docs
/
AppEngine API

Choosing an auth method

Which credential to use for which kind of client.

Five ways to authenticate. Pick by what is calling.

Calling fromUseStart here
An operator console (Studio, Business App, Appmint Mobile)User password sign-inUser authentication
A customer-facing site or app (Event App, a storefront)Customer sign-in / sign-upCustomer authentication
A server, script or integrationAPI keyAPI keys
A point-of-sale terminalPasscode or NFC cardPOS passcode
A hardware hub in a venuex-hub-key on the WebSocket handshakehub-agent

The rules that apply to all of them

  • orgid is always required. Header, query, body or cookie.
  • Every route is guarded by default. JwtAuthGuard is registered globally; @PublicRoute() is the opt-out, and 145 routes take it.
  • The token payload is the signed record. Roles and permissions travel inside it, but the user is re-fetched from the database on every request. Per-role menu access (data.permissions.menu) is left out of the token — read it from the sign-in or refresh response (Menu access).
  • Deleted users fail closed with 401 user_not_found; roles changed after issue keep applying until refresh.

Where things live

AreaPrefix
Sign-in, sign-up, invitations, OAuth, blocklists/profile/* — also mounted at /user/*
2FA, devices, login history, security settings/profile/security/*
API keys and org service users/api-key/*
Integration OAuth callbacks and webhooks/connect/*

Reference