Which credential to use for which kind of client.
Five ways to authenticate. Pick by what is calling.
| Calling from | Use | Start here |
|---|
| An operator console (Studio, Business App, Appmint Mobile) | User password sign-in | User authentication |
| A customer-facing site or app (Event App, a storefront) | Customer sign-in / sign-up | Customer authentication |
| A server, script or integration | API key | API keys |
| A point-of-sale terminal | Passcode or NFC card | POS passcode |
| A hardware hub in a venue | x-hub-key on the WebSocket handshake | hub-agent |
The rules that apply to all of them
orgid is always required. Header, query, body or cookie.
- Every route is guarded by default.
JwtAuthGuard is registered globally; @PublicRoute() is the opt-out, and 145 routes take it.
- The token payload is the signed record. Roles and permissions travel inside it, but the user is re-fetched from the database on every request. Per-role menu access (
data.permissions.menu) is left out of the token — read it from the sign-in or refresh response (Menu access).
- Deleted users fail closed with
401 user_not_found; roles changed after issue keep applying until refresh.
Where things live
| Area | Prefix |
|---|
| Sign-in, sign-up, invitations, OAuth, blocklists | /profile/* — also mounted at /user/* |
| 2FA, devices, login history, security settings | /profile/security/* |
| API keys and org service users | /api-key/* |
| Integration OAuth callbacks and webhooks | /connect/* |
Reference