleanup completed.SuccessResponseDto

Open in Swagger (opens in a new tab)

Schemas

AdminMeResponseDto schema

FieldTypeRequiredDescription
avatarstring or nullnoDiscord avatar hash or full CDN URL
displayNamestring or nullnoDiscord guild nickname (rewritten on every sync)
emailstring or nullnoEmail address from Discord (requires email OAuth scope)
globalNamestring or nullnoDiscord global display name
idstringyesMember ID (Discord snowflake)
isSystemAdminbooleanyesWhether the member has the system admin flag set
preferredNamestring or nullnoAdmin-set display-name override (via PATCH /api/admin/profile); takes precedence over displayName in the UI when present
sessionExpiresAtstring (date-time)yesISO 8601 timestamp when the current session expires
usernamestringyesDiscord username

SuccessResponseDto schema

FieldTypeRequiredDescription
successbooleanyesOperation success status

Source: apps/api/openapi.json.