Skip to main content

Authentication

Every endpoint in this guide requires a credential sent in the Authorization header.


Getting a token​

API tokens are issued by an AnchorPoint superadmin from the admin application (or by an operator running api:token generate on the server). Ask your AnchorPoint administrator for one, giving them:

  • a name identifying your integration (e.g. marketing-site-production), and
  • whether the token should expire, and when.

The token is a 64-character random string.

It is displayed exactly once

The token is shown only at the moment it is created or rotated — only a SHA-256 hash is stored, so nobody (including AnchorPoint support) can recover it later. If you lose it, ask for a rotation.


Sending a token​

Send the token as a bearer credential on every request:

Authorization: Bearer 0k3NrQ9xVb2LpYd7...

JavaScript​

const res = await fetch(`${API_BASE}/v2/public/courses`, {
headers: { Authorization: `Bearer ${process.env.ANCHORPOINT_API_TOKEN}` },
});
const { data } = await res.json();

PHP (Laravel)​

$response = Http::withToken(config('services.anchorpoint.token'))
->get(config('services.anchorpoint.base_url') . '/v2/public/courses');

Python​

requests.get(
f"{API_BASE}/v2/public/courses",
headers={"Authorization": f"Bearer {os.environ['ANCHORPOINT_API_TOKEN']}"},
timeout=10,
)

The token must be stored server-side — in an environment variable or secret manager — and never shipped to a browser, a mobile bundle, or a public repository. A token is not scoped to a user; anyone holding it can read your public catalogue.


API token or JWT​

Every endpoint in this guide sits behind the api.or.jwt middleware, which accepts either credential in the same header:

CredentialIssued toTypical caller
API tokenAn integrationMarketing site, partner system
JWTA signed-in AnchorPoint userThe student/admin web app

This means your integration and the logged-in student app can share one set of endpoints. The only behavioural difference is personalisation: a JWT identifies a user, so GET /public/class/{id} can report that user's own registration. An API token has no user behind it, so those fields always come back empty — see Get a class.


Token lifecycle​

EventEffect on your requests
Token expires (expires_at passes)401 on every request, immediately
Token revoked by an admin401 on every request, immediately
Token rotatedThe old secret stops working the moment the new one is issued
Token deleted401, and the token's name cannot be reused

Successful requests stamp a last_used_at timestamp on the token (throttled to one write per minute), which administrators use to spot dormant integrations.

Plan for a rotation window: if your platform supports it, read the token from configuration at request time rather than at boot, so a rotation does not require a redeploy. See Handling a rotated token without downtime.